Joe Sandbox - Abstract Analysis File
               16203
            
                  			Generated with Joe Sandbox 6.0.2
            | General information | |
| Start time: | 20:02:20 | 
| Start date: | 02/07/2012 | 
| Overall analysis duration: | 0h 2m 48s | 
| Sample file name: | 6f7e68ac83fb111653e2093c17d46b21 | 
| Cookbook file name: | Analyse Banking Trojan.jbs | 
| Analysis system description: | XP SP3 (Office 2003 SP2, Java 1.6.0, Acrobat Reader 9.3.4, Internet Explorer 8) | 
| Number of analysed new started processes analysed: | 6 | 
| Number of new started drivers analysed: | 0 | 
| Number of existing processes analysed: | 0 | 
| Number of existing drivers analysed: | 0 | 
| Number of injected processes analysed: | 20 | 
| Errors: | 
 | 
| Classification / Threat Score | |||||||
| Persistence, Installation, Boot Survival: |  | ||||||
| Hiding, Stealthiness, Detection and Removal Protection: |  | ||||||
| Security Solution / Mechanism bypass, termination and removal, Anti Debugging, VM Detection: |  | ||||||
| Spreading: |  | ||||||
| Exploiting: |  | ||||||
| Networking: |  | ||||||
| Data spying, Sniffing, Keylogging, Ebanking Fraud: |  | ||||||
| Signature Detections | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
| 
 | |
Static File Information
            | General Information | |
| File name: | 6f7e68ac83fb111653e2093c17d46b21 | 
| File size: | 196096 | 
| MD5: | 6f7e68ac83fb111653e2093c17d46b21 | 
| SHA1: | 5dbe5f3f62456998d8bf2b351783f26e15d154de | 
| SHA256: | b22ffd981d026c84fc20edd94f21d74a189ae349d9608c719088415ed54da70e | 
| File type: | PE32 executable for MS Windows (GUI) Intel 80386 32-bit | 
| PE Information | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
String Analysis
            | Formattings for printf style functions | |
| String value | Source | 
| 3[)%gY | iexplore.exe | 
| LOG: File %s being registered. | iexplore.exe | 
| CPenIMX(sketch)::OnKillThreadFocus(); _GetOnOff() returns %s. | iexplore.exe | 
| zD\%ce | 6f7e68ac83fb111653e2093c17d46b21.exe, B6232F3AC2C.exe, 5CBD14A05E0D693.dr | 
| Identified by %s7%1!ls! | iexplore.exe | 
| Netscape Navigator profile: %s | iexplore.exe | 
| %OHB"s | iexplore.exe | 
| |%SystemRoot%\system32\rsvpsp.dll | iexplore.exe | 
| %IEFRAME.dl | iexplore.exe | 
| %s hr | iexplore.exe | 
| CTipFunctionProvider(sketch)::GetFunction %s | iexplore.exe | 
| %SystemRoot%\Debug\UserMode\userenv.bak | iexplore.exe | 
| %Can't create necessary temporary | iexplore.exe | 
| %s Document|*%s|All Files|*.*|| | iexplore.exe | 
| var L_ACR_ReturnTo_TEXT = "Try to return to %s"; | iexplore.exe | 
| Unknown-Lear&n more about search provider preferences%Lear&n more about InPrivate Filtering | iexplore.exe | 
| CTipFunctionProvider(sketch)::GetFunction(...,...,%s) | iexplore.exe | 
| Start Page.Would you like to set your Start Page to "%s"? | iexplore.exe | 
| !.LOG: INF Processing: Satellite DLL found:%s | iexplore.exe | 
| %SystemRoot%\Debug\UserMode\userenv.log | iexplore.exe | 
| %s Line: %ld Character: %ld | iexplore.exe | 
| BERR: Run Setup Hook: Failed Error Code:(hr) = %lx, processing: %s | iexplore.exe | 
| Accelerators: %s | iexplore.exe | 
| Netscape versions less than 4.0"Netscape Navigator 4.0 profile: %s | iexplore.exe | 
| %sAuthor: %s | iexplore.exe | 
| ERR: Security Trust Verification Failed or rejected by user/administrator. Check Security Settings. Detailed Error Code (hr) = %lx | iexplore.exe | 
| m&&delete g[m];g[a]=r;h[i]=a;i=(i+1)%f}e!=_.p&&j.vv==_.p&&(j.vv=e);c!=_.p&&(j.lx=c);d!=_.p&&(j.rv+=d)}function c(a,e){for(var b=0,c;b<a.length;++b)if(c=e[b],0<c&&a[b]>c)return _.l;return _.w}var f=e||10,g={},h=[],i=0,j=b(),m=b(),e={LX:function updateTimeToFirstChunk(a,e){d(a,e,_.p,_.p)},MX:function updateTimeToLastChunk(a,e){d(a,_.p,e,_.p)},JX:function updateProcessingTime(a,e){d(a,_.p,_.p,e)},YR:function checkThresholds(e,b,d){a();var g=[j.vv,j.lx,j.rv],i=[m.vv,m.lx,m.rv];if(e=e.sI(b,d))if(b=h.length== | iexplore.exe, rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1].dr | 
| End downloading component %s | iexplore.exe | 
| Unknown Setup Error.=LOG: Downloaded images must now be all native code, URL:(%s) | iexplore.exe | 
| $xsJ%xs{%xs | iexplore.exe | 
| %s (expiring) | iexplore.exe | 
| Do you want to replace it?+Cannot find %s. | iexplore.exe | 
| Global\%s | iexplore.exe | 
| %s\%s\%s\%s\%s\%s | iexplore.exe | 
| Default: %s | iexplore.exe | 
| %s min | iexplore.exe | 
| re = /%s/g; | iexplore.exe | 
| %SystemRoot%\System32\mswsock.dll | iexplore.exe | 
| [ERROR] : dwErr == %u | iexplore.exe | 
| Pw%n[w | iexplore.exe | 
| %C&&]N | iexplore.exe | 
| Connecting to site %s | iexplore.exe | 
| %ls %ls | iexplore.exe | 
| 6This is the full list of %s. No filters are available. | iexplore.exe | 
| Export the favorites to %s | iexplore.exe | 
| %d.%d.%d.%d | iexplore.exe | 
| Export the cookies to %s | iexplore.exe | 
| Go to '%s' | iexplore.exe | 
| _.Oba=function(e,a){function b(a){a-=e;0>a&&(a=0);c[f]=a;f=(f+1)%d}var d=a||20,c=[],f=0,g=_.w,h={start:function start$$9(){function a(){var d=window.google.time();b(d-c);g&&(c=d,window.setTimeout(a,e))}var c=window.google.time();g=_.l;window.setTimeout(a,e)},stop:function stop$$1(){g=_.w},GS:function getAllDataPoints(){return c.slice(f).concat(c.slice(0,f))}};h.hZ=b;return h}; | iexplore.exe, rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1].dr | 
| EERR: INF Processing: No section for processing: %s | iexplore.exe | 
| %s (Upgrade) | iexplore.exe | 
| %u minute ago | iexplore.exe | 
| Q%fLY 8 | B6232F3AC2C.exe.dr | 
| Packager*Would you like to allow pop-ups from '%s'?*Would you like to block pop-ups from '%s'? | iexplore.exe | 
| New Folder (%d) | iexplore.exe | 
| %userenv.dll | iexplore.exe | 
| %%%%GGGGOOOOBBBB(((( | iexplore.exe | 
| %Certisign Certificadora Digital Ltda.100. | iexplore.exe | 
| . Cannot get primary/default language!RLOG: URL Download Complete: hrStatus:%lx, hrOSB:%lx, hrResponseHdr:%lx, URL:(%ws) | iexplore.exe | 
| Disclosed to others who might contact you for marketing of services and/or products. You will have an opportunity to ask the site not to do this.%Disclosed to others for any purposes. | iexplore.exe | 
| #!V!W!"!&!r%!%#%%%'%)%c%e%g%C%<!"%$%&%(%*%+%-%/%1%3%5%7%9%;%=%?%A%D%F%H%J%K%L%M%N%O%R%U%X%[%^%_%`%a%b%d%f%h%i%j%k%l%m%o%s%+!,! | iexplore.exe | 
| %sWhat's New: %s | iexplore.exe | 
| [ERROR] : dwErr == %u ( Could be invalid encryption key ) | iexplore.exe | 
| %systemr | svchost.exe | 
| Tab Group %d | iexplore.exe | 
| Installing component %s | iexplore.exe | 
| %SystemRoot%\ | iexplore.exe | 
| UERR: Setup Failed Error Code: (hr) = %lx, installing: %s to %s destination code(%lx) | iexplore.exe | 
| nLOG: Reporting Code Download Completion: (hr:%lx%s, CLASSID: %lx..., szCODE:(%ws), MainType:%ws, MainExt:%ws) | iexplore.exe | 
| "%s"pInternet Explorer does not support this type of search provider. | iexplore.exe | 
| %systemroot%\system32\com\dmp | iexplore.exe | 
| %s%s%s | iexplore.exe | 
| Back to %s (Alt+Left) | iexplore.exe | 
| %u hours ago | iexplore.exe | 
| eHu%ip | nav_logo107[1].png.dr | 
| http://%s.com | iexplore.exe | 
| 1Are you sure you want to delete History Item: %s?7Are you sure you want to delete these %d History items?5Are you sure you want to delete the selected Cookies? | iexplore.exe | 
| Do you want to format it now?)The disk in drive %c cannot be formatted. | iexplore.exe | 
| CPenIMX(sketch)::_EditInk(...,%s,%s) | iexplore.exe | 
| URL:%s Protocol | iexplore.exe | 
| %%%FFFFFFFiiiii | iexplore.exe | 
| Shows or hides the status bar.%Shows or hides formatting indicators. | iexplore.exe | 
| Sketch-Ink version=%s | iexplore.exe | 
| %s Accelerator | iexplore.exe | 
| %s (new) | iexplore.exe | 
| %f7A{[ | iexplore.exe | 
| %SystemRoot%\system32\mswso | iexplore.exe | 
| %s (Alt+Z) | iexplore.exe | 
| %sSubject: %s | iexplore.exe | 
| Pages visited %s%Pages visited in week starting %1!ws!#Pages visited from %1!ws! to %2!ws! | iexplore.exe | 
| %i>0T; | iexplore.exe, 0797C381B2F87EB5A1D5573BD15BA4F40.dr | 
| Expires at: %s | iexplore.exe | 
| %odm650 | B6232F3AC2C.exe.dr | 
| Updated %s | iexplore.exe | 
| CWndMain(sketch)::Enable(fEnable=%s) | iexplore.exe | 
| %s|*%s|All Files|*.*|| | iexplore.exe | 
| ,%.%0%2%4%6%8%:%<%>%@%B%E%G%I% | iexplore.exe | 
| Content-Length: %u | iexplore.exe | 
| Feed %d | iexplore.exe | 
| %s (Default)cPlease choose another default search provider for Internet Explorer before removing this selection. | iexplore.exe | 
| SOFTWARE\Microsoft\CTF\TIP\%s\LanguageProfile\0x%08X | iexplore.exe | 
| %ole32.dll | iexplore.exe | 
| LOG: Item %s being processed. | iexplore.exe | 
| q%I0z(e*& | 6f7e68ac83fb111653e2093c17d46b21.exe, B6232F3AC2C.exe | 
| [ERROR] : dwErr == %u ( Config is damaged ) | iexplore.exe | 
| 2LOG: Redundant download started on %s (hr = %lx). | iexplore.exe | 
| Search for "%s" | iexplore.exe | 
| EncodeUrl = EncodeUrl + '%u' + OutputEncoder_TwoByteHex(c); | iexplore.exe | 
| %d-%d-%d | iexplore.exe | 
| &'return' statement outside of function"Can't have 'break' outside of loop%Can't have 'continue' outside of loop | iexplore.exe | 
| yOpening %d tabs at once might take a long time and cause Internet Explorer to respond slowly. | iexplore.exe | 
| %s sec | iexplore.exe | 
| !XERR: INF Processing: Failed (%lx) processing: %s | iexplore.exe | 
| %%%FFFFF | iexplore.exe | 
| %Secure Server Certification Authority0 | iexplore.exe | 
| . language = %s | iexplore.exe | 
| UYour current security settings do not allow you to download files from this location.vWhen you send information to the %s, it might be possible for others to see that information. Do you want to continue?xWhen you send information from the %s, it might be possible for others to see that information. Do you want to continue? | iexplore.exe | 
| Import the favorites from %s | iexplore.exe | 
| \%1\$s|\%s | iexplore.exe | 
| SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%d | iexplore.exe | 
| r = %s | iexplore.exe | 
| %s\%s\%s\%s\%s | iexplore.exe | 
| `w%D,3 | iexplore.exe | 
| %u matches | iexplore.exe | 
| threadmetadata!nfo%d | iexplore.exe | 
| H$Bee%n: | iexplore.exe | 
| Cicero version=%s | iexplore.exe | 
| %s - Security Warning$Al&ways ask before opening this file | iexplore.exe | 
| A%emC{ | iexplore.exe | 
| rERR: OCX Install: detected incompatible platform binary (%s). Please contact site for a binary for your platform. | iexplore.exe | 
| You have imported %i feeds. | iexplore.exe | 
| %%%FFFFFF | iexplore.exe | 
| %s Suggestions | iexplore.exe | 
| running from location : %s | iexplore.exe | 
| CPenIMX(sketch)::OnChange(); _GetOnOff() returns %s. | iexplore.exe | 
| rogram Files\Windows Media Player\wmplayer.exe /Open "%L" | explorer.exe | 
| Assertion failed: %s, file %s, line %d | iexplore.exe | 
| CWndMain(sketch)::Show(fShow=%s) %s | iexplore.exe | 
| %sLast Updated: %s | iexplore.exe | 
| Adding CDL=(CLASSID: %lx..., szCODE:(%ws), VersionMS:%lx, VersionLS:%lx) | iexplore.exe | 
| %s (unverified publisher) | iexplore.exe | 
| of webpages that are designed for older browsers.aA problem displaying %s caused Internet Explorer to refresh the webpage using Compatibility View. | iexplore.exe | 
| %s\Content.IE5\%s | iexplore.exe | 
| [ERROR] : Cannot dump file (%u bytes) { %s } | iexplore.exe | 
| Add Search Providers...Mhttp://auto.search.msn.com/response.asp?MT={searchTerms}&srch=%d&prov=%s&utf8NThe following search provider is already installed. Do you want to replace it?9The following search provider is already installed: | iexplore.exe | 
| Sho&w: %s0Add-ons that have been used by Internet Explorer-Add-ons that run without requiring permission$Downloaded ActiveX Controls (32-bit)-Add-ons currently loaded in Internet Explorer | iexplore.exe | 
| tid=%u&stat= | iexplore.exe | 
| Expires in: %s | iexplore.exe | 
| CPenIMX::_ICCallback(%s,%08X,...) | iexplore.exe | 
| /LOG: Version not identified for %s, using 0.1. | iexplore.exe | 
| %d %d %d %d | iexplore.exe | 
| (Not verified) %s | iexplore.exe | 
| %Opens a new Internet Explorer window./Adds the current page to your Favorites folder.&Previews how this document will print.*Prints the document in the selected frame. | iexplore.exe | 
| %iX,43X | B6232F3AC2C.exe.dr | 
| %sLast Visited: %s | iexplore.exe | 
| CWndMain(sketch)::ShowHideUI() GetTipWantsToBeVisible()=%s _GetOnOff=%s this->bCanGetIC()=%s bShowMain=%s bEnable=%s | iexplore.exe | 
| Expired %s | iexplore.exe | 
| %SystemRoot | iexplore.exe | 
| %ld sites | iexplore.exe | 
| %IgnoreLoadLibrary | iexplore.exe | 
| Label not found6'default' can only appear once in a 'switch' statement%Expected identifier, string or number | iexplore.exe | 
| /Z%D,3 | iexplore.exe | 
| %s Feed %d | iexplore.exe | 
| CLSID\%s\InprocServer32 | iexplore.exe | 
| Pages visited at %s | iexplore.exe | 
| SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\%d | iexplore.exe | 
| Redirecting to site: %s | iexplore.exe | 
| (GMT %s%02u:%02u) %s | iexplore.exe | 
| Forward to %s (Alt+Right) | iexplore.exe | 
| Import the cookies from %s | iexplore.exe | 
| DragDrop%lx | iexplore.exe | 
| 0%clear | iexplore.exe | 
| AThere is no disk in drive %c. | iexplore.exe | 
| (Default for %s Accelerator)jThis Accelerator runs code. To remove this Accelerator, please try Remove Programs from the Control Panel. | iexplore.exe | 
| %u(t:B,c' | iexplore.exe | 
| %Opens the webpage for this Web Slice. | iexplore.exe | 
| Open '%s' in a new tab | iexplore.exe | 
| CPenIMX(sketch)::OnSetThreadFocus(); _GetOnOff() returns %s. | iexplore.exe | 
| (%d new) | iexplore.exe | 
| Start downloading from site: %s | iexplore.exe | 
| ache%OLK* | 6f7e68ac83fb111653e2093c17d46b21.exe, B6232F3AC2C.exe, svchost.exe, iexplore.exe | 
| For details, see 9ERR: Could not convert extension %s or type %s to clsid. | iexplore.exe | 
| Search %s | iexplore.exe | 
| [ERR: INF Processing: Failed Error Code:(%lx) processing: %s. Cannot get primary language! | iexplore.exe | 
| %%s has requested information from you | iexplore.exe | 
| %s (expired) | iexplore.exe | 
| %HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache%OLK* | iexplore.exe | 
| CPenIMX(sketch)::EditInk(%s) | iexplore.exe | 
| Getting data from cache %s#Website found. Waiting for reply... | iexplore.exe | 
| %d Weeks Ago | iexplore.exe | 
| 4O0-%i1 | iexplore.exe | 
| %xpsp2res.dll | iexplore.exe | 
| %OLE32.DLL | iexplore.exe | 
| Application: %s | iexplore.exe | 
| %Certisign Certificadora Digital Ltda.1301 | iexplore.exe | 
| %u hour ago | iexplore.exe | 
| %s (Default) | iexplore.exe | 
| E&dit with %s | iexplore.exe | 
| %u minutes ago | iexplore.exe | 
| .LOG: Setup Hook %s was executed successfully. | iexplore.exe | 
| ,Select which folder you want to export from.+Where do you want to export your favorites?7Select where you would like your favorites exported to..Where do you want to import your cookies from?8You can select where we should import your cookies from.)Where do you want to export your cookies?6You can select where we should export your cookies to.-%s already exists. | iexplore.exe | 
| 0,_.Gd)(b,"disabled")||this.B.push(b)};_.EI=function(e,a){e.IB(e.M==_.p?a?0:e.B.length-1:(e.M+(a?1:e.B.length-1))%e.B.length)}; | iexplore.exe | 
| %USERPROFILE%\Favo | iexplore.exe | 
| Keep &maximum items (%i) | iexplore.exe | 
| l%s has been removed from this computer. Do you want to clean up your personalized settings for this program? | iexplore.exe | 
| %O*@hv# | iexplore.exe | 
| Navigate to '%s' | iexplore.exe | 
| CPenIMX::_DIMCallback(%s,%08X,%08X,...) | iexplore.exe | 
| rI]%ipF | iexplore.exe | 
| zqnj%SNT | svchost.exe, ROUTER1.dr | 
| %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%System32\*.exe | iexplore.exe | 
| Insert a disk, and then try again.EThe disk in drive %c is not formatted. | iexplore.exe | 
| Search with %s | iexplore.exe | 
| Sketch TIP version=1.00.2297.1 m_langIDCurrent=0x%04X %s | iexplore.exe | 
| This item expired %s | iexplore.exe | 
| %sComments: %s | iexplore.exe | 
| Downloading from site: %s | iexplore.exe | 
| %SystemRoot%\system32\rsvpsp.dll | iexplore.exe | 
| `OyB%i | explorer.exe, B6232F3AC2C.exe.dr | 
| Importing: %s | iexplore.exe | 
| 8A webpage is not responding on the following website: %s | iexplore.exe | 
| _.DI=function(e){this.element=e;this.B=[];this.M=_.p;"ab_opt"==this.element.id&&0==this.element.childNodes.length&&window.gbar.aomc(this.element);for(var e=(0,_.Qc)(".ab_dropdownitem",this.element),a=0,b;b=e[a];a++)(0,_.Gd)(b,"disabled")||this.B.push(b)};_.EI=function(e,a){e.IB(e.M==_.p?a?0:e.B.length-1:(e.M+(a?1:e.B.length-1))%e.B.length)}; | rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1].dr | 
| 88qB%S | iexplore.exe | 
| %s, %s | iexplore.exe | 
| Looking up %s | iexplore.exe | 
| Host: %s | iexplore.exe | 
| erJ `%I" | 6f7e68ac83fb111653e2093c17d46b21.exe, B6232F3AC2C.exe, svchost.exe, iexplore.exe | 
| hNp%cxr | B6232F3AC2C.exe.dr | 
| :LOG: Downloaded images must now be all x86 code, URL:(%s) | iexplore.exe | 
| %s\Content.IE5\0 | iexplore.exe | 
| WRN: OCX Registration: no DllRegisterServer entry point in (%s). Skipping registration. INF Author: mark this section with RegisterServer=No as a performance optimization. | iexplore.exe | 
| _.Zfa=function(){(0,_.Rc)("#iur");for(var e=(0,_.Qc)("li.uh_r"),a=_.Xw,b=0,d;d=e[b++];){var c=(0,_.Rc)("a.bia",d),f=_.Yw[c.id];d=(0,_.Rc)("button.esw",d);f&&d&&(d.setAttribute("g:imgtbn",f[0]),c=c.href,d.setAttribute("g:imgland",c),c=/:\/\/(www.)?([^/?#]*)/i.exec((0,_.Sw)(c,"imgrefurl")),c=a.replace(/\%1\$s|\%s/,c?c[2]:""),d.setAttribute("g:imgtitle",c))}}; | iexplore.exe, rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1].dr | 
| Search provider: %s | iexplore.exe | 
| var L_ACR_Title_TEXT = "We were unable to return you to %s."; | iexplore.exe | 
| Export the feeds to %s | iexplore.exe | 
| Compatibility View(%s is now running in Compatibility View. | iexplore.exe | 
| %SystemRoot%\system32\SHELL32.dll | iexplore.exe | 
| %s%03d.tmp | iexplore.exe | 
| %s bytes | iexplore.exe | 
| ?Are you sure you want to import '%ls' to your Favorites folder?8Are you sure you want to export your Favorites to '%ls'?aFavorites cannot be imported because modification of favorites on this machine has been disabled.HThe Import/Export Wizard has been disabled by your system administrator.@Select Folder to Import Bookmarks | iexplore.exe | 
| K%f"Vl | iexplore.exe | 
| %s%s&rep=%s | iexplore.exe | 
| Expected '@end'%Conditional compilation is turned off | iexplore.exe | 
| %s&stat=online | explorer.exe | 
| %1!s!, %2!s!%Do you want to run or save this file? | iexplore.exe | 
| %sTitle: %s | iexplore.exe | 
| %d.%d.%d | iexplore.exe | 
| CPenIMX(sketch)::ActivateUI(...); GetTipWantsToBeVisible()=%s _GetOnOff=%s this->bCanGetIC()=%s. | iexplore.exe | 
| %d%% complete.CThe webpage could not be saved because one of its files is missing. | iexplore.exe | 
| %SHIMENG.DLL | iexplore.exe | 
| fz0z%D6 | B6232F3AC2C.exe.dr | 
| KLOG: Download OnStopBinding called (hrStatus = %lx / hrResponseHdr = %lx). | iexplore.exe | 
| Open in new tab (Ctrl+Enter)%Open '%s' in a tab group (Ctrl+Enter) | iexplore.exe | 
| %SystemRoot%\System32\winrnr.dll | iexplore.exe | 
| %SystemRoot%\system32\mswsock.dll | iexplore.exe | 
| WISP - %s | iexplore.exe | 
| VWRN: File %s was installed, but will require a reboot for the install to take effect. | iexplore.exe | 
| ALOG: Setup successful installing: %s to %s destination code(%lx) | iexplore.exe | 
| This is the new setting suggested by %s | iexplore.exe | 
| http://www.%s.com Launch Internet Explorer Browser Launch Internet Explorer Browser | iexplore.exe | 
| Start downloading component %s | iexplore.exe | 
| %d,%d,%d,%d | iexplore.exe | 
| %systemroot%\Registration | iexplore.exe | 
| Drive %c cannot be accessed. | iexplore.exe | 
| %s File | iexplore.exe | 
| ;ERR: Error installing Java Package. Error Code (hr) = %lx. | iexplore.exe | 
| guid=%s&ver=%u&ie=%s&os=%u.%u.%u&ut=%s&ccrc=%08X&md5=%s&plg=%s&plgstat=%s&wake=%u | explorer.exe | 
| OWRN: OBJECT tags for CLASSID=%lx... have mixed usage with CODEBASE=%ws and %ws | iexplore.exe | 
| Open all items (%u new) | iexplore.exe | 
| P%S%V%Y%\% | iexplore.exe | 
| HTTP/%d.%d | iexplore.exe | 
| +Go to "%s" (Alt+Enter to open in a new tab) | iexplore.exe | 
| re = /%s/g; | iexplore.exe | 
| Filter by %s:jAre you sure you want to delete this feed item? | iexplore.exe | 
| (s) (AC:3C) [09:36:44:546]: Executing op: FeaturePublish(Feature=FT_VC_Redist_MFC_x86,Parent=VC_Redist_12222_x86_enu,Absent=2,Component=-EnVx*}4B8{{l=gZ@m1kI@yCj'brE4q0LDoYL~fX^+NYK4w?(7+e=i(MTt%-g[m0%C!}L5O6hxDf?@'NMrNuGte}T4$fobOP4@MM~NpMp$[Dm4HGyYz=3~&x) | msiexec.exe | 
| SOFTWARE\Microsoft\CTF\TIP\%s\LanguageProfile\0x%08X\%s | iexplore.exe | 
| Open '%s' in a background tab | iexplore.exe | 
| %%%FFFFFFFiiiiii | iexplore.exe | 
| %%%FFFF | iexplore.exe | 
| URLs | |
| String value | Source | 
| http://%s.com | iexplore.exe | 
| http://ads1.msn.com/library/dap.js | explorer.exe | 
| http://ajax.aspnetcdn.com/ajax/jquery/jquery-1.5.1.min.js | explorer.exe | 
| http://amazon.fr/ | iexplore.exe | 
| http://answers.microsoft.com/en-us?wt.mc_id=mscom_en_us_hp_supporthome_131z4enus21969 | explorer.exe | 
| http://api.bing.com/qsml.aspx?query= | iexplore.exe | 
| http://api.search.live.com/qsml.aspx?query= | iexplore.exe | 
| http://ariadna.elmundo.es/ | iexplore.exe | 
| http://ariadna.elmundo.es/favicon.ico | iexplore.exe | 
| http://arianna.libero.it/ | iexplore.exe | 
| http://arianna.libero.it/favicon.ico | iexplore.exe | 
| http://asp.usatoday.com/ | iexplore.exe | 
| http://asp.usatoday.com/favicon.ico | iexplore.exe | 
| http://auone.jp/favicon.ico | iexplore.exe | 
| http://auto.search.msn.com/response.asp?mt= | iexplore.exe | 
| http://books.google.fr/bkshp?hl=fr&tab=wp | iexplore.exe, google_fr[1].txt.dr | 
| http://br.search.yahoo.com/ | iexplore.exe | 
| http://browse.guardian.co.uk/ | iexplore.exe | 
| http://browse.guardian.co.uk/favicon.ico | iexplore.exe | 
| http://busca.buscape.com.br/ | iexplore.exe | 
| http://busca.buscape.com.br/favicon.ico | iexplore.exe | 
| http://busca.estadao.com.br/favicon.ico | iexplore.exe | 
| http://busca.igbusca.com.br/ | iexplore.exe | 
| http://busca.igbusca.com.br//app/static/images/favicon.ico | iexplore.exe | 
| http://busca.orange.es/ | iexplore.exe | 
| http://busca.uol.com.br/ | iexplore.exe | 
| http://busca.uol.com.br/favicon.ico | iexplore.exe | 
| http://buscador.lycos.es/ | iexplore.exe | 
| http://buscador.terra.com.br/ | iexplore.exe | 
| http://buscador.terra.com/ | iexplore.exe | 
| http://buscador.terra.com/favicon.ico | iexplore.exe | 
| http://buscador.terra.es/ | iexplore.exe | 
| http://buscar.ozu.es/ | iexplore.exe | 
| http://buscar.ya.com/ | iexplore.exe | 
| http://busqueda.aol.com.mx/ | iexplore.exe | 
| http://c.microsoft.com/trans_pixel.aspx | explorer.exe | 
| http://ca.sia.it/seccli/repository/crl.der0j | iexplore.exe | 
| http://ca.sia.it/secsrv/repository/crl.der0j | iexplore.exe | 
| http://cerca.lycos.it/ | iexplore.exe | 
| http://cgi.search.biglobe.ne.jp/ | iexplore.exe | 
| http://cgi.search.biglobe.ne.jp/favicon.ico | iexplore.exe | 
| http://clients5.google.com/complete/search?hl= | iexplore.exe | 
| http://clk.atdmt.com/mrt/go/403600292/direct/01/ | explorer.exe | 
| http://clk.atdmt.com/mrt/go/403930520/direct/01/ | explorer.exe | 
| http://clk.atdmt.com/mrt/go/403952099/direct/01/ | explorer.exe | 
| http://clk.atdmt.com/mrt/go/404082205/direct/01/ | explorer.exe | 
| http://cnet.search.com/ | iexplore.exe | 
| http://cnweb.search.live.com/ | iexplore.exe | 
| http://cnweb.search.live.com/favicon.ico | iexplore.exe | 
| http://corp.naukri.com/ | iexplore.exe | 
| http://corp.naukri.com/favicon.ico | iexplore.exe | 
| http://crl.comodo.net/utn-userfirst-hardware.crl0q | iexplore.exe | 
| http://crl.comodoca.com/utn-userfirst-hardware.crl06 | iexplore.exe | 
| http://crl.quovadisglobal.com/qvrca2.crl0 | iexplore.exe | 
| http://crl.usertrust.com/utn-datacorpsgc.crl0 | iexplore.exe | 
| http://crl.usertrust.com/utn-userfirst-clientauthenticationandemail.crl0 | iexplore.exe | 
| http://crl.usertrust.com/utn-userfirst-hardware.crl01 | iexplore.exe | 
| http://crl.usertrust.com/utn-userfirst-networkapplications.crl0 | iexplore.exe | 
| http://crl.usertrust.com/utn-userfirst-object.crl0) | iexplore.exe | 
| http://crl.verisign.com/pca1.1.1.crl0g | iexplore.exe | 
| http://crl.verisign.com/pca2.1.1.crl0g | iexplore.exe | 
| http://crl.verisign.com/pca3.crl | iexplore.exe, 60E31627FDA0A46932B0E5948949F2A5.dr | 
| http://crl.verisign.com/pca3.crl0) | iexplore.exe | 
| http://crl.verisign.com/thawtetimestampingca.crl0 | iexplore.exe | 
| http://crl.verisign.com/tss-ca.crl0 | iexplore.exe | 
| http://crt.comodoca.com/utnaddtrustserverca.crt0$ | iexplore.exe | 
| http://cs.wikipedia.org/ | iexplore.exe | 
| http://cs.wikipedia.org/favicon.ico | iexplore.exe | 
| http://cs.wikipedia.org/w/api.php?action=opensearch&format=xml&search= | iexplore.exe | 
| http://csc3-2009-2-aia.verisign.com/csc3-2009-2.cer0 | iexplore.exe | 
| http://csc3-2009-2-crl.verisign.com/csc3-2009-2.crl | iexplore.exe, 0797C381B2F87EB5A1D5573BD15BA4F4.dr | 
| http://csc3-2009-2-crl.verisign.com/csc3-2009-2.crl0d | iexplore.exe | 
| http://de.search.yahoo.com/ | iexplore.exe | 
| http://de.wikipedia.org/ | iexplore.exe | 
| http://de.wikipedia.org/favicon.ico | iexplore.exe | 
| http://de.wikipedia.org/w/api.php?action=opensearch&format=xml&search= | iexplore.exe | 
| http://download.macromedia.com/pub/shockwave/cabs/flash/ | iexplore.exe, rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1].dr | 
| http://eeopqogagjqoqq.ru/vvvvvv.php | explorer.exe | 
| http://eeopqogagjqoqq.ru/vvvvvv.php;300 | explorer.exe | 
| http://eewtoopqq.ru/wwww.php | explorer.exe | 
| http://eewtoopqq.ru/wwww.php;300 | explorer.exe | 
| http://en.wikipedia.org/ | iexplore.exe | 
| http://en.wikipedia.org/favicon.ico | iexplore.exe | 
| http://en.wikipedia.org/w/api.php?action=opensearch&format=xml&search= | iexplore.exe | 
| http://es.ask.com/ | iexplore.exe | 
| http://es.search.yahoo.com/ | iexplore.exe | 
| http://es.wikipedia.org/ | iexplore.exe | 
| http://es.wikipedia.org/favicon.ico | iexplore.exe | 
| http://es.wikipedia.org/w/api.php?action=opensearch&format=xml&search= | iexplore.exe | 
| http://esearch.rakuten.co.jp/ | iexplore.exe | 
| http://espanol.search.yahoo.com/ | iexplore.exe | 
| http://espn.go.com/favicon.ico | iexplore.exe | 
| http://find.joins.com/ | iexplore.exe | 
| http://fr.search.yahoo.com/ | iexplore.exe | 
| http://fr.wikipedia.org/ | iexplore.exe | 
| http://fr.wikipedia.org/favicon.ico | iexplore.exe | 
| http://fr.wikipedia.org/w/api.php?action=opensearch&format=xml&search= | iexplore.exe | 
| http://go.microsoft.com/?linkid=2 | explorer.exe | 
| http://go.microsoft.com/?linkid=2028325 | explorer.exe | 
| http://go.microsoft.com/?linkid=4412892 | explorer.exe | 
| http://go.microsoft.com/favicon.ico | iexplore.exe | 
| http://go.microsoft.com/fwlink/?l | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=105563 | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=120347-http://go.microsoft.com/fwlink/?linkid=1203463read | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=120476 | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=121315 | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=121792 | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=122812hthe | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=124983 | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=12658 | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=12939 | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=134080)search | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=140502 | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=50462 | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=50893)lear&n | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=54537&clcid= | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=54729&clcid= | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=54758 | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=54796&clcid= | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=54896&clcid= | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=55027&clcid= | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=55028&clcid= | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=55107&clcid= | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=55242&clcid= | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=55245&clcid= | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=56297&clcid= | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=57427&protocol= | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=58472&clcid= | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=58473&clcid= | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=58658 | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=66725 | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=68928 | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=68929 | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=69157 | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=74005finternet | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=76277 | iexplore.exe | 
| http://go.microsoft.com/fwlink/?linkid=81184 | explorer.exe | 
| http://go.microsoft.com/fwlink/?linkid=99193 | iexplore.exe | 
| http://go.microsoft.com/fwlink/p/?linkid=139753 | explorer.exe | 
| http://go.microsoft.com/fwlink/p/?linkid=139754 | explorer.exe | 
| http://google.pchome.com.tw/ | iexplore.exe | 
| http://hhotelst555.ru/apache.php | explorer.exe | 
| http://hhotelst555.ru/apache.php;300 | explorer.exe | 
| http://home.altervista.org/ | iexplore.exe | 
| http://home.altervista.org/favicon.ico | iexplore.exe | 
| http://i.microsoft.com/en-us/homepage/bimapping.js?gv=bimapping&k=/en-us/homepage/components/bimappingen-us.xml&v=-2004919139 | explorer.exe | 
| http://i.microsoft.com/en-us/homepage/script.jsx?k=~/shared/templates/components/mscomviews/controls/scripts/jquery.bi.js;~/shared/templates/components/mscomviews/controls/scripts/jquery.bi.dataretrievers.attr.js;~/shared/templat | explorer.exe | 
| http://i.microsoft.com/en-us/homepage/script.jsx?k=~/shared/templates/components/mscomviews/controls/scripts/jquery.bi.js;~/shared/templates/components/mscomviews/controls/scripts/jquery.bi.dataretrievers.attr.js;~/shared/templates/components/mscomviews/controls/scripts/jquery.bi.dataretrievers.structure.js;~/shared/templates/components/mscomviews/controls/scripts/jquery.bi.queue.js;~/shared/templates/components/mscomviews/controls/scripts/wedcs.js;~/shared/templates/components/mscomviews/controls/scripts/jquery.bi.dataconsumers.wedcs.js;~/shared/templates/components/mscomviews/controls/scripts/webtrends_16.js;~/shared/templates/components/mscomviews/controls/scripts/jquery.bi.dataconsumers.webtrends.js;~/shared/templates/components/mscomviews/controls/scripts/jquery.bi.dataconsumers.saas.js&v=1112179869 | explorer.exe | 
| http://i.microsoft.com/en-us/homepage/script.jsx?k=~/shared/templates/components/mscomviews/controls/scripts/mscomhelper.js;~/shared/templates/components/mscomviews/controls/scripts/mscommenu.js;~/shared/templates/components/mscomviews/search/search.js;~/shared/templates/components/mscomviews/geo/geocookie.js;~/shared/templates/components/mscomviews/localepicker/localepicker.js&v=-309888484 | explorer.exe | 
| http://i.microsoft.com/en-us/homepage/script.jsx?k=~/shared/templates/components/mscomviews/vpivot/vpivot.js;~/shared/templates/components/mscomviews/grid/grid.js;~/shared/templates/components/mscomviews/hero/hero.js&v=743108056 | explorer.exe | 
| http://i.microsoft.com/en-us/homepage/shared/templates/components/hpsearch/images/searchsprite.ltr.gif | explorer.exe | 
| http://i.microsoft.com/en-us/homepage/style.cssx?k=~/shared/templates/components/mscomviews/vpivot/vpivot-css.aspx;~/shared/templates/components/mscomviews/grid/grid-css.aspx;~/shared/templates/components/mscomviews/hero/hero-css.aspx;~/shared/templates/components/mscomviews/list/list-css.aspx;~/shared/templates/components/mscomviews/controls/featureitem/featureitem-css.aspx&sc=/en-us/homepage/site.config&pc=&v=-820925690 | explorer.exe | 
| http://i.microsoft.com/en-us/homepage/style.cssx?k=~/shared/templates/master/hpmaster/master-css.aspx;~/shared/templates/components/mscomviews/header/header-css.aspx;~/shared/templates/components/mscomviews/products/products-css.aspx;~/shared/templates/components/mscomviews/producttiles/producttiles-css.aspx;~/shared/templates/components/mscomviews/productlist/productlist-css.aspx;~/shared/templates/components/mscomviews/search/search-css.aspx;~/shared/templates/components/mscomviews/localepicker/localepicker-css.aspx;~/shared/templates/components/mscomviews/menu/menu-css.aspx;~/shared/templates/components/mscomviews/footer/footer-css.aspx&sc=/en-us/homepage/site.config&pc=&v=-2141141143 | explorer.exe | 
| http://i.microsoft.com/global/en-us/homepage/publishingimages/header/ielogo.png | explorer.exe | 
| http://i.microsoft.com/global/en-us/homepage/publishingimages/header/officelogo.png | explorer.exe | 
| http://i.microsoft.com/global/en-us/homepage/publishingimages/header/phonelogo.png | explorer.exe | 
| http://i.microsoft.com/global/en-us/homepage/publishingimages/header/windowslogo.png | explorer.exe | 
| http://i.microsoft.com/global/en-us/homepage/publishingimages/header/xboxlogo.png | explorer.exe | 
| http://i.microsoft.com/global/en-us/homepage/publishingimages/sprite.png | explorer.exe | 
| http://i.microsoft.com/global/en-us/homepage/publishingimages/sprites/16/bg_fade.png | explorer.exe | 
| http://i.microsoft.com/global/en-us/homepage/publishingimages/sprites/16/bg_skirtsolid.png | explorer.exe | 
| http://i.microsoft.com/global/en-us/homepage/publishingimages/sprites/microsoft.png | explorer.exe | 
| http://i.microsoft.com/global/en-us/homepage/publishingimages/sprites/microsoft_header.png | explorer.exe | 
| http://i.microsoft.com/global/en-us/homepage/publishingimages/sprites/welcome_microsoft.png | explorer.exe | 
| http://i.microsoft.com/global/en-us/homepage/publishingimages/sprites/wh | explorer.exe | 
| http://i.microsoft.com/global/en-us/homepage/publishingimages/sprites/white_vpivot.png | explorer.exe | 
| http://i.microsoft.com/global/en-us/homepage/publishingimages/v2/footer/footer-bing.jpg | explorer.exe | 
| http://i.microsoft.com/global/en-us/homepage/publishingimages/v2/footer/footer-office.jpg | explorer.exe | 
| http://i.microsoft.com/global/en-us/homepage/publishingimages/v2/footer/footer-store.jpg | explorer.exe | 
| http://i.microsoft.com/global/en-us/homepage/publishingimages/v2/footer/footer-windows-phone.jpg | explorer.exe | 
| http://i.microsoft.com/global/en-us/homepage/publishingimages/v2/footer/footer-windows.jpg | explorer.exe | 
| http://i.microsoft.com/global/en-us/homepage/publishingimages/v2/footer/footer-xbox.jpg | explorer.exe | 
| http://i.microsoft.com/global/en-us/homepage/publishingimages/v2/hrule.jpg | explorer.exe | 
| http://i.microsoft.com/global/en-us/news/publishingimages/homepage/highlights/event_kinectacc_hl.jpg | explorer.exe | 
| http://i.microsoft.com/global/en-us/news/publishingimages/homepage/highlights/prod_global365_hl.jpg | explorer.exe | 
| http://i.microsoft.com/global/en-us/news/publishingimages/homepage/highlights/theme_localimpact_hl.jpg | explorer.exe | 
| http://i.microsoft.com/global/imagestore/publishingimages/asset/features/bingsocial_0702_260x130_en-us.png | explorer.exe | 
| http://i.microsoft.com/global/imagestore/publishingimages/asset/features/fixit_0702_260x130_en-us.png | explorer.exe | 
| http://i.microsoft.com/global/imagestore/publishingimages/asset/features/officetrial_0702_260x130_en-us.png | explorer.exe | 
| http://i.microsoft.com/global/imagestore/publishingimages/asset/features/windowsphone_0702_800x470_en-us.jpg | explorer.exe | 
| http://i.microsoft.com/global/imagestore/publishingimages/asset/footer/about.jpg | explorer.exe | 
| http://i.microsoft.com/global/imagestore/publishingimages/asset/footer/footer_skype.jpg | explorer.exe | 
| http://i.microsoft.com/global/imagestore/publishingimages/asset/footer/support.jpg | explorer.exe | 
| http://i.microsoft.com/global/imagestore/publishingimages/asset/thumbnails/icon_answers_40x40.png | explorer.exe | 
| http://i.microsoft.com/global/imagestore/publishingimages/asset/thumbnails/icon_mssecurityessentials_40x40.png | explorer.exe | 
| http://i.microsoft.com/global/imagestore/publishingimages/asset/thumbnails/icon_msupdates_40x40.png | explorer.exe | 
| http://i.microsoft.com/global/imagestore/publishingimages/asset/thumbnails/icon_winservicepackcenter_40x40.png | explorer.exe | 
| http://i3.microsoft.com/library/svy/broker.js | explorer.exe | 
| http://ie.search.yahoo.com/os?command= | iexplore.exe | 
| http://ie8.ebay.com/open-search/output-xml.php?q= | iexplore.exe | 
| http://image.excite.co.jp/jp/favicon/lep.ico | iexplore.exe | 
| http://images.joins.com/ui_c/fvc_joins.ico | iexplore.exe | 
| http://images.monster.com/favicon.ico | iexplore.exe | 
| http://img.atlas.cz/favicon.ico | iexplore.exe | 
| http://img.shopzilla.com/shopzilla/shopzilla.ico | iexplore.exe | 
| http://in.search.yahoo.com/ | iexplore.exe | 
| http://it.search.dada.net/ | iexplore.exe | 
| http://it.search.dada.net/favicon.ico | iexplore.exe | 
| http://it.search.yahoo.com/ | iexplore.exe | 
| http://it.wikipedia.org/ | iexplore.exe | 
| http://it.wikipedia.org/favicon.ico | iexplore.exe | 
| http://it.wikipedia.org/w/api.php?action=opensearch&format=xml&search= | iexplore.exe | 
| http://ja.wikipedia.org/ | iexplore.exe | 
| http://ja.wikipedia.org/favicon.ico | iexplore.exe | 
| http://ja.wikipedia.org/w/api.php?action=opensearch&format=xml&search= | iexplore.exe | 
| http://jobsearch.monster.com/ | iexplore.exe | 
| http://kr.search.yahoo.com/ | iexplore.exe | 
| http://list.taobao.com/ | iexplore.exe | 
| http://list.taobao.com/browse/search_visual.htm?n=15&q= | iexplore.exe | 
| http://livesearch.msn.co.kr/ | iexplore.exe | 
| http://logo.verisign.com/vslogo.gif0 | iexplore.exe | 
| http://mail.live.com/ | iexplore.exe | 
| http://mail.live.com/?rru=compose%3fsubject%3d | iexplore.exe | 
| http://maps.google.fr/maps?hl=fr&tab=wl | iexplore.exe, google_fr[1].txt.dr | 
| http://maps.live.com/ | iexplore.exe | 
| http://maps.live.com/default.aspx | iexplore.exe | 
| http://maps.live.com/geotager.aspx | iexplore.exe | 
| http://msdn.microsoft.com/ | iexplore.exe | 
| http://msdn.microsoft.com/en-us/default.aspx | explorer.exe | 
| http://msdn.microsoft.com/en-us/evalcenter/default.aspx | explorer.exe | 
| http://msdn.microsoft.com/en-us/hh361695 | explorer.exe | 
| http://msdn.microsoft.com/workshop/security/privacy/overview/privacyimportxml.asp) | iexplore.exe | 
| http://msdn.microsoft.com/workshop/security/szone/overview/templates.asp) | iexplore.exe | 
| http://msk.afisha.ru/ | iexplore.exe | 
| http://news.google.fr/nwshp?hl=fr&tab=wn | iexplore.exe, google_fr[1].txt.dr | 
| http://nl.wikipedia.org/ | iexplore.exe | 
| http://nl.wikipedia.org/favicon.ico | iexplore.exe | 
| http://nl.wikipedia.org/w/api.php?action=opensearch&format=xml&search= | iexplore.exe | 
| http://ns.adobe.com/exif/1.0/ | iexplore.exe | 
| http://ns.adobe.com/ix/1.0/ | iexplore.exe | 
| http://ns.adobe.com/pdf/1.3/ | iexplore.exe | 
| http://ns.adobe.com/photoshop/1.0/ | iexplore.exe | 
| http://ns.adobe.com/tiff/1.0/ | iexplore.exe | 
| http://ns.adobe.com/xap/1.0/ | iexplore.exe | 
| http://ns.adobe.com/xap/1.0/mm/ | iexplore.exe | 
| http://ocnsearch.goo.ne.jp/ | iexplore.exe | 
| http://office.microsoft.com/en-us/ | explorer.exe | 
| http://office.microsoft.com/en-us/downloads | explorer.exe | 
| http://office.microsoft.com/en-us/downloads?wt.mc_id=mscom_en_us_hp_supporthome_131o4enus22344 | explorer.exe | 
| http://office.microsoft.com/en-us/images/ | explorer.exe | 
| http://office.microsoft.com/en-us/images/images-clip-art-photos-sounds-animations-fx101741979.aspx?ctt=97&wt.mc_id=mscom_en_us_hp_supporthome_131o4enus21996 | explorer.exe | 
| http://office.microsoft.com/en-us/products/ | explorer.exe | 
| http://office.microsoft.com/en-us/support | explorer.exe | 
| http://office.microsoft.com/en-us/support/?wt.mc_id=mscom_en_us_hp_supporthome_131o4enus21971 | explorer.exe | 
| http://office.microsoft.com/en-us/templates/ | explorer.exe | 
| http://office.microsoft.com/en-us/templates/?wt.mc_id=mscom_en_us_hp_supporthome_131o4enus21983 | explorer.exe | 
| http://office.microsoft.com/en-us/try | explorer.exe | 
| http://openimage.interpark.com/interpark.ico | iexplore.exe | 
| http://p.zhongsou.com/ | iexplore.exe | 
| http://p.zhongsou.com/favicon.ico | iexplore.exe | 
| http://p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i1.ds.ipv6-exp.l.google.com/ | iexplore.exe | 
| http://p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i1.ds.ipv6-exp.l.google.com/intl/en_all/ipv6/images/6.gif | iexplore.exe | 
| http://p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i2.v4.ipv6-exp.l.google.com/ | iexplore.exe | 
| http://p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i2.v4.ipv6-exp.l.google.com/intl/en_all/ipv6/images/6.gif | iexplore.exe | 
| http://picasaweb.google.fr/home?hl=fr&tab=wq | iexplore.exe, google_fr[1].txt.dr | 
| http://pinpoint.microsoft.com/en-us/default.aspx?wt.mc_id=mscom_hp_us_bl_pinpoint | explorer.exe | 
| http://pinpoint.microsoft.com/en-us/home?wt.mc_id=mscom_hp_us_nav_pc_solutions | explorer.exe | 
| http://pl.wikipedia.org/ | iexplore.exe | 
| http://pl.wikipedia.org/favicon.ico | iexplore.exe | 
| http://pl.wikipedia.org/w/api.php?action=opensearch&format=xml&search= | iexplore.exe | 
| http://price.ru/ | iexplore.exe | 
| http://price.ru/favicon.ico | iexplore.exe | 
| http://pt.wikipedia.org/ | iexplore.exe | 
| http://pt.wikipedia.org/w/api.php?action=opensearch&format=xml&search= | iexplore.exe | 
| http://purl.org/dc/elements/1.1/ | iexplore.exe | 
| http://purl.org/rss/1.0/modules/content/ | iexplore.exe | 
| http://purl.org/rss/1.0/modules/slash/ | iexplore.exe | 
| http://recherche.linternaute.com/ | iexplore.exe | 
| http://recherche.tf1.fr/ | iexplore.exe | 
| http://recherche.tf1.fr/favicon.ico | iexplore.exe | 
| http://rover.ebay.com | iexplore.exe | 
| http://ru.search.yahoo.com | iexplore.exe | 
| http://ru.wikipedia.org/ | iexplore.exe | 
| http://ru.wikipedia.org/favicon.ico | iexplore.exe | 
| http://ru.wikipedia.org/w/api.php?action=opensearch&format=xml&search= | iexplore.exe | 
| http://sads.myspace.com/ | iexplore.exe | 
| http://schema.org/webpage | iexplore.exe, google_fr[1].txt.dr | 
| http://schemas.microsoft.com/office/2004/12/omml | iexplore.exe | 
| http://search-dyn.tiscali.it/ | iexplore.exe | 
| http://search.about.com/ | iexplore.exe | 
| http://search.alice.it/ | iexplore.exe | 
| http://search.alice.it/favicon.ico | iexplore.exe | 
| http://search.aol.com/ | iexplore.exe | 
| http://search.aol.in/ | iexplore.exe | 
| http://search.atlas.cz/ | iexplore.exe | 
| http://search.auction.co.kr/ | iexplore.exe | 
| http://search.auone.jp/ | iexplore.exe | 
| http://search.books.com.tw/ | iexplore.exe | 
| http://search.books.com.tw/favicon.ico | iexplore.exe | 
| http://search.centrum.cz/ | iexplore.exe | 
| http://search.centrum.cz/favicon.ico | iexplore.exe | 
| http://search.chol.com/ | iexplore.exe | 
| http://search.chol.com/favicon.ico | iexplore.exe | 
| http://search.cn.yahoo.com/ | iexplore.exe | 
| http://search.daum.net/ | iexplore.exe | 
| http://search.daum.net/favicon.ico | iexplore.exe | 
| http://search.dreamwiz.com/ | iexplore.exe | 
| http://search.dreamwiz.com/favicon.ico | iexplore.exe | 
| http://search.ebay.co.uk/ | iexplore.exe | 
| http://search.ebay.com/ | iexplore.exe | 
| http://search.ebay.com/favicon.ico | iexplore.exe | 
| http://search.ebay.de/ | iexplore.exe | 
| http://search.ebay.es/ | iexplore.exe | 
| http://search.ebay.fr/ | iexplore.exe | 
| http://search.ebay.in/ | iexplore.exe | 
| http://search.ebay.it/ | iexplore.exe | 
| http://search.empas.com/ | iexplore.exe | 
| http://search.empas.com/favicon.ico | iexplore.exe | 
| http://search.espn.go.com/ | iexplore.exe | 
| http://search.gamer.com.tw/ | iexplore.exe | 
| http://search.gamer.com.tw/favicon.ico | iexplore.exe | 
| http://search.gismeteo.ru/ | iexplore.exe | 
| http://search.goo.ne.jp/ | iexplore.exe | 
| http://search.goo.ne.jp/favicon.ico | iexplore.exe | 
| http://search.hanafos.com/ | iexplore.exe | 
| http://search.hanafos.com/favicon.ico | iexplore.exe | 
| http://search.interpark.com/ | iexplore.exe | 
| http://search.ipop.co.kr/ | iexplore.exe | 
| http://search.ipop.co.kr/favicon.ico | iexplore.exe | 
| http://search.live.com/results.aspx?form=iefm1&q= | iexplore.exe | 
| http://search.live.com/results.aspx?form=so2tdf&q= | iexplore.exe | 
| http://search.live.com/results.aspx?form=soltdf&q= | iexplore.exe | 
| http://search.live.com/results.aspx?q= | iexplore.exe | 
| http://search.live.com/results.aspx?q=search&form=hpdtdf | iexplore.exe | 
| http://search.live.com/results.aspx?q=search&form=hpntdf | iexplore.exe | 
| http://search.livedoor.com/ | iexplore.exe | 
| http://search.livedoor.com/favicon.ico | iexplore.exe | 
| http://search.lycos.co.uk/ | iexplore.exe | 
| http://search.lycos.com/ | iexplore.exe | 
| http://search.lycos.com/favicon.ico | iexplore.exe | 
| http://search.microsoft.com/ | iexplore.exe | 
| http://search.microsoft.com/results.aspx?form=mshome&mkt= | explorer.exe | 
| http://search.microsoft.com/shared/templates/master/smcpage/autosuggesthandler.ashx?q= | explorer.exe | 
| http://search.msn.co.jp/results.aspx?q= | iexplore.exe | 
| http://search.msn.co.uk/results.aspx?q= | iexplore.exe | 
| http://search.msn.com.cn/results.aspx?q= | iexplore.exe | 
| http://search.msn.com/results.aspx?q= | iexplore.exe | 
| http://search.nate.com/ | iexplore.exe | 
| http://search.naver.com/ | iexplore.exe | 
| http://search.naver.com/favicon.ico | iexplore.exe | 
| http://search.nifty.com/ | iexplore.exe | 
| http://search.orange.co.uk/ | iexplore.exe | 
| http://search.orange.co.uk/favicon.ico | iexplore.exe | 
| http://search.rediff.com/ | iexplore.exe | 
| http://search.rediff.com/favicon.ico | iexplore.exe | 
| http://search.seznam.cz/ | iexplore.exe | 
| http://search.seznam.cz/favicon.ico | iexplore.exe | 
| http://search.sify.com/ | iexplore.exe | 
| http://search.yahoo.co.jp | iexplore.exe | 
| http://search.yahoo.co.jp/favicon.ico | iexplore.exe | 
| http://search.yahoo.com/ | iexplore.exe | 
| http://search.yahoo.com/favicon.ico | iexplore.exe | 
| http://search.yam.com/ | iexplore.exe | 
| http://search1.taobao.com/ | iexplore.exe | 
| http://search2.estadao.com.br/ | iexplore.exe | 
| http://searchresults.news.com.au/ | iexplore.exe | 
| http://service2.bfast.com/ | iexplore.exe | 
| http://si.wikipedia.org/ | iexplore.exe | 
| http://si.wikipedia.org/favicon.ico | iexplore.exe | 
| http://si.wikipedia.org/w/api.php?action=opensearch&format=xml&search= | iexplore.exe | 
| http://sitesearch.timesonline.co.uk/ | iexplore.exe | 
| http://so-net.search.goo.ne.jp/ | iexplore.exe | 
| http://spaces.live.com/ | iexplore.exe | 
| http://spaces.live.com/blogit.aspx | iexplore.exe | 
| http://ssl.gstatic.com/ | iexplore.exe | 
| http://ssl.gstatic.com/gb/images/j_e6a6aca6.png | iexplore.exe | 
| http://ssl.gstatic.com/gb/images/j_e6a6aca6.png... | iexplore.exe | 
| http://ssl.gstatic.com/gb/js/sem_feed2a2e2d54cd5f40fb4b5f5244fff2.js | iexplore.exe | 
| http://store.microsoft.com/;icon-uri=http://img3.store.microsoft.com/prod/clusterb/v2/framework/pages/global/msstore_icon.ico | explorer.exe | 
| http://suche.aol.de/ | iexplore.exe | 
| http://suche.freenet.de/ | iexplore.exe | 
| http://suche.freenet.de/favicon.ico | iexplore.exe | 
| http://suche.lycos.de/ | iexplore.exe | 
| http://suche.t-online.de/ | iexplore.exe | 
| http://suche.web.de/ | iexplore.exe | 
| http://suche.web.de/favicon.ico | iexplore.exe | 
| http://support.microsoft.com | iexplore.exe | 
| http://support.microsoft.com/ | explorer.exe | 
| http://support.microsoft.com/;icon-uri=http://www.microsoft.com/favicon.ico | explorer.exe | 
| http://support.microsoft.com/?ln=en-us&x=16&y=12 | explorer.exe | 
| http://support.microsoft.com/?wt.mc_id=mscom_en_us_hp_supporthome_131z4enus21977 | explorer.exe | 
| http://support.microsoft.com/fixit/;icon-uri=http://www.microsoft.com/favicon.ico | explorer.exe | 
| http://support.microsoft.com/fixit?wt.mc_id=mscom_en_us_hp_hlhome_131z4enus22012 | explorer.exe | 
| http://support.microsoft.com/search | explorer.exe | 
| http://support.xbox.com/en-us/home?wt.mc_id=mscom_en_us_hp_supporthome_131x4enus21975 | explorer.exe | 
| http://technet.microsoft.com/en-us/default.aspx | explorer.exe | 
| http://technet.microsoft.com/en-us/evalcenter | explorer.exe | 
| http://technet.microsoft.com/en-us/ms772425 | explorer.exe | 
| http://translate.google.fr/?hl=fr&tab=wt | iexplore.exe, google_fr[1].txt.dr | 
| http://translator.live.com/?ref=ie8activity | iexplore.exe | 
| http://translator.live.com/bv.aspx?ref=ie8activity&a= | iexplore.exe | 
| http://translator.live.com/bvprev.aspx?ref=ie8activity | iexplore.exe | 
| http://translator.live.com/default.aspx?ref=ie8activity | iexplore.exe | 
| http://translator.live.com/defaultprev.aspx?ref=ie8activity | iexplore.exe | 
| http://treyresearch.net | iexplore.exe | 
| http://tw.search.yahoo.com/ | iexplore.exe | 
| http://udn.com/ | iexplore.exe | 
| http://udn.com/favicon.ico | iexplore.exe | 
| http://uk.ask.com/ | iexplore.exe | 
| http://uk.ask.com/favicon.ico | iexplore.exe | 
| http://uk.search.yahoo.com/ | iexplore.exe | 
| http://update.microsoft.com/microsoftupdate?wt.mc_id=mscom_en_us_hp_securityhome_131z4enus21978 | explorer.exe | 
| http://vachercher.lycos.fr/ | iexplore.exe | 
| http://video.globo.com/ | iexplore.exe | 
| http://video.globo.com/favicon.ico | iexplore.exe | 
| http://video.google.fr/?hl=fr&tab=wv | iexplore.exe, google_fr[1].txt.dr | 
| http://web.ask.com/ | iexplore.exe | 
| http://wellformedweb.org/commentapi/ | iexplore.exe | 
| http://windows.microsoft.com/en-us/hotmail/home | explorer.exe | 
| http://windows.microsoft.com/en-us/internet-explorer/downloads/ie | explorer.exe | 
| http://windows.microsoft.com/en-us/internet-explorer/help?wt.mc_id=mscom_en_us_hp_supporthome_131i4enus21974 | explorer.exe | 
| http://windows.microsoft.com/en-us/internet-explorer/products/ie/home | explorer.exe | 
| http://windows.microsoft.com/en-us/skydrive/home | explorer.exe | 
| http://windows.microsoft.com/en-us/windows-live/essentials-home | explorer.exe | 
| http://windows.microsoft.com/en-us/windows/downloads | explorer.exe | 
| http://windows.microsoft.com/en-us/windows/downloads/service-packs | explorer.exe | 
| http://windows.microsoft.com/en-us/windows/downloads/service-packs?wt.mc_id=mscom_en_us_hp_securityhome_131w4enus21980 | explorer.exe | 
| http://windows.microsoft.com/en-us/windows/downloads?wt.mc_id=mscom_en_us_hp_supporthome_131w4enus22343 | explorer.exe | 
| http://windows.microsoft.com/en-us/windows/help | explorer.exe | 
| http://windows.microsoft.com/en-us/windows/help?wt.mc_id=mscom_en_us_hp_supporthome_131w4enus21970 | explorer.exe | 
| http://windows.microsoft.com/en-us/windows/home | explorer.exe | 
| http://windows.microsoft.com/en-us/windows/products | explorer.exe | 
| http://windows.microsoft.com/en-us/windows/products/security-essentials | explorer.exe | 
| http://windows.microsoft.com/en-us/windows/products/security-essentials?wt.mc_id=mscom_en_us_hp_securityhome_131z4enus21979 | explorer.exe | 
| http://windows.microsoft.com/en-us/windows/products/windows-xp | explorer.exe | 
| http://windows.microsoft.com/en-us/windows7/products/home | explorer.exe | 
| http://windowsupdate.microsoft.com | iexplore.exe | 
| http://www.abril.com.br/ | iexplore.exe | 
| http://www.abril.com.br/favicon.ico | iexplore.exe | 
| http://www.afisha.ru/app_themes/default/images/favicon.ico | iexplore.exe | 
| http://www.alarabiya.net/ | iexplore.exe | 
| http://www.alarabiya.net/favicon.ico | iexplore.exe | 
| http://www.amazon.co.jp/ | iexplore.exe | 
| http://www.amazon.co.uk/ | iexplore.exe | 
| http://www.amazon.com/exec/obidos/external-search/104-2981279-3455918?index=blended&keyword= | iexplore.exe | 
| http://www.amazon.com/favicon.ico | iexplore.exe | 
| http://www.amazon.com/gp/search?ie=utf8&tag=ie8search-20&index=blended&linkcode=qs&camp=1789&creative=9325&keywords= | iexplore.exe | 
| http://www.amazon.de/ | iexplore.exe | 
| http://www.aol.com/favicon.ico | iexplore.exe | 
| http://www.arrakis.com/ | iexplore.exe | 
| http://www.arrakis.com/favicon.ico | iexplore.exe | 
| http://www.asharqalawsat.com/ | iexplore.exe | 
| http://www.asharqalawsat.com/favicon.ico | iexplore.exe | 
| http://www.ask.com/ | iexplore.exe | 
| http://www.asp.net/ajaxlibrary/cdn.ashx.-- | explorer.exe | 
| http://www.auction.co.kr/auction.ico | iexplore.exe | 
| http://www.autoitscript.com/autoit3/ | explorer.exe | 
| http://www.baidu.com/ | iexplore.exe | 
| http://www.baidu.com/favicon.ico | iexplore.exe | 
| http://www.bing.com/ | explorer.exe | 
| http://www.bing.com/;icon-uri=http://www.bing.com/fd/s/a/bing.ico | explorer.exe | 
| http://www.bing.com/favicon.ico | iexplore.exe | 
| http://www.bing.com/search?form=mshpls&q= | explorer.exe | 
| http://www.bing.com/search?q= | iexplore.exe | 
| http://www.bing.com/search?q=%7bsearchterms%7d&src=ie-searchbox&form=ie8src | iexplore.exe | 
| http://www.blogger.com/?tab=wj | iexplore.exe, google_fr[1].txt.dr | 
| http://www.cdiscount.com/ | iexplore.exe | 
| http://www.cdiscount.com/favicon.ico | iexplore.exe | 
| http://www.ceneo.pl/ | iexplore.exe | 
| http://www.ceneo.pl/favicon.ico | iexplore.exe | 
| http://www.certplus.com/crl/class1.crl0 | iexplore.exe | 
| http://www.certplus.com/crl/class2.crl0 | iexplore.exe | 
| http://www.certplus.com/crl/class3.crl0 | iexplore.exe | 
| http://www.certplus.com/crl/class3p.crl0 | iexplore.exe | 
| http://www.certplus.com/crl/class3ts.crl0 | iexplore.exe | 
| http://www.chennaionline.com/ncommon/images/collogo.ico | iexplore.exe | 
| http://www.cjmall.com/ | iexplore.exe | 
| http://www.cjmall.com/favicon.ico | iexplore.exe | 
| http://www.clarin.com/favicon.ico | iexplore.exe | 
| http://www.cnet.co.uk/ | iexplore.exe | 
| http://www.cnet.com/favicon.ico | iexplore.exe | 
| http://www.dailymail.co.uk/ | iexplore.exe | 
| http://www.dailymail.co.uk/favicon.ico | iexplore.exe | 
| http://www.digsigtrust.com/dst_trust_cps_v990701.html0 | iexplore.exe | 
| http://www.entrust.net/crl/net1.crl0 | iexplore.exe | 
| http://www.etmall.com.tw/ | iexplore.exe | 
| http://www.etmall.com.tw/favicon.ico | iexplore.exe | 
| http://www.excite.co.jp/ | iexplore.exe | 
| http://www.expedia.com/ | iexplore.exe | 
| http://www.expedia.com/favicon.ico | iexplore.exe | 
| http://www.facebook.com/ | iexplore.exe | 
| http://www.facebook.com/favicon.ico | iexplore.exe | 
| http://www.gamesforwindows.com/en-us | explorer.exe | 
| http://www.gismeteo.ru/favicon.ico | iexplore.exe | 
| http://www.gmarket.co.kr/ | iexplore.exe | 
| http://www.gmarket.co.kr/favicon.ico | iexplore.exe | 
| http://www.google.co.in/ | iexplore.exe | 
| http://www.google.co.jp/ | iexplore.exe | 
| http://www.google.co.uk/ | iexplore.exe | 
| http://www.google.com | iexplore.exe | 
| http://www.google.com.br/ | iexplore.exe | 
| http://www.google.com.sa/ | iexplore.exe | 
| http://www.google.com.tw/ | iexplore.exe | 
| http://www.google.com/ | iexplore.exe | 
| http://www.google.com/favicon.ico | iexplore.exe | 
| http://www.google.com/ncr | iexplore.exe, google_fr[1].txt.dr | 
| http://www.google.com/support/accounts/bin/answer.py?hl=en&answer=151657 | iexplore.exe | 
| http://www.google.com/support/websearch/bin/answer.py?hl= | iexplore.exe, rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1].dr | 
| http://www.google.com/textinput | iexplore.exe | 
| http://www.google.com/textinputassistant/tia.png | iexplore.exe | 
| http://www.google.cz/ | iexplore.exe | 
| http://www.google.de/ | iexplore.exe | 
| http://www.google.es/ | iexplore.exe | 
| http://www.google.fr | iexplore.exe | 
| http://www.google.fr/ | {0DD04C9E-4667-11E1-97AA-08002763FBB4}.dat.dr | 
| http://www.google.fr/%20-%20windows%20internet%20explorer | iexplore.exe | 
| http://www.google.fr/&sig=0_y9ghr6l8ehidh5wp82jawajplts%3d&suggon=2 | iexplore.exe, google_fr[1].txt.dr | 
| http://www.google.fr/&sig=0_y9ghr6l8ehidh5wp82jawajplts%3d&suggon=2 | iexplore.exe | 
| http://www.google.fr/advanced_search?hl=fr | iexplore.exe | 
| http://www.google.fr/chrome/index.html?hl=fr&brand=chng&utm_source=fr-hpp&utm_medium=hpp&utm_campaign=fr | iexplore.exe | 
| http://www.google.fr/csi?v=3&s=webhp&action=&e=17259 | iexplore.exe | 
| http://www.google.fr/extern_chrome/b0659096785d29d3.js | iexplore.exe | 
| http://www.google.fr/favicon.ico | iexplore.exe | 
| http://www.google.fr/history/optout?hl=fr | iexplore.exe | 
| http://www.google.fr/ig | iexplore.exe | 
| http://www.google.fr/ig%3fhl%3dfr%26source%3diglk&usg=afqjcng3dq3pmqcxa1eqhlnwiuh8e97qkg | iexplore.exe, google_fr[1].txt.dr | 
| http://www.google.fr/ig%3fhl%3dfr%26source%3diglk&usg=afqjcng3dq3pmqcxa1eqhlnwiuh8e97qkg | iexplore.exe | 
| http://www.google.fr/ig/ | iexplore.exe | 
| http://www.google.fr/images/icons/product/chrome-48.png | iexplore.exe | 
| http://www.google.fr/images/mgyhp_sm.png | iexplore.exe | 
| http://www.google.fr/images/nav_logo107.png | iexplore.exe | 
| http://www.google.fr/images/srpr/logo3w.png | iexplore.exe | 
| http://www.google.fr/images/swxa.gif | iexplore.exe | 
| http://www.google.fr/imghp?hl=fr&tab=wi | iexplore.exe, google_fr[1].txt.dr | 
| http://www.google.fr/in | iexplore.exe | 
| http://www.google.fr/intl/fr/about.html | iexplore.exe | 
| http://www.google.fr/intl/fr/ads/ | iexplore.exe | 
| http://www.google.fr/intl/fr/options | iexplore.exe | 
| http://www.google.fr/intl/fr/options/ | google_fr[1].txt.dr | 
| http://www.google.fr/intl/fr/policies | iexplore.exe | 
| http://www.google.fr/intl/fr/policies/ | iexplore.exe | 
| http://www.google.fr/language_tools?hl=fr | iexplore.exe | 
| http://www.google.fr/mgyhp.html | iexplore.exe | 
| http://www.google.fr/preferences?hl=fr | iexplore.exe | 
| http://www.google.fr/reader/?hl=fr&tab=wy | iexplore.exe, google_fr[1].txt.dr | 
| http://www.google.fr/search | iexplore.exe | 
| http://www.google.fr/services/ | iexplore.exe | 
| http://www.google.fr/setprefs?prev=http://www.google.fr/&sig=0_y9ghr6l8ehidh5wp82jawajplts%3d&suggon=2 | iexplore.exe | 
| http://www.google.fr/shopping?hl=fr&tab=wf | iexplore.exe, google_fr[1].txt.dr | 
| http://www.google.fr/support/we | iexplore.exe | 
| http://www.google.fr/support/websearch/bin/answer.py?answer=186645&form=bb&hl=fr | iexplore.exe | 
| http://www.google.fr/url?sa=p&pref=ig&pval=3&q=http://w | iexplore.exe | 
| http://www.google.fr/url?sa=p&pref=ig&pval=3&q=http://www.google.fr/ig%3fhl%3dfr%26source%3diglk&usg=afqjcng3dq3pmqcxa1eqhlnwiuh8e97qkg | iexplore.exe | 
| http://www.google.fr/webhp | iexplore.exe | 
| http://www.google.fr/webhp/ | iexplore.exe | 
| http://www.google.fr/webhp?hl=fr&tab=ww | iexplore.exe, google_fr[1].txt.dr | 
| http://www.google.fr/xjs/_/js/s/s | iexplore.exe | 
| http://www.google.it/ | iexplore.exe | 
| http://www.google.pl/ | iexplore.exe | 
| http://www.google.ru/ | iexplore.exe | 
| http://www.google.si/ | iexplore.exe | 
| http://www.iask.com/ | iexplore.exe | 
| http://www.iask.com/favicon.ico | iexplore.exe | 
| http://www.iegallery.com/ | explorer.exe | 
| http://www.kkbox.com.tw/ | iexplore.exe | 
| http://www.kkbox.com.tw/favicon.ico | iexplore.exe | 
| http://www.linternaute.com/favicon.ico | iexplore.exe | 
| http://www.live.com/favicon.ico | iexplore.exe | 
| http://www.maktoob.com/favicon.ico | iexplore.exe | 
| http://www.mercadolibre.com.mx/ | iexplore.exe | 
| http://www.mercadolibre.com.mx/favicon.ico | iexplore.exe | 
| http://www.mercadolivre.com.br/ | iexplore.exe | 
| http://www.mercadolivre.com.br/favicon.ico | iexplore.exe | 
| http://www.merlin.com.pl/ | iexplore.exe | 
| http://www.merlin.com.pl/favicon.ico | iexplore.exe | 
| http://www.microsoft.com | explorer.exe | 
| http://www.microsoft.com/ | explorer.exe | 
| http://www.microsoft.com/about/en/us/default.aspx | explorer.exe | 
| http://www.microsoft.com/ar/eg/ | explorer.exe | 
| http://www.microsoft.com/ar/gulf/ | explorer.exe | 
| http://www.microsoft.com/ar/iq/ | explorer.exe | 
| http://www.microsoft.com/ar/ly/ | explorer.exe | 
| http://www.microsoft.com/ar/sa/ | explorer.exe | 
| http://www.microsoft.com/ar/xm/ | explorer.exe | 
| http://www.microsoft.com/az-latn/az/ | explorer.exe | 
| http://www.microsoft.com/be-by/ | explorer.exe | 
| http://www.microsoft.com/bg-bg/ | explorer.exe | 
| http://www.microsoft.com/bs/ba/ | explorer.exe | 
| http://www.microsoft.com/business/en-us/?fbid=la48qib2qmo | explorer.exe | 
| http://www.microsoft.com/careers | explorer.exe | 
| http://www.microsoft.com/careers/ | explorer.exe | 
| http://www.microsoft.com/communities/forums/default.mspx | explorer.exe | 
| http://www.microsoft.com/cs-cz/ | explorer.exe | 
| http://www.microsoft.com/da-dk/ | explorer.exe | 
| http://www.microsoft.com/de-at/ | explorer.exe | 
| http://www.microsoft.com/de-ch/ | explorer.exe | 
| http://www.microsoft.com/de-de/ | explorer.exe | 
| http://www.microsoft.com/download/en/default.aspx | explorer.exe | 
| http://www.microsoft.com/el-gr/ | explorer.exe | 
| http://www.microsoft.com/en-au/ | explorer.exe | 
| http://www.microsoft.com/en-ca/ | explorer.exe | 
| http://www.microsoft.com/en-cy/ | explorer.exe | 
| http://www.microsoft.com/en-eg/ | explorer.exe | 
| http://www.microsoft.com/en-gb/ | explorer.exe | 
| http://www.microsoft.com/en-gulf/ | explorer.exe | 
| http://www.microsoft.com/en-hk/ | explorer.exe | 
| http://www.microsoft.com/en-id/ | explorer.exe | 
| http://www.microsoft.com/en-in/ | explorer.exe | 
| http://www.microsoft.com/en-jo/ | explorer.exe | 
| http://www.microsoft.com/en-lb/ | explorer.exe | 
| http://www.microsoft.com/en-mt/ | explorer.exe | 
| http://www.microsoft.com/en-my/ | explorer.exe | 
| http://www.microsoft.com/en-ng/ | explorer.exe | 
| http://www.microsoft.com/en-nz/ | explorer.exe | 
| http://www.microsoft.com/en-ph/ | explorer.exe | 
| http://www.microsoft.com/en-pk/ | explorer.exe | 
| http://www.microsoft.com/en-sa/ | explorer.exe | 
| http://www.microsoft.com/en-sg/ | explorer.exe | 
| http://www.microsoft.com/en-us/ | explorer.exe | 
| http://www.microsoft.com/en-us/cloud/default.aspx | explorer.exe | 
| http://www.microsoft.com/en-us/download/?wt.mc_id=mscom_en_us_hp_supporthome_131z4enus21986 | explorer.exe | 
| http://www.microsoft.com/en-us/download/default.aspx?wt.mc_id=mscom_hp_us_nav_downloads | explorer.exe | 
| http://www.microsoft.com/en-us/dynamics/default.aspx | explorer.exe | 
| http://www.microsoft.com/en-us/news/ | explorer.exe | 
| http://www.microsoft.com/en-us/office365/online-software.aspx | explorer.exe | 
| http://www.microsoft.com/en-us/server-cloud/windows-server/default.aspx | explorer.exe | 
| http://www.microsoft.com/en-za/ | explorer.exe | 
| http://www.microsoft.com/en/bd/ | explorer.exe | 
| http://www.microsoft.com/en/bn/ | explorer.exe | 
| http://www.microsoft.com/en/esa/ | explorer.exe | 
| http://www.microsoft.com/en/ie/ | explorer.exe | 
| http://www.microsoft.com/en/lk/ | explorer.exe | 
| http://www.microsoft.com/en/us/sitemap.aspx | explorer.exe | 
| http://www.microsoft.com/en/westindies/default.aspx | explorer.exe | 
| http://www.microsoft.com/en/xf/ | explorer.exe | 
| http://www.microsoft.com/en/xm/ | explorer.exe | 
| http://www.microsoft.com/enterprise | explorer.exe | 
| http://www.microsoft.com/enterprise/default.aspx | explorer.exe | 
| http://www.microsoft.com/es-ar/ | explorer.exe | 
| http://www.microsoft.com/es-bo/ | explorer.exe | 
| http://www.microsoft.com/es-cl/ | explorer.exe | 
| http://www.microsoft.com/es-co/ | explorer.exe | 
| http://www.microsoft.com/es-cr/ | explorer.exe | 
| http://www.microsoft.com/es-do/ | explorer.exe | 
| http://www.microsoft.com/es-ec/ | explorer.exe | 
| http://www.microsoft.com/es-es/ | explorer.exe | 
| http://www.microsoft.com/es-gt/ | explorer.exe | 
| http://www.microsoft.com/es-hn/ | explorer.exe | 
| http://www.microsoft.com/es-mx/ | explorer.exe | 
| http://www.microsoft.com/es-ni/ | explorer.exe | 
| http://www.microsoft.com/es-pa/ | explorer.exe | 
| http://www.microsoft.com/es-pe/ | explorer.exe | 
| http://www.microsoft.com/es-pr/ | explorer.exe | 
| http://www.microsoft.com/es-py/ | explorer.exe | 
| http://www.microsoft.com/es-sv/ | explorer.exe | 
| http://www.microsoft.com/es-uy/ | explorer.exe | 
| http://www.microsoft.com/es-ve/ | explorer.exe | 
| http://www.microsoft.com/es/xl/ | explorer.exe | 
| http://www.microsoft.com/et-ee/ | explorer.exe | 
| http://www.microsoft.com/favicon.ico | iexplore.exe | 
| http://www.microsoft.com/fi-fi/ | explorer.exe | 
| http://www.microsoft.com/fr-be/ | explorer.exe | 
| http://www.microsoft.com/fr-ca/ | explorer.exe | 
| http://www.microsoft.com/fr-ch/ | explorer.exe | 
| http://www.microsoft.com/fr-dz/ | explorer.exe | 
| http://www.microsoft.com/fr-fr/ | explorer.exe | 
| http://www.microsoft.com/fr-ma/ | explorer.exe | 
| http://www.microsoft.com/fr-tn/ | explorer.exe | 
| http://www.microsoft.com/fr/ioi// | explorer.exe | 
| http://www.microsoft.com/fr/wca/ | explorer.exe | 
| http://www.microsoft.com/fr/xf/ | explorer.exe | 
| http://www.microsoft.com/hardware/en-us | explorer.exe | 
| http://www.microsoft.com/he/il/ | explorer.exe | 
| http://www.microsoft.com/hr-hr/ | explorer.exe | 
| http://www.microsoft.com/hu-hu/ | explorer.exe | 
| http://www.microsoft.com/hy-am/ | explorer.exe | 
| http://www.microsoft.com/investor | explorer.exe | 
| http://www.microsoft.com/is-is/ | explorer.exe | 
| http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome | iexplore.exe | 
| http://www.microsoft.com/it-it/ | explorer.exe | 
| http://www.microsoft.com/ja-jp/ | explorer.exe | 
| http://www.microsoft.com/ka-ge/ | explorer.exe | 
| http://www.microsoft.com/ko-kr/ | explorer.exe | 
| http://www.microsoft.com/learning/en/us/default.aspx | explorer.exe | 
| http://www.microsoft.com/library/toolbar/3.0/trademarks/en-us.mspx | explorer.exe | 
| http://www.microsoft.com/licensing/default.aspx | explorer.exe | 
| http://www.microsoft.com/lt-lt/ | explorer.exe | 
| http://www.microsoft.com/lv-lv/ | explorer.exe | 
| http://www.microsoft.com/mk-mk/ | explorer.exe | 
| http://www.microsoft.com/nb-no/ | explorer.exe | 
| http://www.microsoft.com/nl-be/ | explorer.exe | 
| http://www.microsoft.com/nl-nl/ | explorer.exe | 
| http://www.microsoft.com/pl-pl/ | explorer.exe | 
| http://www.microsoft.com/pt-br/ | explorer.exe | 
| http://www.microsoft.com/pt-pt/ | explorer.exe | 
| http://www.microsoft.com/ro-md/ | explorer.exe | 
| http://www.microsoft.com/ro-ro/ | explorer.exe | 
| http://www.microsoft.com/ru-ru/ | explorer.exe | 
| http://www.microsoft.com/ru/kz/ | explorer.exe | 
| http://www.microsoft.com/schemas/rss/core/2005 | iexplore.exe | 
| http://www.microsoft.com/schemas/rss/core/2005/internal | iexplore.exe | 
| http://www.microsoft.com/security/;icon-uri=http://www.microsoft.com/favicon.ico | explorer.exe | 
| http://www.microsoft.com/security/default.aspx | explorer.exe | 
| http://www.microsoft.com/security/pc-security/malware-removal.aspx | explorer.exe | 
| http://www.microsoft.com/servers/en/us/default.aspx | explorer.exe | 
| http://www.microsoft.com/servers/home.mspx | explorer.exe | 
| http://www.microsoft.com/sk-sk/ | explorer.exe | 
| http://www.microsoft.com/sl-si/ | explorer.exe | 
| http://www.microsoft.com/sq-al/ | explorer.exe | 
| http://www.microsoft.com/sr-latn-me/ | explorer.exe | 
| http://www.microsoft.com/sr-latn-rs/ | explorer.exe | 
| http://www.microsoft.com/surface/en/us/default.aspx | explorer.exe | 
| http://www.microsoft.com/sv-se/ | explorer.exe | 
| http://www.microsoft.com/th-th/ | explorer.exe | 
| http://www.microsoft.com/tr-tr/ | explorer.exe | 
| http://www.microsoft.com/uk-ua/ | explorer.exe | 
| http://www.microsoft.com/vi-vn/ | explorer.exe | 
| http://www.microsoft.com/visualstudio/en-us | explorer.exe | 
| http://www.microsoft.com/windowsphone/en-us/default.aspx | explorer.exe | 
| http://www.microsoft.com/windowsphone/en-us/howto/wp7/default.aspx?wt.mc_id=mscom_en_us_hp_supporthome_131p4enus21973 | explorer.exe | 
| http://www.microsoft.com/windowsxp/expertzone/ | iexplore.exe | 
| http://www.microsoft.com/zh-cn/ | explorer.exe | 
| http://www.microsoft.com/zh-hk/ | explorer.exe | 
| http://www.microsoft.com/zh-tw/ | explorer.exe | 
| http://www.microsoftbusinesshub.com/ | explorer.exe | 
| http://www.microsoftbusinesshub.com/products | explorer.exe | 
| http://www.microsoftstore.com/ | explorer.exe | 
| http://www.microsoftstore.com/store/msstore/cat/categoryid.44066900 | explorer.exe | 
| http://www.microsoftstore.com/store/msstore/home?wt.mc_id=mscom_hp_us_nav_buyms | explorer.exe | 
| http://www.msn.com/ | explorer.exe | 
| http://www.mtv.com/ | iexplore.exe | 
| http://www.mtv.com/favicon.ico | iexplore.exe | 
| http://www.myspace.com/favicon.ico | iexplore.exe | 
| http://www.najdi.si/ | iexplore.exe | 
| http://www.najdi.si/favicon.ico | iexplore.exe | 
| http://www.nate.com/favicon.ico | iexplore.exe | 
| http://www.neckermann.de/ | iexplore.exe | 
| http://www.neckermann.de/favicon.ico | iexplore.exe | 
| http://www.news.com.au/favicon.ico | iexplore.exe | 
| http://www.nifty.com/favicon.ico | iexplore.exe | 
| http://www.ocn.ne.jp/favicon.ico | iexplore.exe | 
| http://www.orange.fr/ | iexplore.exe | 
| http://www.otto.de/favicon.ico | iexplore.exe | 
| http://www.ozon.ru/ | iexplore.exe | 
| http://www.ozon.ru/favicon.ico | iexplore.exe | 
| http://www.ozu.es/favicon.ico | iexplore.exe | 
| http://www.paginasamarillas.es/ | iexplore.exe | 
| http://www.paginasamarillas.es/favicon.ico | iexplore.exe | 
| http://www.pchome.com.tw/favicon.ico | iexplore.exe | 
| http://www.priceminister.com/ | iexplore.exe | 
| http://www.priceminister.com/favicon.ico | iexplore.exe | 
| http://www.quovadisglobal.com/cps0 | iexplore.exe | 
| http://www.rakuten.co.jp/favicon.ico | iexplore.exe | 
| http://www.rambler.ru/ | iexplore.exe | 
| http://www.rambler.ru/favicon.ico | iexplore.exe | 
| http://www.recherche.aol.fr/ | iexplore.exe | 
| http://www.rtl.de/ | iexplore.exe | 
| http://www.rtl.de/favicon.ico | iexplore.exe | 
| http://www.servicios.clarin.com/ | iexplore.exe | 
| http://www.shopzilla.com/ | iexplore.exe | 
| http://www.sify.com/favicon.ico | iexplore.exe | 
| http://www.skype.com/ | iexplore.exe | 
| http://www.skype.com/go/download | iexplore.exe | 
| http://www.skype.com/go/help.guides.ieaddon?lang=en | iexplore.exe | 
| http://www.skype.com/intl/en-us/home/ | explorer.exe | 
| http://www.so-net.ne.jp/share/favicon.ico | iexplore.exe | 
| http://www.sogou.com/ | iexplore.exe | 
| http://www.sogou.com/favicon.ico | iexplore.exe | 
| http://www.soso.com/ | iexplore.exe | 
| http://www.soso.com/favicon.ico | iexplore.exe | 
| http://www.t-online.de/favicon.ico | iexplore.exe | 
| http://www.taobao.com/ | iexplore.exe | 
| http://www.taobao.com/favicon.ico | iexplore.exe | 
| http://www.target.com/ | iexplore.exe | 
| http://www.target.com/favicon.ico | iexplore.exe | 
| http://www.tchibo.de/ | iexplore.exe | 
| http://www.tchibo.de/favicon.ico | iexplore.exe | 
| http://www.tesco.com/ | iexplore.exe | 
| http://www.tesco.com/favicon.ico | iexplore.exe | 
| http://www.timesonline.co.uk/img/favicon.ico | iexplore.exe | 
| http://www.tiscali.it/favicon.ico | iexplore.exe | 
| http://www.trustcenter.de/guidelines0 | iexplore.exe | 
| http://www.univision.com/ | iexplore.exe | 
| http://www.univision.com/favicon.ico | iexplore.exe | 
| http://www.update.microsoft.com/microsoftupdate | explorer.exe | 
| http://www.update.microsoft.com/microsoftupdate/v6/vistadefault.aspx?ln=en-us | explorer.exe | 
| http://www.valicert.com/1 | iexplore.exe | 
| http://www.w3.org/1999/02/22-rdf-syntax-ns# | iexplore.exe | 
| http://www.w3.org/1999/xhtml | iexplore.exe | 
| http://www.w3.org/1999/xsl/transform | iexplore.exe | 
| http://www.w3.org/2005/atom | iexplore.exe | 
| http://www.w3.org/tr/html4/loose.dtd | iexplore.exe | 
| http://www.w3.org/tr/html4/strict.dtd | iexplore.exe | 
| http://www.w3.org/tr/html401/strict.dtd | iexplore.exe | 
| http://www.w3.org/tr/rec-html40/strict.dtd | iexplore.exe | 
| http://www.w3.org/tr/wd-xsl | iexplore.exe | 
| http://www.w3.org/tr/xhtml1/dtd/xhtml1-transitional.dtd | iexplore.exe | 
| http://www.walmart.com/ | iexplore.exe | 
| http://www.walmart.com/favicon.ico | iexplore.exe | 
| http://www.weather.com/ | iexplore.exe | 
| http://www.weather.com/favicon.ico | iexplore.exe | 
| http://www.windowsazure.com/en-us/ | explorer.exe | 
| http://www.windowsphone.com/en-us/marketplace | explorer.exe | 
| http://www.xbox.com/ | explorer.exe | 
| http://www.xbox.com/en-us/ | explorer.exe | 
| http://www.ya.com/favicon.ico | iexplore.exe | 
| http://www.yam.com/favicon.ico | iexplore.exe | 
| http://www.yandex.ru/ | iexplore.exe | 
| http://www.yandex.ru/favicon.ico | iexplore.exe | 
| http://www.youtube.com/?tab=w1&gl=fr | iexplore.exe, google_fr[1].txt.dr | 
| http://www.zune.net/en-us/ | explorer.exe | 
| http://www3.fnac.com/ | iexplore.exe | 
| http://www3.fnac.com/favicon.ico | iexplore.exe | 
| http://xml-us.amznxslt.com/onca/xml?service=awsecommerceservice&version=2008-06-26&operation=itemsearch&awsaccesskeyid=15hrv3azsmpk0gxty102&associatetag=ie8suggestion-20&responsegroup=itemattributes | iexplore.exe | 
| http://yellowpages.superpages.com/ | iexplore.exe | 
| http://z.about.com/m/a08.ico | iexplore.exe | 
| https://accounts.google.com/login?hl= | iexplore.exe, rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1].dr | 
| https://accounts.google.com/servicelogin?hl=fr&cont | iexplore.exe | 
| https://accounts.google.com/servicelogin?hl=fr&continue=http://www.google.fr/ | iexplore.exe, google_fr[1].txt.dr | 
| https://apis.google.com | iexplore.exe, google_fr[1].txt.dr | 
| https://bankieren.rabobank.nl/klanten/static/javascript/productoverview.js | iexplore.exe | 
| https://ca.sia.it/seccli/repository/cps0 | iexplore.exe | 
| https://ca.sia.it/secsrv/repository/cps0 | iexplore.exe | 
| https://docs.google.com/?tab=wo | iexplore.exe, google_fr[1].txt.dr | 
| https://example.com | iexplore.exe | 
| https://ib.nab.com.au/nabib/scripts/jquery.js | iexplore.exe | 
| https://ieonline.microsoft.com/#ieslice | iexplore.exe | 
| https://ieonline.microsoft.com/favicon.ico | iexplore.exe | 
| https://ieonlinews.microsoft.com/ | iexplore.exe | 
| https://mail.google.com/mail/?tab=wm | iexplore.exe, google_fr[1].txt.dr | 
| https://mijn.ing.nl/internetbankieren/jsp/indexlogon.jsp | iexplore.exe | 
| https://mijn.ing.nl/internetbankieren/jsp/sesam_cockpit.jsp | iexplore.exe | 
| https://nl.ibloxs.com/files/images/loading2.gif | iexplore.exe | 
| https://partner.microsoft.com/u | explorer.exe | 
| https://partner.microsoft.com/us/30000104 | explorer.exe | 
| https://play.google.com | iexplore.exe | 
| https://play.google.com/?hl=fr&tab=w8 | iexplore.exe, google_fr[1].txt.dr | 
| https://plus.google.com/1069014 | iexplore.exe | 
| https://plus.google.com/106901486880272202822 | iexplore.exe, google_fr[1].txt.dr | 
| https://plus.google.com/?gpsrc=ogpy0&tab=wx | iexplore.exe, google_fr[1].txt.dr | 
| https://plusone.google.com/u/0 | iexplore.exe, google_fr[1].txt.dr | 
| https://profile.microsoft.com/regsysprofilecenter/default.aspx?lcid=1033 | explorer.exe | 
| https://roomitstat.com/m/11/u/20/jsapi/ | iexplore.exe | 
| https://roomitstat.com/m/13/u/20/jsapi/ | iexplore.exe | 
| https://roomitstat.com/media/files/pixel.gif | iexplore.exe | 
| https://roomitstat.com/src/ongyjmck/ | iexplore.exe | 
| https://roomitstat.com/src/qewaohwv/ | iexplore.exe | 
| https://roomitstat.com/src/tmbmpycf/ | iexplore.exe | 
| https://roomitstat.com/src/wsvixxmm/ | iexplore.exe | 
| https://roomitstat.com/src/zufwdzhr/ | iexplore.exe | 
| https://secure.comodo.com/cps0 | iexplore.exe | 
| https://serveseriono.com/abc-sec/scripts/abnam-ro/core.js | iexplore.exe | 
| https://serveseriono.com/abc-sec/scripts/abnam-ro/jquery.js | iexplore.exe | 
| https://www.abnamro.nl/ | iexplore.exe | 
| https://www.google.com/ | iexplore.exe | 
| https://www.google.com/calendar?tab=wc | iexplore.exe, google_fr[1].txt.dr | 
| https://www.netlock.net/docs | iexplore.exe | 
| https://www.snsbank.nl/mijnsns/homepage/ | iexplore.exe | 
| https://www.snsbank.nl/mijnsns/js_public/jquery-1.6.2.min.js | iexplore.exe | 
| https://www.verisign.com/cps0 | iexplore.exe | 
| https://www.verisign.com/repository/cps | iexplore.exe | 
| https://www.verisign.com/repository/verisignlogo.gif0d | iexplore.exe | 
| https://www.verisign.com/rpa | iexplore.exe, 0797C381B2F87EB5A1D5573BD15BA4F40.dr | 
| https://www.verisign.com/rpa0 | iexplore.exe | 
| https://www.verisign.com; | iexplore.exe | 
| Social media names | |
| String value | Source | 
| <li id="ctl00_ctl14_ItemsRepeater_ctl00_Level2Columns_ctl01_Level2Repeater_ctl00_Level2Li" class="Last"><h3 class="hpFeat_Wrap msMnu_Level2Cat noLink" bi:titleflag="item" bi:title="item">More products</h3><ul id="ctl00_ctl14_ItemsRepeater_ctl00_Level2Columns_ctl01_Level2Repeater_ctl00_Level3List" class="msMnu_Level3" bi:parenttitle="item" bi:index="0"><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:cpid="hpMenu" bi:index="0" href="http://www.microsoft.com/surface/en/us/default.aspx">Surface</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:cpid="hpMenu" bi:index="1" href="http://www.microsoft.com/windowsphone/en-us/default.aspx">Windows Phone</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:cpid="hpMenu" bi:index="2" href="http://www.xbox.com/">Xbox</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:cpid="hpMenu" bi:index="3" href="http://windows.microsoft.com/en-US/internet-explorer/products/ie/home">Internet Explorer</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:cpid="hpMenu" bi:index="4" href="http://www.skype.com/intl/en-us/home/">Skype</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:cpid="hpMenu" bi:index="5" href="http://www.bing.com/">Bing</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:cpid="hpMenu" bi:index="6" href="http://windows.microsoft.com/en-US/skydrive/home">SkyDrive</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:cpid="hpMenu" bi:index="7" href="http://windows.microsoft.com/en-US/hotmail/home">Hotmail</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:cpid="hpMenu" bi:index="8" href="http://www.microsoft.com/hardware/en-us">PC hardware</a></li><li ><a class="hpFeat_Link msMnu_Level3_Lnk" bi:cpid="hpMenu" bi:index="9" href="http://www.zune.net/en-US/">Zune</a></li></ul></li> equals www.hotmail.com (Hotmail) | explorer.exe | 
| <SuggestionsURL>http://ie.search.yahoo.com/os?command={SearchTerms}</SuggestionsURL> equals www.yahoo.com (Yahoo) | iexplore.exe | 
| <FavoriteIcon>http://search.yahoo.co.jp/favicon.ico</FavoriteIcon> equals www.yahoo.com (Yahoo) | iexplore.exe | 
| <FavoriteIcon>http://search.yahoo.com/favicon.ico</FavoriteIcon> equals www.yahoo.com (Yahoo) | iexplore.exe | 
| <FavoriteIcon>http://www.facebook.com/favicon.ico</FavoriteIcon> equals www.facebook.com (Facebook) | iexplore.exe | 
| <FavoriteIcon>http://www.myspace.com/favicon.ico</FavoriteIcon> equals www.myspace.com (Myspace) | iexplore.exe | 
| <FavoriteIcon>http://www.rambler.ru/favicon.ico</FavoriteIcon> equals www.rambler.ru (Rambler) | iexplore.exe | 
| <URL>http://br.search.yahoo.com/</URL> equals www.yahoo.com (Yahoo) | iexplore.exe | 
| <URL>http://de.search.yahoo.com/</URL> equals www.yahoo.com (Yahoo) | iexplore.exe | 
| <URL>http://es.search.yahoo.com/</URL> equals www.yahoo.com (Yahoo) | iexplore.exe | 
| <URL>http://espanol.search.yahoo.com/</URL> equals www.yahoo.com (Yahoo) | iexplore.exe | 
| <URL>http://fr.search.yahoo.com/</URL> equals www.yahoo.com (Yahoo) | iexplore.exe | 
| <URL>http://in.search.yahoo.com/</URL> equals www.yahoo.com (Yahoo) | iexplore.exe | 
| <URL>http://it.search.yahoo.com/</URL> equals www.yahoo.com (Yahoo) | iexplore.exe | 
| <URL>http://kr.search.yahoo.com/</URL> equals www.yahoo.com (Yahoo) | iexplore.exe | 
| <URL>http://ru.search.yahoo.com</URL> equals www.yahoo.com (Yahoo) | iexplore.exe | 
| <URL>http://sads.myspace.com/</URL> equals www.myspace.com (Myspace) | iexplore.exe | 
| <URL>http://search.cn.yahoo.com/</URL> equals www.yahoo.com (Yahoo) | iexplore.exe | 
| <URL>http://search.yahoo.co.jp</URL> equals www.yahoo.com (Yahoo) | iexplore.exe | 
| <URL>http://search.yahoo.com/</URL> equals www.yahoo.com (Yahoo) | iexplore.exe | 
| <URL>http://tw.search.yahoo.com/</URL> equals www.yahoo.com (Yahoo) | iexplore.exe | 
| <URL>http://uk.search.yahoo.com/</URL> equals www.yahoo.com (Yahoo) | iexplore.exe | 
| <URL>http://www.facebook.com/</URL> equals www.facebook.com (Facebook) | iexplore.exe | 
| <URL>http://www.rambler.ru/</URL> equals www.rambler.ru (Rambler) | iexplore.exe | 
| .ebuddy. equals www.ebuddy.com (eBuggy) | globpluginspipe.dr | 
| .facebook. equals www.facebook.com (Facebook) | globpluginspipe.dr | 
| .yahoo. equals www.yahoo.com (Yahoo) | iexplore.exe | 
| /?hl=fr&tab=w8"><span class=gbtb2></span><span class=gbts>Play</span></a></li><li class=gbt><a onclick=gbar.qs(this);gbar.logger.il(1,{t:36}); class=gbzt id=gb_36 href="http://www.youtube.com/?tab=w1&gl=FR"><span class=gbtb2></span><span class=gbts>YouTube</span></a></li><li class=gbt><a onclick=gbar.logger.il(1,{t:5}); class=gbzt id=gb_5 href="http://news.google.fr/nwshp?hl=fr&tab=wn"><span class=gbtb2></span><span class=gbts>Actualit equals www.youtube.com (Youtube) | iexplore.exe | 
| Free Hotmail.url equals www.hotmail.com (Hotmail) | iexplore.exe | 
| YUEvent = YAHOO.util.Event equals www.yahoo.com (Yahoo) | iexplore.exe | 
| YouTube equals www.youtube.com (Youtube) | iexplore.exe | 
| google.promos.mgmhp.initPulldown(rlz,logParams);});})();</script> </div><div id="mngb"><div id=gb><script>window.gbar&&gbar.eli&&gbar.eli()</script><div id=gbw><div id=gbzw><div id=gbz><span class=gbtcb></span><ol id=gbzc class=gbtc><li class=gbt><a onclick=gbar.logger.il(1,{t:119}); class=gbzt id=gb_119 href="https://plus.google.com/?gpsrc=ogpy0&tab=wX"><span class=gbtb2></span><span class=gbts>+Vous</span></a></li><li class=gbt><a onclick=gbar.logger.il(1,{t:1}); class="gbzt gbz0l gbp1" id=gb_1 href="http://www.google.fr/webhp?hl=fr&tab=ww"><span class=gbtb2></span><span class=gbts>Recherche</span></a></li><li class=gbt><a onclick=gbar.qs(this);gbar.logger.il(1,{t:2}); class=gbzt id=gb_2 href="http://www.google.fr/imghp?hl=fr&tab=wi"><span class=gbtb2></span><span class=gbts>Images</span></a></li><li class=gbt><a onclick=gbar.qs(this);gbar.logger.il(1,{t:8}); class=gbzt id=gb_8 href="http://maps.google.fr/maps?hl=fr&tab=wl"><span class=gbtb2></span><span class=gbts>Maps</span></a></li><li class=gbt><a onclick=gbar.logger.il(1,{t:78}); class=gbzt id=gb_78 href="https://play.google.com/?hl=fr&tab=w8"><span class=gbtb2></span><span class=gbts>Play</span></a></li><li class=gbt><a onclick=gbar.qs(this);gbar.logger.il(1,{t:36}); class=gbzt id=gb_36 href="http://www.youtube.com/?tab=w1&gl=FR"><span class=gbtb2></span><span class=gbts>YouTube</span></a></li><li class=gbt><a onclick=gbar.logger.il(1,{t:5}); class=gbzt id=gb_5 href="http://news.google.fr/nwshp?hl=fr&tab=wn"><span class=gbtb2></span><span class=gbts>Actualit equals www.youtube.com (Youtube) | google_fr[1].txt.dr | 
| http://www.youtube.com/?tab=w1&gl=FR equals www.youtube.com (Youtube) | iexplore.exe | 
| ing.myspace.co equals www.myspace.com (Myspace) | iexplore.exe | 
| login.yahoo.com equals www.yahoo.com (Yahoo) | iexplore.exe | 
| login.yahoo.com0 equals www.yahoo.com (Yahoo) | iexplore.exe | 
| messaging.myspace.com equals www.myspace.com (Myspace) | iexplore.exe | 
| profile.myspace.com/Modules/Applications/ equals www.myspace.com (Myspace) | iexplore.exe | 
| trator@http://www.youtube.com/?tab=w1&gl=FR equals www.youtube.com (Youtube) | iexplore.exe | 
| www.login.yahoo.com0 equals www.yahoo.com (Yahoo) | iexplore.exe | 
| www.youtube.com equals www.youtube.com (Youtube) | iexplore.exe | 
| youtube equals www.youtube.com (Youtube) | iexplore.exe | 
| youtube.com equals www.youtube.com (Youtube) | iexplore.exe | 
| Bank names | |
| String value | Source | 
| "https://www.abnamro.nl/*" GP equals www.abnamro.com.pk (ABN AMRO Pakistan) | winlogon.exe | 
| https://*.standardchartered.com/js/global.js* equals www.standardchartered.com (Standard Chartered Bank) | iexplore.exe | 
| https://*ingbank.nl/* equals www.ingbank.nl (ING Bank Netherlands) | iexplore.exe | 
| https://www.abnamro.nl/* equals www.abnamro.com.pk (ABN AMRO Pakistan) | iexplore.exe | 
| https://www.abnamro.nl/*/framekiller.js equals www.abnamro.com.pk (ABN AMRO Pakistan) | iexplore.exe | 
| https://www.abnamro.nl/*/menu/scripts/IB_menu.js equals www.abnamro.com.pk (ABN AMRO Pakistan) | iexplore.exe | 
| set_url "https://www.abnamro.nl/* equals www.abnamro.com.pk (ABN AMRO Pakistan) | msiexec.exe | 
| set_url "https://www.abnamro.nl/*" GP equals www.abnamro.com.pk (ABN AMRO Pakistan) | iexplore.exe | 
| set_url "https://www.abnamro.nl/*/framekiller.js equals www.abnamro.com.pk (ABN AMRO Pakistan) | winlogon.exe, svchost.exe, jqs.exe, msiexec.exe | 
| set_url "https://www.abnamro.nl/*/framekiller.js" GP equals www.abnamro.com.pk (ABN AMRO Pakistan) | iexplore.exe | 
| set_url "https://www.abnamro.nl/*/menu/scripts/IB_menu.js equals www.abnamro.com.pk (ABN AMRO Pakistan) | winlogon.exe, svchost.exe, jqs.exe, msiexec.exe | 
| set_url "https://www.abnamro.nl/*/menu/scripts/IB_menu.js" GP equals www.abnamro.com.pk (ABN AMRO Pakistan) | iexplore.exe | 
| set_url https://*.standardchartered.c equals www.standardchartered.com (Standard Chartered Bank) | svchost.exe | 
| set_url https://*.standardchartered.com/js/global.js* GP equals www.standardchartered.com (Standard Chartered Bank) | iexplore.exe | 
| set_url https://*.standardchartered.com/js/global.js* equals www.standardchartered.com (Standard Chartered Bank) | winlogon.exe, jqs.exe, msiexec.exe | 
| set_url https://*ingbank.nl/* GPLHF equals www.ingbank.nl (ING Bank Netherlands) | iexplore.exe | 
| set_url https://*ingbank.nl/* equals www.ingbank.nl (ING Bank Netherlands) | winlogon.exe, svchost.exe, jqs.exe, msiexec.exe | 
| t_url "https://www.abnamro.nl/* equals www.abnamro.com.pk (ABN AMRO Pakistan) | iexplore.exe | 
Analysis Overview
| Startup | |
| 
 
 
 | |
| Dropped Files | |
| File Path | MD5 | 
| C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF2E3B.tmp | 58BA7A67BD18C3701F84C233BABFE811 | 
| C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF3ED3.tmp | 70A2C42DA68990E1E6BB9CDC0FDA31FC | 
| C:\Documents and Settings\Administrator\Application Data\Microsoft\CryptnetUrlCache\Content\0797C381B2F87EB5A1D5573BD15BA4F4 | DFDF3FCC73C3D79D960A4BF0142E270B | 
| C:\Documents and Settings\Administrator\Application Data\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5 | F7129BD2F205ED6146BB1342D12C903F | 
| C:\Documents and Settings\Administrator\Application Data\Microsoft\CryptnetUrlCache\MetaData\0797C381B2F87EB5A1D5573BD15BA4F4 | 7C490DB616DD204E67CB91482EA6840C | 
| C:\Documents and Settings\Administrator\Application Data\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5 | 76BDE78999196BEC5C59F48142263C9B | 
| C:\Documents and Settings\Administrator\Cookies\administrator@google[1].txt | 7D04A67BFE246E09247D48720799B4C5 | 
| C:\Documents and Settings\Administrator\Cookies\administrator@google[2].txt | 83DCCFB295A499C66B1E6519E35211EC | 
| C:\Documents and Settings\Administrator\Cookies\administrator@google[3].txt | 9034C308F0C9FD7B6170B2038648B480 | 
| C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\T0DFTGB2\www.google[1].xml | 8C1A9C229612D01B5F762EB5CF1B46B7 | 
| C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.dat | 000A2C9A7F0CA8B7AABE3EEF315E7E33 | 
| C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{0DD04C9E-4667-11E1-97AA-08002763FBB4}.dat | 25F93609D1520C7576EB074D09FCE929 | 
| C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\3FZRZ9KZ\logo3w[1].png | 169E859DB7F28A01E1B51E1C9E2D6B2B | 
| C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\3FZRZ9KZ\mgyhp_sm[1].png | 6EFE849BCCA95A1036A846F618FDE913 | 
| C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\3FZRZ9KZ\tia[1].png | AD07EE4CB98DA073DDA56CE7CEB88F5A | 
| C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js | 0FA09E7314A4BAC8093E64309A152A19 | 
| C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\chrome-48[1].png | 3FE84B8B53D7401B32FABD0C70F211BB | 
| C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\google_fr[1].txt | 9587C00152120E2E6CAA85BA12DEAD70 | 
| C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\j_e6a6aca6[1].png | E6A6ACA6F0BF41491306FB48C5CBC2EF | 
| C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\favicon[1].ico | 09B565A51E14B721A323F0BA44B2982A | 
| C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\nav_logo107[1].png | 92D80817414D8985DE1DCC4425754D66 | 
| C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\swxa[1].gif | 72630BE6F3743631E1FC2C53F8F25344 | 
| C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] | 6C9F39E8946018FB1631E818F9668EAE | 
| C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js | FEED2A2E2D54CD5F40FB4B5F5244FFF2 | 
| C:\Recycle.Bin\5CBD14A05E0D693 | 32DEA343CA0ADD98E441EEAFF6F28D22 | 
| C:\Recycle.Bin\B6232F3AC2C.exe | 6F7E68AC83FB111653E2093C17D46B21 | 
| C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf | B4B8B02DB9E43A95A0D61B24D68C4581 | 
| C:\WINDOWS\system32\wbem\Logs\wmiprov.log | A38C53660FC2B34F46B6C360DF872E22 | 
| \ROUTER | 8D7564381D943011C644C48017C9F2F0 | 
| \globpluginspipe | 087A51F1B049EB817D817863AAE5297C | 
| \lsass | 3182E954630821EC0EA6E440419D3864 | 
Global Network Data
| All TCP | ||||
| Timestamp | Source Port | Dest Port | Source IP | Dest IP | 
| Jul 2, 2012 20:03:43.598177910 CEST | 1039 | 1427 | 192.168.0.10 | 92.241.162.53 | 
| Jul 2, 2012 20:03:43.598207951 CEST | 1427 | 1039 | 92.241.162.53 | 192.168.0.10 | 
| Jul 2, 2012 20:03:43.598546028 CEST | 1039 | 1427 | 192.168.0.10 | 92.241.162.53 | 
| Jul 2, 2012 20:03:43.600795031 CEST | 1039 | 1427 | 192.168.0.10 | 92.241.162.53 | 
| Jul 2, 2012 20:03:43.600810051 CEST | 1427 | 1039 | 92.241.162.53 | 192.168.0.10 | 
| Jul 2, 2012 20:03:43.608885050 CEST | 1039 | 1427 | 192.168.0.10 | 92.241.162.53 | 
| Jul 2, 2012 20:03:43.608942032 CEST | 1427 | 1039 | 92.241.162.53 | 192.168.0.10 | 
| Jul 2, 2012 20:03:43.609213114 CEST | 1039 | 1427 | 192.168.0.10 | 92.241.162.53 | 
| Jul 2, 2012 20:03:58.935945034 CEST | 1042 | 80 | 192.168.0.10 | 173.194.69.106 | 
| Jul 2, 2012 20:03:58.935976982 CEST | 80 | 1042 | 173.194.69.106 | 192.168.0.10 | 
| Jul 2, 2012 20:03:58.936338902 CEST | 1042 | 80 | 192.168.0.10 | 173.194.69.106 | 
| Jul 2, 2012 20:03:58.942425013 CEST | 1042 | 80 | 192.168.0.10 | 173.194.69.106 | 
| Jul 2, 2012 20:03:58.942440033 CEST | 80 | 1042 | 173.194.69.106 | 192.168.0.10 | 
| Jul 2, 2012 20:03:59.596462965 CEST | 80 | 1042 | 173.194.69.106 | 192.168.0.10 | 
| Jul 2, 2012 20:03:59.656255960 CEST | 80 | 1042 | 173.194.69.106 | 192.168.0.10 | 
| Jul 2, 2012 20:03:59.656788111 CEST | 1042 | 80 | 192.168.0.10 | 173.194.69.106 | 
| Jul 2, 2012 20:03:59.656809092 CEST | 80 | 1042 | 173.194.69.106 | 192.168.0.10 | 
| Jul 2, 2012 20:03:59.838814020 CEST | 1042 | 80 | 192.168.0.10 | 173.194.69.106 | 
| Jul 2, 2012 20:04:00.690382957 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:00.690416098 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:00.690773010 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:00.695569992 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:00.695585966 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:01.531971931 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:01.607877016 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:01.608283997 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:01.608304024 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:01.608309984 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:01.608715057 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:01.652854919 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:01.653129101 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:01.653143883 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:01.655642033 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:01.656053066 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:01.656066895 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:01.675091982 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:01.675400972 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:01.675412893 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:01.696902037 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:01.697268963 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:01.697283983 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:01.780771971 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:01.780790091 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:01.836039066 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:01.836302996 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:01.836319923 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:01.836606026 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:01.858313084 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:01.951930046 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:01.952116966 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:01.952136993 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:02.006422043 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:02.006676912 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:02.006692886 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:02.006714106 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:02.031719923 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:02.032643080 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:02.078569889 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:02.078859091 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:02.078876972 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:02.246087074 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:02.602509022 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:02.602529049 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:02.610963106 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:02.610987902 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:02.611186028 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:02.612231016 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:02.612245083 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:03.028846979 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:03.085880041 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:03.086214066 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:03.086235046 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:03.132586956 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:03.132603884 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:03.504678965 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:03.631467104 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:03.669061899 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:03.669080019 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:03.740099907 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:03.740374088 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:03.740391970 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:03.740614891 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:03.740619898 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:03.740633965 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:03.740859032 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:03.886898041 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:03.887018919 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:05.217415094 CEST | 1045 | 80 | 192.168.0.10 | 199.7.71.190 | 
| Jul 2, 2012 20:04:05.217444897 CEST | 80 | 1045 | 199.7.71.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:05.217648029 CEST | 1045 | 80 | 192.168.0.10 | 199.7.71.190 | 
| Jul 2, 2012 20:04:05.218806982 CEST | 1045 | 80 | 192.168.0.10 | 199.7.71.190 | 
| Jul 2, 2012 20:04:05.218822002 CEST | 80 | 1045 | 199.7.71.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:05.682365894 CEST | 80 | 1045 | 199.7.71.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:05.853900909 CEST | 1045 | 80 | 192.168.0.10 | 199.7.71.190 | 
| Jul 2, 2012 20:04:05.853920937 CEST | 80 | 1045 | 199.7.71.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:06.084184885 CEST | 1045 | 80 | 192.168.0.10 | 199.7.71.190 | 
| Jul 2, 2012 20:04:07.207951069 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 
| Jul 2, 2012 20:04:07.207983971 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:07.208204031 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 
| Jul 2, 2012 20:04:07.210767984 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 
| Jul 2, 2012 20:04:07.210791111 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:07.919285059 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:07.955991983 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:07.956376076 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 
| Jul 2, 2012 20:04:07.956397057 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:07.977957964 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:07.978363037 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 
| Jul 2, 2012 20:04:08.105735064 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.106091976 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 
| Jul 2, 2012 20:04:08.109411955 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.124725103 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.125099897 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 
| Jul 2, 2012 20:04:08.125116110 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.131436110 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.131810904 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 
| Jul 2, 2012 20:04:08.131824970 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.169255972 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.169610977 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 
| Jul 2, 2012 20:04:08.169625044 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.176518917 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.176863909 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 
| Jul 2, 2012 20:04:08.176877975 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.191273928 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.191704988 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 
| Jul 2, 2012 20:04:08.202244997 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.224265099 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.224647999 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 
| Jul 2, 2012 20:04:08.224661112 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.225024939 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 
| Jul 2, 2012 20:04:08.231926918 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.254288912 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.254724979 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 
| Jul 2, 2012 20:04:08.254740953 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.334666014 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.335221052 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 
| Jul 2, 2012 20:04:08.335236073 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.364252090 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.364773035 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 
| Jul 2, 2012 20:04:08.376440048 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.376961946 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 
| Jul 2, 2012 20:04:08.388438940 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.388937950 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 
| Jul 2, 2012 20:04:08.396892071 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.396899939 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.397497892 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 
| Jul 2, 2012 20:04:08.397511959 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.398029089 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.398397923 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 
| Jul 2, 2012 20:04:08.398411036 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 
| Jul 2, 2012 20:04:08.588527918 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 
| Jul 2, 2012 20:04:09.968908072 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:09.968923092 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:10.024929047 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:10.024945021 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:10.345019102 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:10.345046043 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:10.345269918 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:10.348225117 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:10.348238945 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.225372076 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.246577024 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.246850014 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.246866941 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.247241020 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.247298956 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.269587994 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.282352924 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.282850981 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.282866001 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.283385038 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.283628941 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.283642054 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.305330038 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.305843115 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.305855989 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.306242943 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.313623905 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.318712950 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.319267988 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.319283009 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.319672108 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.327496052 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.340873957 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.341427088 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.341439962 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.341830015 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.348859072 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.355947018 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.356499910 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.356513023 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.398077965 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.398637056 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.398654938 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.399039030 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.432427883 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.432440996 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.577205896 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:11.577233076 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.577596903 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:11.580758095 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:11.580773115 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.651004076 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.704292059 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.797154903 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.797724962 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.797749996 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.806847095 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.807332039 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.807347059 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.851984024 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.852529049 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.852545023 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.869460106 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.870016098 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.870031118 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.870562077 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.873893976 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.873902082 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.874368906 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.889039040 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.908606052 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.909149885 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.909162998 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.909480095 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.909874916 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.909888029 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.938453913 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.938941002 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.938952923 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.955626965 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.956171989 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.956186056 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.960093021 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.960144997 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.960527897 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.960541010 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.960787058 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.963048935 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.963062048 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.963378906 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.971985102 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.993886948 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.994040012 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.994263887 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.994278908 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:11.994524956 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.994606972 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:11.995269060 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.002657890 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.002986908 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.003000021 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.003236055 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.009238005 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.019074917 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.019428968 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.019440889 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.024126053 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.024466991 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.024478912 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.024796963 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.024807930 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.039027929 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.039383888 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.039397955 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.046045065 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.046464920 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.046478033 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.059706926 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.060023069 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.060034990 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.060353994 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.079751015 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.080398083 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.080676079 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.080689907 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.099225044 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.102668047 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.102683067 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.108110905 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.111572027 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.111584902 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.115154028 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.126745939 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.128695011 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.136352062 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.137916088 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.144146919 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.144473076 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.144488096 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.161675930 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.162054062 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.162067890 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.163410902 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.163829088 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.163841963 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.181817055 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.182255030 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.182267904 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.202362061 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.202707052 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.202721119 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.202950954 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.203161955 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.203169107 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.203552961 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.203567028 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.214448929 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.214855909 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.214869022 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.222835064 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.223184109 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.223196983 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.243673086 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.243963957 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.243978024 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.250842094 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.251107931 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.251122952 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.254251003 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.254642010 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.254654884 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.273911953 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.274220943 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.274240017 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.274554968 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.278862000 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.294950008 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.295357943 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.295372963 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.295444965 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.295643091 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.295948029 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.295958996 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.301417112 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.301837921 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.301851034 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.321052074 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.321394920 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.321408987 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.323467016 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.323785067 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.323796034 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.332284927 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.332617998 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.332638979 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.332859993 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.338002920 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.345818996 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.349231958 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.349246025 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.387293100 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.387686968 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.387702942 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.388030052 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.388041019 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.390113115 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.390471935 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.390487909 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.403413057 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.403795004 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.403809071 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.404164076 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.409868956 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.418077946 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.418086052 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.418457985 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.421533108 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.421544075 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.424386978 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.424738884 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.424751997 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.424957991 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.425276995 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.425291061 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.448971033 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.449348927 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.449363947 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.449734926 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.450115919 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.450520039 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.450860977 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.450875044 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.480830908 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.481187105 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.481205940 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.481241941 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.481556892 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.481570005 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.503060102 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.503412008 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.503427029 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.506702900 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.525495052 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.525871992 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:12.525887966 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.525895119 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.526295900 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:12.526400089 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:12.551084995 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.556826115 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.557245016 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:12.557260036 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.557738066 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:12.558888912 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.560503006 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.567543030 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:12.573832989 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.574256897 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:12.574270964 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.574609995 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:12.635873079 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.842432022 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.842803955 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:13.327394962 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:13.346952915 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:13.584280014 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:13.584300041 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:13.617311954 CEST | 1042 | 80 | 192.168.0.10 | 173.194.69.106 | 
| Jul 2, 2012 20:04:13.617326021 CEST | 80 | 1042 | 173.194.69.106 | 192.168.0.10 | 
| Jul 2, 2012 20:04:13.744057894 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:13.744076967 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:13.784454107 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:13.784475088 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:13.883213043 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:13.964555025 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:13.965082884 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:13.965100050 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:13.965472937 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:13.987257957 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:13.991763115 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:13.992180109 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:13.992197037 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:13.993233919 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:14.018239975 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.031369925 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.031414986 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.031739950 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:14.031757116 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.043231010 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.043695927 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:14.043715000 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.043720961 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.044125080 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:14.051960945 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.064893961 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.065253019 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:14.065268040 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.086762905 CEST | 80 | 1042 | 173.194.69.106 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.132999897 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.133403063 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.133430958 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:14.133449078 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.133822918 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:14.133836031 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.165466070 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.165824890 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:14.165838003 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.166682005 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:14.187467098 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.187480927 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.187864065 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:14.187876940 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.194185972 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.194592953 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:14.194607019 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.209667921 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.210082054 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:14.210093975 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.275837898 CEST | 1042 | 80 | 192.168.0.10 | 173.194.69.106 | 
| Jul 2, 2012 20:04:14.310000896 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:14.310017109 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.385521889 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:14.385533094 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.385586977 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 
| Jul 2, 2012 20:04:14.607681990 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 
| Jul 2, 2012 20:04:14.614272118 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:14.716474056 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 
| Jul 2, 2012 20:04:30.615546942 CEST | 1050 | 80 | 192.168.0.10 | 173.194.69.99 | 
| Jul 2, 2012 20:04:30.615576029 CEST | 80 | 1050 | 173.194.69.99 | 192.168.0.10 | 
| Jul 2, 2012 20:04:30.615941048 CEST | 1050 | 80 | 192.168.0.10 | 173.194.69.99 | 
| Jul 2, 2012 20:04:30.618577003 CEST | 1050 | 80 | 192.168.0.10 | 173.194.69.99 | 
| Jul 2, 2012 20:04:30.618591070 CEST | 80 | 1050 | 173.194.69.99 | 192.168.0.10 | 
| Jul 2, 2012 20:04:30.638438940 CEST | 1051 | 80 | 192.168.0.10 | 173.194.69.147 | 
| Jul 2, 2012 20:04:30.638458014 CEST | 80 | 1051 | 173.194.69.147 | 192.168.0.10 | 
| Jul 2, 2012 20:04:30.638833046 CEST | 1051 | 80 | 192.168.0.10 | 173.194.69.147 | 
| Jul 2, 2012 20:04:30.642021894 CEST | 1051 | 80 | 192.168.0.10 | 173.194.69.147 | 
| Jul 2, 2012 20:04:30.642035007 CEST | 80 | 1051 | 173.194.69.147 | 192.168.0.10 | 
| Jul 2, 2012 20:04:31.459068060 CEST | 80 | 1050 | 173.194.69.99 | 192.168.0.10 | 
| Jul 2, 2012 20:04:31.545617104 CEST | 80 | 1051 | 173.194.69.147 | 192.168.0.10 | 
| Jul 2, 2012 20:04:31.666548014 CEST | 1050 | 80 | 192.168.0.10 | 173.194.69.99 | 
| Jul 2, 2012 20:04:31.666675091 CEST | 1051 | 80 | 192.168.0.10 | 173.194.69.147 | 
| All UDP | ||||
| Timestamp | Source Port | Dest Port | Source IP | Dest IP | 
| Jul 2, 2012 20:03:19.634973049 CEST | 61120 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:03:20.187199116 CEST | 53 | 61120 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:03:20.200793028 CEST | 51208 | 53 | 192.168.0.10 | 195.186.4.121 | 
| Jul 2, 2012 20:03:20.200853109 CEST | 53 | 51208 | 195.186.4.121 | 192.168.0.10 | 
| Jul 2, 2012 20:03:36.911964893 CEST | 56719 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:03:36.912050962 CEST | 53 | 56719 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:03:36.925652981 CEST | 51094 | 53 | 192.168.0.10 | 195.186.4.121 | 
| Jul 2, 2012 20:03:36.925681114 CEST | 53 | 51094 | 195.186.4.121 | 192.168.0.10 | 
| Jul 2, 2012 20:03:45.330770969 CEST | 63631 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:03:46.323252916 CEST | 63631 | 53 | 192.168.0.10 | 195.186.4.121 | 
| Jul 2, 2012 20:03:47.323080063 CEST | 63631 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:03:49.323508978 CEST | 63631 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:03:49.323910952 CEST | 63631 | 53 | 192.168.0.10 | 195.186.4.121 | 
| Jul 2, 2012 20:03:50.204643011 CEST | 53 | 63631 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:03:50.325241089 CEST | 53 | 63631 | 195.186.4.121 | 192.168.0.10 | 
| Jul 2, 2012 20:03:50.347255945 CEST | 53 | 63631 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:03:51.835757017 CEST | 58466 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:03:52.652427912 CEST | 53604 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:03:52.823400021 CEST | 58466 | 53 | 192.168.0.10 | 195.186.4.121 | 
| Jul 2, 2012 20:03:53.653381109 CEST | 53604 | 53 | 192.168.0.10 | 195.186.4.121 | 
| Jul 2, 2012 20:03:53.754273891 CEST | 53 | 58466 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:03:54.008047104 CEST | 53 | 63631 | 195.186.4.121 | 192.168.0.10 | 
| Jul 2, 2012 20:03:54.030069113 CEST | 53 | 63631 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:03:54.651412010 CEST | 53604 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:03:55.163966894 CEST | 53 | 58466 | 195.186.4.121 | 192.168.0.10 | 
| Jul 2, 2012 20:03:56.651685953 CEST | 53604 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:03:56.652255058 CEST | 53604 | 53 | 192.168.0.10 | 195.186.4.121 | 
| Jul 2, 2012 20:03:58.261976957 CEST | 53 | 53604 | 195.186.4.121 | 192.168.0.10 | 
| Jul 2, 2012 20:03:58.283910990 CEST | 53 | 53604 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:03:58.283945084 CEST | 53 | 53604 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:03:58.283973932 CEST | 53 | 53604 | 195.186.4.121 | 192.168.0.10 | 
| Jul 2, 2012 20:03:58.284003973 CEST | 53 | 53604 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:03:58.427973032 CEST | 64441 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:03:58.924629927 CEST | 53 | 64441 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:03:59.720899105 CEST | 63632 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:00.542463064 CEST | 63633 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:00.682996035 CEST | 53 | 63632 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:01.685765028 CEST | 63633 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:02.685579062 CEST | 63633 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:03.853359938 CEST | 52775 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:04.687407970 CEST | 63633 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:04.687835932 CEST | 63633 | 53 | 192.168.0.10 | 195.186.4.121 | 
| Jul 2, 2012 20:04:04.874731064 CEST | 52775 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:04.926287889 CEST | 53 | 63633 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:05.060086966 CEST | 53 | 63633 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:05.060549021 CEST | 63633 | 53 | 192.168.0.10 | 195.186.4.121 | 
| Jul 2, 2012 20:04:05.082056046 CEST | 53 | 63633 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:05.213291883 CEST | 53 | 52775 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:05.882652044 CEST | 51899 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:06.172941923 CEST | 53 | 52775 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:06.868124008 CEST | 53 | 51899 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:09.297158957 CEST | 53 | 63633 | 195.186.4.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:09.299439907 CEST | 53 | 63633 | 195.186.4.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:09.299468994 CEST | 53 | 63633 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:10.446734905 CEST | 57021 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:11.433229923 CEST | 57021 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:11.571012020 CEST | 53 | 57021 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:12.278769016 CEST | 53 | 57021 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:24.087856054 CEST | 49368 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:24.108073950 CEST | 59107 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:25.073632002 CEST | 49368 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:25.104787111 CEST | 59107 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:26.073851109 CEST | 49368 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:26.104685068 CEST | 59107 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:28.073496103 CEST | 49368 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:28.073900938 CEST | 49368 | 53 | 192.168.0.10 | 195.186.4.121 | 
| Jul 2, 2012 20:04:28.104861975 CEST | 59107 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:28.105267048 CEST | 59107 | 53 | 192.168.0.10 | 195.186.4.121 | 
| Jul 2, 2012 20:04:30.610111952 CEST | 53 | 49368 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:30.632275105 CEST | 53 | 59107 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:31.236272097 CEST | 53 | 49368 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:31.424006939 CEST | 53 | 59107 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:32.790303946 CEST | 53 | 49368 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:32.985280991 CEST | 53 | 59107 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:34.266618013 CEST | 53 | 49368 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:34.379714966 CEST | 53 | 49368 | 195.186.4.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:34.427088976 CEST | 53 | 59107 | 195.186.1.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:34.450025082 CEST | 53 | 59107 | 195.186.4.121 | 192.168.0.10 | 
| Jul 2, 2012 20:04:54.280107021 CEST | 58179 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:55.276139975 CEST | 58179 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:56.276381969 CEST | 58179 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:58.276968956 CEST | 58179 | 53 | 192.168.0.10 | 195.186.1.121 | 
| Jul 2, 2012 20:04:58.277539968 CEST | 58179 | 53 | 192.168.0.10 | 195.186.4.121 | 
| All ICMP | |||||
| Timestamp | Source IP | Dest IP | Checksum | Code | Type | 
| Jul 2, 2012 20:03:50.347618103 CEST | 192.168.0.10 | 195.186.1.121 | 831c | (Port unreachable) | Destination Unreachable | 
| Jul 2, 2012 20:03:54.008441925 CEST | 192.168.0.10 | 195.186.4.121 | 861c | (Port unreachable) | Destination Unreachable | 
| Jul 2, 2012 20:03:54.030389071 CEST | 192.168.0.10 | 195.186.1.121 | 831c | (Port unreachable) | Destination Unreachable | 
| Jul 2, 2012 20:03:55.164190054 CEST | 192.168.0.10 | 195.186.4.121 | 862f | (Port unreachable) | Destination Unreachable | 
| Jul 2, 2012 20:04:06.173224926 CEST | 192.168.0.10 | 195.186.1.121 | 832e | (Port unreachable) | Destination Unreachable | 
| Jul 2, 2012 20:04:09.297492027 CEST | 192.168.0.10 | 195.186.4.121 | 861c | (Port unreachable) | Destination Unreachable | 
| Jul 2, 2012 20:04:09.299806118 CEST | 192.168.0.10 | 195.186.4.121 | 861c | (Port unreachable) | Destination Unreachable | 
| Jul 2, 2012 20:04:09.299894094 CEST | 192.168.0.10 | 195.186.1.121 | 831c | (Port unreachable) | Destination Unreachable | 
| Jul 2, 2012 20:04:12.279110909 CEST | 192.168.0.10 | 195.186.1.121 | 832d | (Port unreachable) | Destination Unreachable | 
| Jul 2, 2012 20:04:31.236797094 CEST | 192.168.0.10 | 195.186.1.121 | 8362 | (Port unreachable) | Destination Unreachable | 
| Jul 2, 2012 20:04:31.424489975 CEST | 192.168.0.10 | 195.186.1.121 | 8362 | (Port unreachable) | Destination Unreachable | 
| Jul 2, 2012 20:04:32.790769100 CEST | 192.168.0.10 | 195.186.1.121 | 8362 | (Port unreachable) | Destination Unreachable | 
| Jul 2, 2012 20:04:32.985493898 CEST | 192.168.0.10 | 195.186.1.121 | 8362 | (Port unreachable) | Destination Unreachable | 
| Jul 2, 2012 20:04:34.266949892 CEST | 192.168.0.10 | 195.186.1.121 | 8362 | (Port unreachable) | Destination Unreachable | 
| Jul 2, 2012 20:04:34.379986048 CEST | 192.168.0.10 | 195.186.4.121 | 8662 | (Port unreachable) | Destination Unreachable | 
| Jul 2, 2012 20:04:34.427354097 CEST | 192.168.0.10 | 195.186.1.121 | 8362 | (Port unreachable) | Destination Unreachable | 
| Jul 2, 2012 20:04:34.450331926 CEST | 192.168.0.10 | 195.186.4.121 | 8662 | (Port unreachable) | Destination Unreachable | 
| DNS Query | |||||||
| Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | 
| Jul 2, 2012 20:03:20.200793028 CEST | 192.168.0.10 | 195.186.4.121 | 0x5826 | Standard query (0) | _LDAP._TCP | 33 | IN (0x0001) | 
| Jul 2, 2012 20:03:36.925652981 CEST | 192.168.0.10 | 195.186.4.121 | 0xa5cb | Standard query (0) | _LDAP._TCP | 33 | IN (0x0001) | 
| Jul 2, 2012 20:03:45.330770969 CEST | 192.168.0.10 | 195.186.1.121 | 0xc5af | Standard query (0) | hhotelst555.ru | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:03:46.323252916 CEST | 192.168.0.10 | 195.186.4.121 | 0xc5af | Standard query (0) | hhotelst555.ru | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:03:47.323080063 CEST | 192.168.0.10 | 195.186.1.121 | 0xc5af | Standard query (0) | hhotelst555.ru | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:03:49.323508978 CEST | 192.168.0.10 | 195.186.1.121 | 0xc5af | Standard query (0) | hhotelst555.ru | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:03:49.323910952 CEST | 192.168.0.10 | 195.186.4.121 | 0xc5af | Standard query (0) | hhotelst555.ru | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:03:52.652427912 CEST | 192.168.0.10 | 195.186.1.121 | 0x88c9 | Standard query (0) | hhotelst555.ru | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:03:53.653381109 CEST | 192.168.0.10 | 195.186.4.121 | 0x88c9 | Standard query (0) | hhotelst555.ru | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:03:54.651412010 CEST | 192.168.0.10 | 195.186.1.121 | 0x88c9 | Standard query (0) | hhotelst555.ru | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:03:56.651685953 CEST | 192.168.0.10 | 195.186.1.121 | 0x88c9 | Standard query (0) | hhotelst555.ru | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:03:56.652255058 CEST | 192.168.0.10 | 195.186.4.121 | 0x88c9 | Standard query (0) | hhotelst555.ru | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:03:58.427973032 CEST | 192.168.0.10 | 195.186.1.121 | 0x1cb0 | Standard query (0) | www.google.com | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:03:59.720899105 CEST | 192.168.0.10 | 195.186.1.121 | 0x9772 | Standard query (0) | www.google.fr | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:00.542463064 CEST | 192.168.0.10 | 195.186.1.121 | 0x7fb4 | Standard query (0) | hhotelst555.ru | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:01.685765028 CEST | 192.168.0.10 | 195.186.1.121 | 0x7fb4 | Standard query (0) | hhotelst555.ru | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:02.685579062 CEST | 192.168.0.10 | 195.186.1.121 | 0x7fb4 | Standard query (0) | hhotelst555.ru | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:03.853359938 CEST | 192.168.0.10 | 195.186.1.121 | 0x6f1c | Standard query (0) | crl.verisign.com | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:04.687407970 CEST | 192.168.0.10 | 195.186.1.121 | 0x7fb4 | Standard query (0) | hhotelst555.ru | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:04.687835932 CEST | 192.168.0.10 | 195.186.4.121 | 0x7fb4 | Standard query (0) | hhotelst555.ru | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:04.874731064 CEST | 192.168.0.10 | 195.186.1.121 | 0x6f1c | Standard query (0) | crl.verisign.com | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:05.060549021 CEST | 192.168.0.10 | 195.186.4.121 | 0x7fb4 | Standard query (0) | hhotelst555.ru | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:05.882652044 CEST | 192.168.0.10 | 195.186.1.121 | 0xcb27 | Standard query (0) | csc3-2009-2-crl.verisign.com | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:10.446734905 CEST | 192.168.0.10 | 195.186.1.121 | 0x1cc7 | Standard query (0) | ssl.gstatic.com | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:11.433229923 CEST | 192.168.0.10 | 195.186.1.121 | 0x1cc7 | Standard query (0) | ssl.gstatic.com | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:24.087856054 CEST | 192.168.0.10 | 195.186.1.121 | 0x51c0 | Standard query (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i1.ds.ipv6-exp.l.google.com | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:24.108073950 CEST | 192.168.0.10 | 195.186.1.121 | 0x4edd | Standard query (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i2.v4.ipv6-exp.l.google.com | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:25.073632002 CEST | 192.168.0.10 | 195.186.1.121 | 0x51c0 | Standard query (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i1.ds.ipv6-exp.l.google.com | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:25.104787111 CEST | 192.168.0.10 | 195.186.1.121 | 0x4edd | Standard query (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i2.v4.ipv6-exp.l.google.com | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:26.073851109 CEST | 192.168.0.10 | 195.186.1.121 | 0x51c0 | Standard query (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i1.ds.ipv6-exp.l.google.com | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:26.104685068 CEST | 192.168.0.10 | 195.186.1.121 | 0x4edd | Standard query (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i2.v4.ipv6-exp.l.google.com | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:28.073496103 CEST | 192.168.0.10 | 195.186.1.121 | 0x51c0 | Standard query (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i1.ds.ipv6-exp.l.google.com | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:28.073900938 CEST | 192.168.0.10 | 195.186.4.121 | 0x51c0 | Standard query (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i1.ds.ipv6-exp.l.google.com | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:28.104861975 CEST | 192.168.0.10 | 195.186.1.121 | 0x4edd | Standard query (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i2.v4.ipv6-exp.l.google.com | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:28.105267048 CEST | 192.168.0.10 | 195.186.4.121 | 0x4edd | Standard query (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i2.v4.ipv6-exp.l.google.com | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:54.280107021 CEST | 192.168.0.10 | 195.186.1.121 | 0x362b | Standard query (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.s1.v4.ipv6-exp.l.google.com | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:55.276139975 CEST | 192.168.0.10 | 195.186.1.121 | 0x362b | Standard query (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.s1.v4.ipv6-exp.l.google.com | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:56.276381969 CEST | 192.168.0.10 | 195.186.1.121 | 0x362b | Standard query (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.s1.v4.ipv6-exp.l.google.com | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:58.276968956 CEST | 192.168.0.10 | 195.186.1.121 | 0x362b | Standard query (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.s1.v4.ipv6-exp.l.google.com | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:58.277539968 CEST | 192.168.0.10 | 195.186.4.121 | 0x362b | Standard query (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.s1.v4.ipv6-exp.l.google.com | A (IP address) | IN (0x0001) | 
| DNS Answer | |||||||||
| Timestamp | Source IP | Dest IP | Trans ID | Replay Code | Name | CName | Address | Type | Class | 
| Jul 2, 2012 20:03:20.200853109 CEST | 195.186.4.121 | 192.168.0.10 | 0x5826 | Not Implemented (4) | _LDAP._TCP | none | none | 33 | IN (0x0001) | 
| Jul 2, 2012 20:03:36.925681114 CEST | 195.186.4.121 | 192.168.0.10 | 0xa5cb | Not Implemented (4) | _LDAP._TCP | none | none | 33 | IN (0x0001) | 
| Jul 2, 2012 20:03:50.204643011 CEST | 195.186.1.121 | 192.168.0.10 | 0xc5af | Server failure (2) | hhotelst555.ru | none | none | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:03:50.325241089 CEST | 195.186.4.121 | 192.168.0.10 | 0xc5af | Server failure (2) | hhotelst555.ru | none | none | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:03:50.347255945 CEST | 195.186.1.121 | 192.168.0.10 | 0xc5af | Server failure (2) | hhotelst555.ru | none | none | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:03:54.008047104 CEST | 195.186.4.121 | 192.168.0.10 | 0xc5af | Server failure (2) | hhotelst555.ru | none | none | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:03:54.030069113 CEST | 195.186.1.121 | 192.168.0.10 | 0xc5af | Server failure (2) | hhotelst555.ru | none | none | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:03:58.261976957 CEST | 195.186.4.121 | 192.168.0.10 | 0x88c9 | Server failure (2) | hhotelst555.ru | none | none | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:03:58.283910990 CEST | 195.186.1.121 | 192.168.0.10 | 0x88c9 | Server failure (2) | hhotelst555.ru | none | none | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:03:58.283945084 CEST | 195.186.1.121 | 192.168.0.10 | 0x88c9 | Server failure (2) | hhotelst555.ru | none | none | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:03:58.283973932 CEST | 195.186.4.121 | 192.168.0.10 | 0x88c9 | Server failure (2) | hhotelst555.ru | none | none | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:03:58.284003973 CEST | 195.186.1.121 | 192.168.0.10 | 0x88c9 | Server failure (2) | hhotelst555.ru | none | none | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:03:58.924629927 CEST | 195.186.1.121 | 192.168.0.10 | 0x1cb0 | No error (0) | www.google.com | 173.194.69.106 | A (IP address) | IN (0x0001) | |
| Jul 2, 2012 20:04:00.682996035 CEST | 195.186.1.121 | 192.168.0.10 | 0x9772 | No error (0) | www.google.fr | 173.194.69.94 | A (IP address) | IN (0x0001) | |
| Jul 2, 2012 20:04:04.926287889 CEST | 195.186.1.121 | 192.168.0.10 | 0x7fb4 | Server failure (2) | hhotelst555.ru | none | none | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:05.060086966 CEST | 195.186.1.121 | 192.168.0.10 | 0x7fb4 | Server failure (2) | hhotelst555.ru | none | none | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:05.082056046 CEST | 195.186.1.121 | 192.168.0.10 | 0x7fb4 | Server failure (2) | hhotelst555.ru | none | none | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:05.213291883 CEST | 195.186.1.121 | 192.168.0.10 | 0x6f1c | No error (0) | crl.verisign.com | 199.7.71.190 | A (IP address) | IN (0x0001) | |
| Jul 2, 2012 20:04:06.172941923 CEST | 195.186.1.121 | 192.168.0.10 | 0x6f1c | No error (0) | crl.verisign.com | 199.7.71.190 | A (IP address) | IN (0x0001) | |
| Jul 2, 2012 20:04:06.868124008 CEST | 195.186.1.121 | 192.168.0.10 | 0xcb27 | No error (0) | csc3-2009-2-crl.verisign.com | 199.7.54.190 | A (IP address) | IN (0x0001) | |
| Jul 2, 2012 20:04:09.297158957 CEST | 195.186.4.121 | 192.168.0.10 | 0x7fb4 | Server failure (2) | hhotelst555.ru | none | none | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:09.299439907 CEST | 195.186.4.121 | 192.168.0.10 | 0x7fb4 | Server failure (2) | hhotelst555.ru | none | none | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:09.299468994 CEST | 195.186.1.121 | 192.168.0.10 | 0x7fb4 | Server failure (2) | hhotelst555.ru | none | none | A (IP address) | IN (0x0001) | 
| Jul 2, 2012 20:04:11.571012020 CEST | 195.186.1.121 | 192.168.0.10 | 0x1cc7 | No error (0) | ssl.gstatic.com | 173.194.69.120 | A (IP address) | IN (0x0001) | |
| Jul 2, 2012 20:04:12.278769016 CEST | 195.186.1.121 | 192.168.0.10 | 0x1cc7 | No error (0) | ssl.gstatic.com | 173.194.69.120 | A (IP address) | IN (0x0001) | |
| Jul 2, 2012 20:04:30.610111952 CEST | 195.186.1.121 | 192.168.0.10 | 0x51c0 | No error (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i1.ds.ipv6-exp.l.google.com | 173.194.69.99 | A (IP address) | IN (0x0001) | |
| Jul 2, 2012 20:04:30.632275105 CEST | 195.186.1.121 | 192.168.0.10 | 0x4edd | No error (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i2.v4.ipv6-exp.l.google.com | 173.194.69.147 | A (IP address) | IN (0x0001) | |
| Jul 2, 2012 20:04:31.236272097 CEST | 195.186.1.121 | 192.168.0.10 | 0x51c0 | No error (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i1.ds.ipv6-exp.l.google.com | 173.194.69.99 | A (IP address) | IN (0x0001) | |
| Jul 2, 2012 20:04:31.424006939 CEST | 195.186.1.121 | 192.168.0.10 | 0x4edd | No error (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i2.v4.ipv6-exp.l.google.com | 173.194.69.147 | A (IP address) | IN (0x0001) | |
| Jul 2, 2012 20:04:32.790303946 CEST | 195.186.1.121 | 192.168.0.10 | 0x51c0 | No error (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i1.ds.ipv6-exp.l.google.com | 173.194.69.99 | A (IP address) | IN (0x0001) | |
| Jul 2, 2012 20:04:32.985280991 CEST | 195.186.1.121 | 192.168.0.10 | 0x4edd | No error (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i2.v4.ipv6-exp.l.google.com | 173.194.69.147 | A (IP address) | IN (0x0001) | |
| Jul 2, 2012 20:04:34.266618013 CEST | 195.186.1.121 | 192.168.0.10 | 0x51c0 | No error (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i1.ds.ipv6-exp.l.google.com | 173.194.69.99 | A (IP address) | IN (0x0001) | |
| Jul 2, 2012 20:04:34.379714966 CEST | 195.186.4.121 | 192.168.0.10 | 0x51c0 | No error (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i1.ds.ipv6-exp.l.google.com | 173.194.69.99 | A (IP address) | IN (0x0001) | |
| Jul 2, 2012 20:04:34.427088976 CEST | 195.186.1.121 | 192.168.0.10 | 0x4edd | No error (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i2.v4.ipv6-exp.l.google.com | 173.194.69.147 | A (IP address) | IN (0x0001) | |
| Jul 2, 2012 20:04:34.450025082 CEST | 195.186.4.121 | 192.168.0.10 | 0x4edd | No error (0) | p5.6qizwgpslmgcg.k2cxhkzltvi3hxmd.912250.i2.v4.ipv6-exp.l.google.com | 173.194.69.147 | A (IP address) | IN (0x0001) | |
| HTTP Dependency Graph | 
| 
 
 
 
 | 
| HTTP | ||||||
| Timestamp | Source Port | Dest Port | Source IP | Dest IP | Header | Total Bytes Transfered (KB) | 
| Jul 2, 2012 20:03:58.942425013 CEST | 1042 | 80 | 192.168.0.10 | 173.194.69.106 | 4 | |
| Jul 2, 2012 20:03:59.596462965 CEST | 80 | 1042 | 173.194.69.106 | 192.168.0.10 | 4 | |
| Jul 2, 2012 20:04:00.695569992 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 7 | |
| Jul 2, 2012 20:04:01.531971931 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 8 | |
| Jul 2, 2012 20:04:02.602509022 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 38 | |
| Jul 2, 2012 20:04:02.612231016 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 39 | |
| Jul 2, 2012 20:04:03.028846979 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 39 | |
| Jul 2, 2012 20:04:03.132586956 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 42 | |
| Jul 2, 2012 20:04:03.504678965 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 42 | |
| Jul 2, 2012 20:04:03.631467104 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 43 | |
| Jul 2, 2012 20:04:05.218806982 CEST | 1045 | 80 | 192.168.0.10 | 199.7.71.190 | 51 | |
| Jul 2, 2012 20:04:05.682365894 CEST | 80 | 1045 | 199.7.71.190 | 192.168.0.10 | 52 | |
| Jul 2, 2012 20:04:07.210767984 CEST | 1046 | 80 | 192.168.0.10 | 199.7.54.190 | 54 | |
| Jul 2, 2012 20:04:07.919285059 CEST | 80 | 1046 | 199.7.54.190 | 192.168.0.10 | 55 | |
| Jul 2, 2012 20:04:09.968908072 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 132 | |
| Jul 2, 2012 20:04:10.024929047 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 133 | |
| Jul 2, 2012 20:04:10.348225117 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 165 | |
| Jul 2, 2012 20:04:11.225372076 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 282 | |
| Jul 2, 2012 20:04:11.269587994 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 288 | |
| Jul 2, 2012 20:04:11.580758095 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 314 | |
| Jul 2, 2012 20:04:11.704292059 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 314 | |
| Jul 2, 2012 20:04:12.506702900 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 471 | |
| Jul 2, 2012 20:04:13.584280014 CEST | 1044 | 80 | 192.168.0.10 | 173.194.69.94 | 489 | |
| Jul 2, 2012 20:04:13.617311954 CEST | 1042 | 80 | 192.168.0.10 | 173.194.69.106 | 490 | |
| Jul 2, 2012 20:04:13.744057894 CEST | 1049 | 80 | 192.168.0.10 | 173.194.69.120 | 491 | |
| Jul 2, 2012 20:04:13.784454107 CEST | 1043 | 80 | 192.168.0.10 | 173.194.69.94 | 491 | |
| Jul 2, 2012 20:04:13.883213043 CEST | 80 | 1044 | 173.194.69.94 | 192.168.0.10 | 492 | |
| Jul 2, 2012 20:04:14.031414986 CEST | 80 | 1049 | 173.194.69.120 | 192.168.0.10 | 503 | |
| Jul 2, 2012 20:04:14.086762905 CEST | 80 | 1042 | 173.194.69.106 | 192.168.0.10 | 511 | |
| Jul 2, 2012 20:04:14.187480927 CEST | 80 | 1043 | 173.194.69.94 | 192.168.0.10 | 520 | |
| Jul 2, 2012 20:04:14.310000896 CEST | 1048 | 80 | 192.168.0.10 | 173.194.69.94 | 526 | |
| Jul 2, 2012 20:04:14.607681990 CEST | 80 | 1048 | 173.194.69.94 | 192.168.0.10 | 527 | |
| Jul 2, 2012 20:04:30.618577003 CEST | 1050 | 80 | 192.168.0.10 | 173.194.69.99 | 530 | |
| Jul 2, 2012 20:04:30.642021894 CEST | 1051 | 80 | 192.168.0.10 | 173.194.69.147 | 531 | |
| Jul 2, 2012 20:04:31.459068060 CEST | 80 | 1050 | 173.194.69.99 | 192.168.0.10 | 532 | |
| Jul 2, 2012 20:04:31.545617104 CEST | 80 | 1051 | 173.194.69.147 | 192.168.0.10 | 532 | |
Hooks
| User Modules | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Sections | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Section Activities: 
 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Process Activities: 
 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Thread Activities: 
 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Memory Activities: 
 
 
 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Section loaded | Path: \KnownDlls\kernel32.dll Access: write and read and execute Type: unknown Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid | success or wait | 540135493 | 
| Process information queried | PID: 1076 Info Class: Cookie | success or wait | 540144210 | 
| Section loaded | Path: unknown Access: query and write and read and execute and extend size Type: reserve Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid | success or wait | 540147677 | 
| Section loaded | Path: \NLS\NlsSectionUnicode Access: read Type: unknown Baseaddress: 260000 Size: 90112 Protection: readonly Mapped to pid: own pid | success or wait | 540157374 | 
| Section loaded | Path: \NLS\NlsSectionLocale Access: read Type: unknown Baseaddress: 280000 Size: 266240 Protection: readonly Mapped to pid: own pid | success or wait | 540159339 | 
| Section loaded | Path: \NLS\NlsSectionSortkey Access: query and read Type: unknown Baseaddress: 2D0000 Size: 266240 Protection: readonly Mapped to pid: own pid | success or wait | 540162753 | 
| Section loaded | Path: \NLS\NlsSectionSortTbls Access: read Type: unknown Baseaddress: 320000 Size: 24576 Protection: readonly Mapped to pid: own pid | success or wait | 540165881 | 
| Section loaded | Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 540168235 | 
| Section loaded | Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 540168604 | 
| Process information queried | PID: 1076 Info Class: ImageInformation | success or wait | 540172103 | 
| Memory allocated | PID: 1076 Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Base: 330000 Length: 12FE80 Allocation Type: unknown Protection: page read and write | success or wait | 540182664 | 
| Memory allocated | PID: 1076 Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Base: 330000 Length: 12FE84 Allocation Type: unknown Protection: page read and write | success or wait | 540182934 | 
| Memory attributes changed | PID: 1076 Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Base: 401000 Length: 5000 New Protection: page read and write New Protection: page execute read | success or wait | 540184081 | 
| Section loaded | Path: \KnownDlls\Wininet.dll Access: write and read and execute Type: unknown Baseaddress: 3D930000 Size: 942080 Protection: read write Mapped to pid: own pid | success or wait | 540186217 | 
| Section loaded | Path: \KnownDlls\msvcrt.dll Access: write and read and execute Type: unknown Baseaddress: 77C10000 Size: 360448 Protection: read write Mapped to pid: own pid | success or wait | 540189983 | 
| Section loaded | Path: \KnownDlls\SHLWAPI.dll Access: write and read and execute Type: unknown Baseaddress: 77F60000 Size: 483328 Protection: read write Mapped to pid: own pid | success or wait | 540196534 | 
| Section loaded | Path: \KnownDlls\ADVAPI32.dll Access: write and read and execute Type: unknown Baseaddress: 77DD0000 Size: 634880 Protection: read write Mapped to pid: own pid | success or wait | 540200633 | 
| Section loaded | Path: \KnownDlls\RPCRT4.dll Access: write and read and execute Type: unknown Baseaddress: 77E70000 Size: 602112 Protection: read write Mapped to pid: own pid | success or wait | 540207309 | 
| Section loaded | Path: \KnownDlls\Secur32.dll Access: write and read and execute Type: unknown Baseaddress: 77FE0000 Size: 69632 Protection: read write Mapped to pid: own pid | success or wait | 540215403 | 
| Section loaded | Path: \KnownDlls\GDI32.dll Access: write and read and execute Type: unknown Baseaddress: 77F10000 Size: 299008 Protection: read write Mapped to pid: own pid | success or wait | 540228714 | 
| Section loaded | Path: \KnownDlls\USER32.dll Access: write and read and execute Type: unknown Baseaddress: 7E410000 Size: 593920 Protection: read write Mapped to pid: own pid | success or wait | 540234867 | 
| Section loaded | Path: \KnownDlls\Normaliz.dll Access: write and read and execute Type: unknown Baseaddress: 340000 Size: 36864 Protection: read write Mapped to pid: own pid | conflicting addresses | 540259525 | 
| Section loaded | Path: \KnownDlls\urlmon.dll Access: write and read and execute Type: unknown Baseaddress: 78130000 Size: 1257472 Protection: read write Mapped to pid: own pid | success or wait | 540269189 | 
| Section loaded | Path: \KnownDlls\ole32.dll Access: write and read and execute Type: unknown Baseaddress: 774E0000 Size: 1302528 Protection: read write Mapped to pid: own pid | success or wait | 540272404 | 
| Section loaded | Path: \KnownDlls\OLEAUT32.dll Access: write and read and execute Type: unknown Baseaddress: 77120000 Size: 569344 Protection: read write Mapped to pid: own pid | success or wait | 540280773 | 
| Section loaded | Path: \KnownDlls\iertutil.dll Access: write and read and execute Type: unknown Baseaddress: 3DFD0000 Size: 2002944 Protection: read write Mapped to pid: own pid | success or wait | 540292548 | 
| Section loaded | Path: \NLS\NlsSectionCType Access: read Type: unknown Baseaddress: 360000 Size: 12288 Protection: readonly Mapped to pid: own pid | success or wait | 540305596 | 
| Process information queried | PID: 1076 Info Class: Cookie | success or wait | 540308230 | 
| Process information queried | PID: 1076 Info Class: Cookie | success or wait | 540308580 | 
| Section loaded | Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit Baseaddress: 370000 Size: 110592 Protection: execute Mapped to pid: own pid | success or wait | 540315263 | 
| Section loaded | Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit Baseaddress: 370000 Size: 110592 Protection: execute Mapped to pid: own pid | success or wait | 540319004 | 
| Section loaded | Path: C:\WINDOWS\system32\imm32.dll Access: query and write and read and execute Type: image Baseaddress: 76390000 Size: 118784 Protection: read write Mapped to pid: own pid | success or wait | 540321686 | 
| Section loaded | Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll Access: write and read and execute Type: commit Baseaddress: 920000 Size: 1056768 Protection: execute Mapped to pid: own pid | success or wait | 540391077 | 
| Section loaded | Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll Access: query and write and read and execute Type: image Baseaddress: 773D0000 Size: 1060864 Protection: read write Mapped to pid: own pid | success or wait | 540394534 | 
| Section loaded | Path: C:\WINDOWS\WindowsShell.Manifest Access: write and read and execute Type: commit Baseaddress: 3A0000 Size: 4096 Protection: execute Mapped to pid: own pid | success or wait | 540406227 | 
| Section loaded | Path: C:\WINDOWS\WindowsShell.Manifest Access: query and read Type: commit Baseaddress: 3A0000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 540410000 | 
| Section loaded | Path: C:\WINDOWS\WindowsShell.Manifest Access: read Type: commit Baseaddress: 3A0000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 540413147 | 
| Process information queried | PID: 1076 Info Class: Wow64Information | success or wait | 540542979 | 
| Section loaded | Path: \KnownDlls\SHELL32.dll Access: write and read and execute Type: unknown Baseaddress: 7C9C0000 Size: 8482816 Protection: read write Mapped to pid: own pid | success or wait | 540554313 | 
| Section loaded | Path: C:\WINDOWS\system32\shell32.dll Access: read Type: commit Baseaddress: B20000 Size: 8462336 Protection: readonly Mapped to pid: own pid | success or wait | 540567562 | 
| Section loaded | Path: \KnownDlls\comctl32.dll Access: write and read and execute Type: unknown Baseaddress: 5D090000 Size: 630784 Protection: read write Mapped to pid: own pid | success or wait | 540602862 | 
| Section loaded | Path: C:\WINDOWS\system32\comctl32.dll Access: read Type: commit Baseaddress: B20000 Size: 618496 Protection: readonly Mapped to pid: own pid | success or wait | 540616902 | 
| Process information queried | PID: 1076 Info Class: SessionInformation | success or wait | 540626232 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Local Settings_Temporary Internet Files_Content.IE5_index.dat_32768 Access: write Type: unknown Baseaddress: 3F0000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 540701922 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Cookies_index.dat_16384 Access: write Type: unknown Baseaddress: B20000 Size: 16384 Protection: read write Mapped to pid: own pid | success or wait | 540716436 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Local Settings_History_History.IE5_index.dat_32768 Access: write Type: unknown Baseaddress: B30000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 540726924 | 
| Section loaded | Path: \KnownDlls\ws2_32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 540856694 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and write and read and execute Type: image Baseaddress: 71AB0000 Size: 94208 Protection: read write Mapped to pid: own pid | success or wait | 540858313 | 
| Section loaded | Path: \KnownDlls\WS2HELP.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 540863445 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2help.dll Access: query and write and read and execute Type: image Baseaddress: 71AA0000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 540865562 | 
| Section loaded | Path: \KnownDlls\VERSION.dll Access: write and read and execute Type: unknown Baseaddress: 77C00000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 540958632 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 540963117 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 540963750 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 540964956 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 540965561 | 
| Section loaded | Path: \BaseNamedObjects\Local\UrlZonesSM_Administrator Access: query and write and read Type: commit Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name exists | 540972106 | 
| Section loaded | Path: \KnownDlls\RASAPI32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 541018665 | 
| Section loaded | Path: C:\WINDOWS\system32\rasapi32.dll Access: query and write and read and execute Type: image Baseaddress: 76EE0000 Size: 245760 Protection: read write Mapped to pid: own pid | success or wait | 541020496 | 
| Section loaded | Path: \KnownDlls\rasman.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 541026652 | 
| Section loaded | Path: C:\WINDOWS\system32\rasman.dll Access: query and write and read and execute Type: image Baseaddress: 76E90000 Size: 73728 Protection: read write Mapped to pid: own pid | success or wait | 541028464 | 
| Section loaded | Path: \KnownDlls\NETAPI32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 541034233 | 
| Section loaded | Path: C:\WINDOWS\system32\netapi32.dll Access: query and write and read and execute Type: image Baseaddress: 5B860000 Size: 348160 Protection: read write Mapped to pid: own pid | success or wait | 541036125 | 
| Section loaded | Path: \KnownDlls\TAPI32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 541048536 | 
| Section loaded | Path: C:\WINDOWS\system32\tapi32.dll Access: query and write and read and execute Type: image Baseaddress: 76EB0000 Size: 192512 Protection: read write Mapped to pid: own pid | success or wait | 541050351 | 
| Section loaded | Path: \KnownDlls\rtutils.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 541057996 | 
| Section loaded | Path: C:\WINDOWS\system32\rtutils.dll Access: query and write and read and execute Type: image Baseaddress: 76E80000 Size: 57344 Protection: read write Mapped to pid: own pid | success or wait | 541059879 | 
| Section loaded | Path: \KnownDlls\WINMM.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 541067673 | 
| Section loaded | Path: C:\WINDOWS\system32\winmm.dll Access: query and write and read and execute Type: image Baseaddress: 76B40000 Size: 184320 Protection: read write Mapped to pid: own pid | success or wait | 541069590 | 
| Section loaded | Path: C:\WINDOWS\system32\tapi32.dll Access: read Type: commit Baseaddress: DD0000 Size: 184320 Protection: readonly Mapped to pid: own pid | success or wait | 541146693 | 
| Section loaded | Path: \KnownDlls\USERENV.dll Access: write and read and execute Type: unknown Baseaddress: 769C0000 Size: 737280 Protection: read write Mapped to pid: own pid | success or wait | 541202647 | 
| Process information queried | PID: 1076 Info Class: QuotaLimits | success or wait | 541234879 | 
| Process information queried | PID: 1076 Info Class: VmCounters | success or wait | 541235263 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 541265435 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 541266069 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 541267011 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 541270452 | 
| Section loaded | Path: \KnownDlls\msapsspc.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 541309972 | 
| Section loaded | Path: C:\WINDOWS\system32\msapsspc.dll Access: query and write and read and execute Type: image Baseaddress: 71E50000 Size: 86016 Protection: read write Mapped to pid: own pid | success or wait | 541323633 | 
| Section loaded | Path: \KnownDlls\MSVCRT40.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 541329443 | 
| Section loaded | Path: C:\WINDOWS\system32\msvcrt40.dll Access: query and write and read and execute Type: image Baseaddress: 78080000 Size: 69632 Protection: read write Mapped to pid: own pid | success or wait | 541331761 | 
| Section loaded | Path: \KnownDlls\schannel.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 541364550 | 
| Section loaded | Path: C:\WINDOWS\system32\schannel.dll Access: query and write and read and execute Type: image Baseaddress: 767F0000 Size: 163840 Protection: read write Mapped to pid: own pid | success or wait | 541366704 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 541375146 | 
| Section loaded | Path: \KnownDlls\CRYPT32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 541376582 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and write and read and execute Type: image Baseaddress: 77A80000 Size: 610304 Protection: read write Mapped to pid: own pid | success or wait | 541378524 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 541384980 | 
| Section loaded | Path: \KnownDlls\MSASN1.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 541389298 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 541391890 | 
| Section loaded | Path: C:\WINDOWS\system32\msasn1.dll Access: query and write and read and execute Type: image Baseaddress: 77B20000 Size: 73728 Protection: read write Mapped to pid: own pid | success or wait | 541396981 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 541403260 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 541404849 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 541413958 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 541445982 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 541447966 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 541448505 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 541449092 | 
| Section loaded | Path: \KnownDlls\digest.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 541461177 | 
| Section loaded | Path: C:\WINDOWS\system32\digest.dll Access: query and write and read and execute Type: image Baseaddress: 75B00000 Size: 86016 Protection: read write Mapped to pid: own pid | success or wait | 541469402 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 541511013 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 541512707 | 
| Section loaded | Path: \KnownDlls\msnsspc.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 541515113 | 
| Section loaded | Path: C:\WINDOWS\system32\msnsspc.dll Access: query and write and read and execute Type: image Baseaddress: 747B0000 Size: 290816 Protection: read write Mapped to pid: own pid | success or wait | 541518946 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 541523842 | 
| Section loaded | Path: \KnownDlls\MSVCRT40.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 541525758 | 
| Section loaded | Path: C:\WINDOWS\system32\msvcrt40.dll Access: query and write and read and execute Type: image Baseaddress: 78080000 Size: 69632 Protection: read write Mapped to pid: own pid | success or wait | 541527616 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 541533504 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 541535899 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 541548903 | 
| Section loaded | Path: \KnownDlls\sensapi.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 541570172 | 
| Section loaded | Path: C:\WINDOWS\system32\sensapi.dll Access: query and write and read and execute Type: image Baseaddress: 722B0000 Size: 20480 Protection: read write Mapped to pid: own pid | success or wait | 541571909 | 
| Section loaded | Path: \BaseNamedObjects\SENS Information Cache Access: read Type: unknown Baseaddress: DD0000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 541591608 | 
| Section loaded | Path: C:\WINDOWS\system32\msv1_0.dll Access: write and read and execute Type: commit Baseaddress: E10000 Size: 139264 Protection: execute Mapped to pid: own pid | success or wait | 541606054 | 
| Section loaded | Path: C:\WINDOWS\system32\msv1_0.dll Access: query and write and read and execute Type: image Baseaddress: 77C70000 Size: 151552 Protection: read write Mapped to pid: own pid | success or wait | 541616841 | 
| Section loaded | Path: \KnownDlls\cryptdll.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 541625748 | 
| Section loaded | Path: C:\WINDOWS\system32\cryptdll.dll Access: query and write and read and execute Type: image Baseaddress: 76790000 Size: 49152 Protection: read write Mapped to pid: own pid | success or wait | 541627618 | 
| Section loaded | Path: \KnownDlls\iphlpapi.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 541644215 | 
| Section loaded | Path: C:\WINDOWS\system32\iphlpapi.dll Access: query and write and read and execute Type: image Baseaddress: 76D60000 Size: 102400 Protection: read write Mapped to pid: own pid | success or wait | 541650073 | 
| Section loaded | Path: C:\WINDOWS\system32\mswsock.dll Access: write and read and execute Type: commit Baseaddress: E10000 Size: 245760 Protection: execute Mapped to pid: own pid | success or wait | 541750551 | 
| Section loaded | Path: C:\WINDOWS\system32\mswsock.dll Access: query and write and read and execute Type: image Baseaddress: 71A50000 Size: 258048 Protection: read write Mapped to pid: own pid | success or wait | 541758787 | 
| Section loaded | Path: \KnownDlls\rasadhlp.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 543860267 | 
| Section loaded | Path: C:\WINDOWS\system32\rasadhlp.dll Access: query and write and read and execute Type: image Baseaddress: 76FC0000 Size: 24576 Protection: read write Mapped to pid: own pid | success or wait | 543862143 | 
| Section loaded | Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Access: query and write and read and execute and extend size Type: image Baseaddress: 76FC0000 Size: 24576 Protection: read write Mapped to pid: own pid | success or wait | 543906858 | 
| Section loaded | Path: \BaseNamedObjects\ShimSharedMemory Access: write Type: unknown Baseaddress: F10000 Size: 57344 Protection: read write Mapped to pid: own pid | success or wait | 543908617 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 543940529 | 
| Process information queried | PID: 1076 Info Class: DefaultHardErrorMode | success or wait | 543941034 | 
| Section loaded | Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Access: query and read Type: commit Baseaddress: F20000 Size: 196608 Protection: readonly Mapped to pid: own pid | success or wait | 543941420 | 
| Process created | PID: 2008 Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Cmdline: C:\6f7e68ac83fb111653e2093c17d46b21.exe Createflags: none | success or wait | 543948161 | 
| Process information queried | PID: 2008 Info Class: BasicInformation | success or wait | 543949193 | 
| Process information queried | PID: 2008 Info Class: BasicInformation | success or wait | 543959362 | 
| Memory allocated | PID: 1076 Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Base: F30000 Length: 12FC98 Allocation Type: unknown Protection: page read and write | success or wait | 545216015 | 
| Memory read | PID: 2008 Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Base: 7FFDE008 Length: 4 Value: 00 00 40 00 | success or wait | 545219892 | 
| Memory allocated | PID: 2008 Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Base: 400000 Length: 12FCC8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 545220246 | 
| Memory written | PID: 2008 Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Base: 400000 Length: 397312 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 03 00 FB 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 D0 01 00 00 10 00 00 00 20 04 00 70 F2 05 00 00 30 04 | success or wait | 545238069 | 
| Memory written | PID: 2008 Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Base: 7FFDE008 Length: 4 Value: 00 00 40 00 | success or wait | 545276200 | 
| Thread context set | TID: 384 PID: 2008 DR0: 0 DR1: 0 DR2: 0 DR3: 0 DR7: 0 EIP: 7C810705 EFLAGS: 200 Imagepath: null | success or wait | 545291297 | 
| Thread resumed | TID: 384 PID: 2008 Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe | success or wait | 545291594 | 
| Sections | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| File Activities: 
 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Section Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Registry Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Mutant Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Process Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Thread Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Memory Activities: 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| System Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Section loaded | Path: \KnownDlls\kernel32.dll Access: write and read and execute Type: unknown Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid | success or wait | 545301389 | 
| Process information queried | PID: 2008 Info Class: Cookie | success or wait | 545308170 | 
| Section loaded | Path: unknown Access: query and write and read and execute and extend size Type: reserve Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid | success or wait | 545309157 | 
| Section loaded | Path: \NLS\NlsSectionUnicode Access: read Type: unknown Baseaddress: 260000 Size: 90112 Protection: readonly Mapped to pid: own pid | success or wait | 545313506 | 
| Section loaded | Path: \NLS\NlsSectionLocale Access: read Type: unknown Baseaddress: 280000 Size: 266240 Protection: readonly Mapped to pid: own pid | success or wait | 545315142 | 
| Section loaded | Path: \NLS\NlsSectionSortkey Access: query and read Type: unknown Baseaddress: 2D0000 Size: 266240 Protection: readonly Mapped to pid: own pid | success or wait | 545316536 | 
| Section loaded | Path: \NLS\NlsSectionSortTbls Access: read Type: unknown Baseaddress: 320000 Size: 24576 Protection: readonly Mapped to pid: own pid | success or wait | 545317504 | 
| Section loaded | Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 545319238 | 
| Section loaded | Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 545319605 | 
| Section loaded | Path: \KnownDlls\ADVAPI32.dll Access: write and read and execute Type: unknown Baseaddress: 77DD0000 Size: 634880 Protection: read write Mapped to pid: own pid | success or wait | 545321785 | 
| Section loaded | Path: \KnownDlls\RPCRT4.dll Access: write and read and execute Type: unknown Baseaddress: 77E70000 Size: 602112 Protection: read write Mapped to pid: own pid | success or wait | 545325093 | 
| Section loaded | Path: \KnownDlls\Secur32.dll Access: write and read and execute Type: unknown Baseaddress: 77FE0000 Size: 69632 Protection: read write Mapped to pid: own pid | success or wait | 545329238 | 
| Process information queried | PID: 2008 Info Class: ImageInformation | success or wait | 545336105 | 
| Memory attributes changed | PID: 2008 Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Base: 400000 Length: 1000 New Protection: page read and write New Protection: page execute and read and write | success or wait | 545452690 | 
| Memory attributes changed | PID: 2008 Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Base: 400000 Length: 1000 New Protection: page execute and read and write New Protection: page read and write | success or wait | 545453254 | 
| Process information queried | PID: 2008 Info Class: Wow64Information | success or wait | 545454471 | 
| File opened | Path: C:\WINDOWS\system32\kernel32.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 545454975 | 
| Section loaded | Path: C:\WINDOWS\system32\kernel32.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 470000 Size: 1007616 Protection: readonly Mapped to pid: own pid | image not at base | 545456025 | 
| Memory attributes changed | PID: 2008 Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Base: 4A5FA8 Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 545457019 | 
| Memory attributes changed | PID: 2008 Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Base: 45615C Length: 1000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 545458350 | 
| Process information queried | PID: 2008 Info Class: Wow64Information | success or wait | 545458945 | 
| File opened | Path: C:\WINDOWS\system32\kernel32.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 545459267 | 
| Section loaded | Path: C:\WINDOWS\system32\kernel32.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 470000 Size: 1007616 Protection: readonly Mapped to pid: own pid | image not at base | 545460101 | 
| Memory attributes changed | PID: 2008 Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Base: 4A5FA8 Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 545460858 | 
| Memory attributes changed | PID: 2008 Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Base: 45B098 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 545461790 | 
| Memory allocated | PID: 2008 Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Base: 330000 Length: 12FFA4 Allocation Type: unknown Protection: page execute and read and write | success or wait | 545462275 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName Name: ComputerName | success or wait | 545463946 | 
| File created | Path: C:\Recycle.Bin\ Access: read data or list directory and synchronize Options: directory file and synchronous io non alert and open for backup ident Attributes: normal Content Overwritten: null | success or wait | 545468762 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 545475359 | 
| Process information queried | PID: 2008 Info Class: Wow64Information | success or wait | 545476001 | 
| File opened | Path: C:\WINDOWS\system32\kernel32.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 545476322 | 
| Section loaded | Path: C:\WINDOWS\system32\kernel32.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 470000 Size: 1007616 Protection: readonly Mapped to pid: own pid | image not at base | 545477159 | 
| Memory attributes changed | PID: 2008 Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Base: 4A5FA8 Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 545477939 | 
| Memory attributes changed | PID: 2008 Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Base: 459098 Length: 3000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 545478901 | 
| System info queried | Type: ProcessInformation | success or wait | 545479493 | 
| Section loaded | Path: unknown Access: query and write and read Type: commit Baseaddress: 330000 Size: 20480 Protection: read write Mapped to pid: own pid | success or wait | 545486692 | 
| Process information queried | PID: 1552 Info Class: BasicInformation | success or wait | 545494302 | 
| Memory allocated | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BA0000 Length: 12FFA4 Allocation Type: unknown Protection: page execute and read and write | success or wait | 545494563 | 
| Memory written | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BA0000 Length: 8192 Value: 55 8B EC 81 EC C0 05 00 00 83 65 E0 00 53 56 57 33 C0 8D 7D E4 AB AB AB 8D 85 58 FF FF FF C7 45 B8 5C 3F 3F 5C C6 45 BC 00 89 85 54 FF FF FF E8 00 00 00 00 58 89 45 F8 8B 45 F8 8B D0 81 E2 FF 0F 00 00 33 C9 2B C2 41 05 20 0B 00 00 81 38 21 45 59 45 8B F8 89 7D C0 74 0B 41 05 00 10 00 00 83 F9 0A 76 E8 83 F9 0A 75 01 CC 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 E8 93 43 77 6A 03 8B F0 E8 0E 05 00 00 59 59 85 C0 74 15 89 65 C4 68 04 01 00 00 8D 8D 48 FC FF FF 51 56 FF D0 8B 65 C4 68 AE B1 A6 C2 33 F6 56 E8 E6 04 00 00 59 59 3B C6 74 11 89 65 A8 8D 4D FF 51 56 6A 01 6A 14 FF D0 8B 65 A8 64 A1 18 00 00 00 68 77 35 07 0A 6A 03 89 70 34 E8 BA 04 00 00 59 59 3B C6 74 14 89 65 A0 56 8D 8F 08 01 00 00 51 FF D0 8B 65 A0 3B C6 75 13 64 A1 18 00 00 00 81 78 34 | success or wait | 552781323 | 
| Memory allocated | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BB0000 Length: 12FBEC Allocation Type: unknown Protection: page execute and read and write | success or wait | 552781925 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 552784202 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@adddd6 | success or wait | 552786393 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 552786497 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@bf34f4 | success or wait | 552791144 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 552792250 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 552792363 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12dbd1a | success or wait | 552794012 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 552795124 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1da1f99 | success or wait | 552797703 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 330000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 552798072 | 
| Memory written | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BB0000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A | success or wait | 553106736 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 553106955 | 
| Memory written | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 7C90CFEE Length: 5 Value: E9 BF 33 2A 84 | success or wait | 553114610 | 
| Thread delayed | Time: -3 TID: 384 | success or wait | 553114851 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 563808454 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 563809044 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 565605273 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 565605916 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 565989339 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 565989907 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 566380736 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 566381796 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 566772280 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 566772916 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 567163734 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 567164337 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 567555331 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 567555934 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 567950665 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 567951237 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 568341437 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 568342003 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 568729750 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 568730352 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 569121224 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 569121828 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 569512749 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 569513342 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 569904274 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 569904897 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 570295873 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 570296441 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 570691671 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 570692235 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 571081875 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 571082479 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 571470434 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 571471351 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 571861941 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 571862558 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 572253381 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 572253986 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 572645506 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 572646082 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 573036993 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 573037598 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 573428442 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 573431018 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 573821984 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 573822622 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 574212250 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 574214323 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 574602198 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 574602857 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 574996971 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 574997536 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 575385607 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 575386185 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 575777079 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 575777686 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 576168600 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 576171099 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 576560056 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 576560668 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 576952646 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 576953257 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 577343193 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 577343768 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 577735119 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 577735665 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 578126152 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 578126763 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 578517600 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 578518216 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 579000187 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 579003844 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 579356567 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 579357180 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 579748193 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 579748768 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 580139614 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 580140186 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 580531136 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 580531743 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 580922741 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 580923351 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 581314128 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 581315412 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 581705610 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 581706220 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 582097132 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 582097696 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 582504548 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 582506684 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 582880234 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 582880921 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 583274475 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 583275085 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 583663194 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 583663805 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 584054709 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 584055323 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 584446956 | 
| Thread delayed | Time: 0 TID: 384 | success or wait | 584838342 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | object name exists | 605420088 | 
| Process terminated | PID: 2008 Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe | success or wait | 606032900 | 
| Sections | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| File Activities: 
 
 
 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Section Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Registry Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Mutant Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Process Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Thread Activities: 
 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Memory Activities: 
 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| System Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| User Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Mutant created | Name: \BaseNamedObjects\zXeRY3a_PtW|00000000 | success or wait | 598765418 | 
| Thread created | PID: 1552 TID: 1808 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 598770369 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 598772388 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 598775492 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 598775778 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 598776145 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 598776427 | 
| File created | Path: C:\Recycle.Bin\ Access: read data or list directory and synchronize Options: directory file and synchronous io non alert and open for backup ident Attributes: normal Content Overwritten: null | object name collision | 598777850 | 
| File other op | Path: C:\Recycle.BinNew path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@189e60f | success or wait | 598779672 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read data or list directory and read ea and read attributes and synchronize Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 598781088 | 
| File opened | Path: C:\Recycle.Bin\ Access: read attributes and synchronize and generic write Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | file is a directory | 598782220 | 
| File opened | Path: C:\Recycle.Bin\ Access: read attributes and synchronize and generic write Options: synchronous io non alert and open for backup ident Attributes: none Content Overwritten: null | success or wait | 598783086 | 
| File opened | Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 598785995 | 
| File read | Path: C:\6f7e68ac83fb111653e2093c17d46b21.exe Offset: unknown Length: 196096 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 70 72 6F 67 72 61 6D 20 63 61 6E 6E 6F 74 20 62 65 | success or wait | 598787916 | 
| File created | Path: C:\Recycle.Bin\B6232F3AC2C.exe Access: read attributes and synchronize and generic write Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 599053242 | 
| File write | Path: C:\Recycle.Bin\B6232F3AC2C.exe Offset: unknown Length: 196096 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 70 72 6F 67 72 61 6D 20 63 61 6E 6E 6F 74 20 62 65 | success or wait | 599321886 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read data or list directory and read ea and read attributes and synchronize Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 599341772 | 
| File opened | Path: C:\Recycle.Bin\B6232F3AC2C.exe Access: read attributes and synchronize and generic write Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 599343014 | 
| Section loaded | Path: C:\Recycle.Bin\B6232F3AC2C.exe Access: query and write and read and execute and extend size Type: image Baseaddress: 330000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 599346858 | 
| File opened | Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 599373955 | 
| Section loaded | Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 2E70000 Size: 1208320 Protection: readonly Mapped to pid: own pid | success or wait | 599374918 | 
| File opened | Path: C:\WINDOWS\AppPatch\systest.sdb Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | object name not found | 599375934 | 
| File opened | Path: \Device\NamedPipe\ShimViewer Access: write data or add file and append data or add subdirectory or create pipe instance and write ea and write attributes and read control and synchronize Options: no options Attributes: normal Content Overwritten: null | object name not found | 599377866 | 
| Process information queried | PID: 1552 Info Class: DefaultHardErrorMode | success or wait | 599380106 | 
| Process information queried | PID: 1552 Info Class: DefaultHardErrorMode | success or wait | 599382100 | 
| Process information queried | PID: 1552 Info Class: DeviceMap | success or wait | 599382772 | 
| Process information queried | PID: 1552 Info Class: DefaultHardErrorMode | success or wait | 599384590 | 
| Process information queried | PID: 1552 Info Class: DefaultHardErrorMode | success or wait | 599386503 | 
| Process information queried | PID: 1552 Info Class: DefaultHardErrorMode | success or wait | 599390295 | 
| Process information queried | PID: 1552 Info Class: DefaultHardErrorMode | success or wait | 599395373 | 
| Section loaded | Path: C:\Recycle.Bin\B6232F3AC2C.exe Access: query and read Type: commit Baseaddress: C90000 Size: 196608 Protection: readonly Mapped to pid: own pid | success or wait | 599395791 | 
| Process created | PID: 188 Path: C:\Recycle.Bin\B6232F3AC2C.exe Cmdline: C:\Recycle.Bin\B6232F3AC2C.exe Createflags: none | success or wait | 599400197 | 
| Process information queried | PID: 188 Info Class: BasicInformation | success or wait | 599404759 | 
| Process information queried | PID: 188 Info Class: BasicInformation | success or wait | 599415539 | 
| File deleted | Path: C:\6f7e68ac83fb111653e2093c17d46b21.exeNew path: Disposition: Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ee6a6 | cannot delete | 602175773 | 
| Thread delayed | Time: -1 TID: 1808 | success or wait | 602179199 | 
| File deleted | Path: C:\6f7e68ac83fb111653e2093c17d46b21.exeNew path: Disposition: Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ee6a6 | cannot delete | 605760653 | 
| Thread delayed | Time: -1 TID: 1808 | success or wait | 605761577 | 
| File deleted | Path: C:\6f7e68ac83fb111653e2093c17d46b21.exeNew path: Disposition: Data : abstraction.selector.functions.gen.NtFunc$FunctionData@78d4e6 | success or wait | 609336354 | 
| Mutant created | Name: \BaseNamedObjects\zXeRY3a_PtW|00000000 | success or wait | 609339807 | 
| Thread created | PID: 1552 TID: 1024 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 609342646 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 609344607 | 
| Thread delayed | Time: -1 TID: 1808 | success or wait | 609345293 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 609345984 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 609346268 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 609346623 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 609346909 | 
| Thread created | PID: 1552 TID: 116 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 609349905 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 609351177 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 609351455 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 609351779 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 609352061 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 609352539 | 
| Process information queried | PID: 1552 Info Class: DefaultHardErrorMode | success or wait | 609352999 | 
| System info queried | Type: HandleInformation | info length mismatch | 609354741 | 
| System info queried | Type: HandleInformation | success or wait | 609371830 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 609503681 | 
| Thread created | PID: 1552 TID: 1120 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 609505520 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 609513356 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 609513637 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 609513965 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 609514247 | 
| System info queried | Type: ProcessInformation | success or wait | 609515486 | 
| Section loaded | Path: unknown Access: query and write and read Type: commit Baseaddress: BC0000 Size: 16384 Protection: read write Mapped to pid: own pid | success or wait | 609522069 | 
| Process information queried | PID: 576 Info Class: BasicInformation | success or wait | 609525854 | 
| Memory allocated | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BAD0000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 609526529 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 609526839 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 609527183 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 609527497 | 
| Memory written | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 613477612 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 613478033 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 613478737 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 613478975 | 
| Thread terminated | TID: 1808 PID: 1552 Path: C:\WINDOWS\explorer.exe | unknown | 613479539 | 
| Memory written | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BADE920 Length: 13 Value: B8 00 00 00 00 50 BA D5 4E AF 0B FF D2 | success or wait | 613486997 | 
| Memory allocated | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: A70000 Length: D6FBD8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 613487140 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 613487525 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 613487852 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 613487945 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 613488178 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 613488269 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 613488380 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 613488596 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 613488686 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 613488875 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: BC0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 613488996 | 
| Memory written | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: A70000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A | success or wait | 613498558 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 613498681 | 
| Memory written | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 7C90CFEE Length: 5 Value: E9 BF 33 16 84 | success or wait | 613506087 | 
| Process information queried | PID: 676 Info Class: BasicInformation | success or wait | 613506596 | 
| Memory allocated | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BAD0000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 613506837 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 613506947 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 613507067 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 613507176 | 
| Memory written | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 614293940 | 
| Memory written | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BADE920 Length: 13 Value: B8 00 00 00 00 50 BA D5 4E AF 0B FF D2 | success or wait | 614300628 | 
| Memory allocated | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: A70000 Length: D6FBD8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 614300734 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 614301129 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 614301476 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 614301569 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 614301799 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 614301889 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 614302000 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 614302214 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 614302304 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 614302492 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: BC0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 614302613 | 
| Memory written | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: A70000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A | success or wait | 614312101 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 614312359 | 
| Memory written | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 7C90CFEE Length: 5 Value: E9 BF 33 16 84 | success or wait | 614318875 | 
| Process information queried | PID: 836 Info Class: BasicInformation | success or wait | 614319327 | 
| Memory allocated | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 614319583 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 614319696 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 614319822 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 614319935 | 
| Memory written | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 615031512 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 615031648 | 
| Memory written | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BADE920 Length: 13 Value: B8 00 00 00 00 50 BA D5 4E AF 0B FF D2 | success or wait | 615039196 | 
| Memory allocated | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: EB0000 Length: D6FBD8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 615039377 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 615039775 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 615040111 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 615040205 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 615040346 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 615040436 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 615040546 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 615040761 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 615040850 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 615041038 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: BC0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 615041159 | 
| Memory written | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: EB0000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A | success or wait | 615050701 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 615050828 | 
| Memory written | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 5 Value: E9 BF 33 5A 84 | success or wait | 615057361 | 
| Process information queried | PID: 912 Info Class: BasicInformation | success or wait | 615057766 | 
| Memory allocated | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 615058023 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 615058136 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 615058301 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 615058415 | 
| Memory written | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 615652388 | 
| Memory written | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BADE920 Length: 13 Value: B8 00 00 00 00 50 BA D5 4E AF 0B FF D2 | success or wait | 615659288 | 
| Memory allocated | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: B70000 Length: D6FBD8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 615659393 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 615659790 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 615660132 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 615660224 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 615660366 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 615660456 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 615660567 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 615660782 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 615660873 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 615661061 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: BC0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 615661482 | 
| Memory written | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: B70000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A | success or wait | 615670604 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 615670786 | 
| Memory written | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 5 Value: E9 BF 33 26 84 | success or wait | 615677230 | 
| Process information queried | PID: 996 Info Class: BasicInformation | success or wait | 615677638 | 
| Memory allocated | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 615677901 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 615678014 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 615678141 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 615678255 | 
| Memory written | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 620965005 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 620966865 | 
| Memory written | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BADE920 Length: 13 Value: B8 00 00 00 00 50 BA D5 4E AF 0B FF D2 | success or wait | 620984342 | 
| Memory allocated | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 16A0000 Length: D6FBD8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 620984837 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 620986279 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 620987202 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 620987501 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 620988136 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 620988401 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 620988710 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 620989255 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 620989481 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 620989950 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: BC0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 620990248 | 
| Memory written | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 16A0000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A | success or wait | 621012662 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 621013146 | 
| Memory written | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 5 Value: E9 BF 33 D9 84 | success or wait | 621026332 | 
| Process information queried | PID: 1052 Info Class: BasicInformation | success or wait | 621027312 | 
| Memory allocated | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 621027922 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 621028202 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 621028584 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 621028868 | 
| Memory written | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 621884480 | 
| Memory written | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BADE920 Length: 13 Value: B8 00 00 00 00 50 BA D5 4E AF 0B FF D2 | success or wait | 621897267 | 
| Memory allocated | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 850000 Length: D6FBD8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 621897525 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 621898459 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 621899226 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 621899469 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 621899815 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 621900040 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 621900313 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 621902047 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 621902276 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 621902745 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: BC0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 621903041 | 
| Memory written | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 850000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A | success or wait | 621918634 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 621926272 | 
| Memory written | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 5 Value: E9 BF 33 F4 83 | success or wait | 621939161 | 
| Process information queried | PID: 1092 Info Class: BasicInformation | success or wait | 621940206 | 
| Memory allocated | PID: 1092 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 621940884 | 
| Memory attributes changed | PID: 1092 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 621941229 | 
| Memory attributes changed | PID: 1092 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 621941626 | 
| Memory attributes changed | PID: 1092 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 621941974 | 
| Memory written | PID: 1092 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 622611167 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 622611315 | 
| Memory written | PID: 1092 Path: C:\WINDOWS\system32\svchost.exe Base: BADE920 Length: 13 Value: B8 00 00 00 00 50 BA D5 4E AF 0B FF D2 | success or wait | 622618422 | 
| Memory allocated | PID: 1092 Path: C:\WINDOWS\system32\svchost.exe Base: 990000 Length: D6FBD8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 622618553 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 622618978 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 622619337 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 622619430 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 622619573 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 622619664 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 622619775 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 622620295 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 622620387 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 622620578 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: BC0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 622620699 | 
| Memory written | PID: 1092 Path: C:\WINDOWS\system32\svchost.exe Base: 990000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A | success or wait | 622630893 | 
| Memory attributes changed | PID: 1092 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 622631042 | 
| Memory written | PID: 1092 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 5 Value: E9 BF 33 08 84 | success or wait | 622638315 | 
| Process information queried | PID: 1412 Info Class: BasicInformation | success or wait | 622638761 | 
| Memory allocated | PID: 1412 Path: C:\WINDOWS\system32\spoolsv.exe Base: BAD0000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 622639037 | 
| Memory attributes changed | PID: 1412 Path: C:\WINDOWS\system32\spoolsv.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 622639172 | 
| Memory attributes changed | PID: 1412 Path: C:\WINDOWS\system32\spoolsv.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 622639318 | 
| Memory attributes changed | PID: 1412 Path: C:\WINDOWS\system32\spoolsv.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 622639452 | 
| Memory written | PID: 1412 Path: C:\WINDOWS\system32\spoolsv.exe Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 623469838 | 
| Memory written | PID: 1412 Path: C:\WINDOWS\system32\spoolsv.exe Base: BADE920 Length: 13 Value: B8 00 00 00 00 50 BA D5 4E AF 0B FF D2 | success or wait | 623476595 | 
| Memory allocated | PID: 1412 Path: C:\WINDOWS\system32\spoolsv.exe Base: 930000 Length: D6FBD8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 623476726 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 623477145 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 623477488 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 623477581 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 623477722 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 623477813 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 623477924 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 623478138 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 623478228 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 623478416 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: BC0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 623478536 | 
| Memory written | PID: 1412 Path: C:\WINDOWS\system32\spoolsv.exe Base: 930000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A | success or wait | 623488425 | 
| Memory attributes changed | PID: 1412 Path: C:\WINDOWS\system32\spoolsv.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 623488572 | 
| Memory written | PID: 1412 Path: C:\WINDOWS\system32\spoolsv.exe Base: 7C90CFEE Length: 5 Value: E9 BF 33 02 84 | success or wait | 623495783 | 
| Process information queried | PID: 1552 Info Class: BasicInformation | success or wait | 623496180 | 
| Memory allocated | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BAD0000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | conflicting addresses | 623496426 | 
| Memory allocated | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BB1E000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | conflicting addresses | 623496525 | 
| Memory allocated | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BB60000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 623496619 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BB60000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 623496718 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BB60000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 623496820 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BB60000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 623496920 | 
| Memory written | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BB60000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 623498850 | 
| Thread created | PID: 1552 TID: 1308 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 623500550 | 
| Process information queried | PID: 1728 Info Class: BasicInformation | success or wait | 623501271 | 
| Memory allocated | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BAD0000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 623501771 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 623501822 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 623501922 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 623502071 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 623502172 | 
| Thread created | PID: 1552 TID: 1708 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 623503341 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and write copy | success or wait | 623503898 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 623504245 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 623504549 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 623504639 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 623504993 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 623505053 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 623505221 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 623505278 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 623505456 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 623505514 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 623505673 | 
| Memory written | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 623935840 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 623936085 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 623936187 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 623936239 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 623936337 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 623936450 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 623936663 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 623936754 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 623936940 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: C10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 623937060 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 623938775 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BB8EA50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 623938883 | 
| Thread created | PID: 1552 TID: 1480 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 623939437 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 623939974 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 623940078 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 623940204 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 623940307 | 
| Thread created | PID: 1552 TID: 988 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 623940893 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 623941417 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 623941517 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 623941636 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 623941738 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 623942005 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 623942205 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 623942389 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 623942528 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 623942591 | 
| Memory written | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BADE920 Length: 13 Value: B8 00 00 00 00 50 BA D5 4E AF 0B FF D2 | success or wait | 623952410 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 623952996 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 623953307 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 623953397 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 623953530 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 623953618 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 623953724 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 623953929 | 
| Memory allocated | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: A30000 Length: D6FBD8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 623954432 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 623954788 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 623955095 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 623955185 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 623955313 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 623955401 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 623955506 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 623955711 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 623955799 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 623955977 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: C90000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 623956092 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 623956796 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 623956983 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: C10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 623957098 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 623958716 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BBA86C0 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 623958820 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 623958925 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 623959264 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 623959569 | 
| Memory written | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: A30000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A | success or wait | 623969268 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 623969329 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 623969467 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 623969556 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 623969662 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 623969869 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 623969956 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 623970135 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: C10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 623970252 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 623970896 | 
| Memory written | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 7C90CFEE Length: 5 Value: E9 BF 33 12 84 | success or wait | 623978076 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 623978822 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BB96F28 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 623978927 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 623979031 | 
| Process information queried | PID: 340 Info Class: BasicInformation | success or wait | 623979856 | 
| Memory allocated | PID: 340 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 623980096 | 
| Memory attributes changed | PID: 340 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 623980207 | 
| Memory attributes changed | PID: 340 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 623980367 | 
| Memory attributes changed | PID: 340 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 623980477 | 
| Memory written | PID: 340 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 624564165 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 624564395 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 624564736 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 624564830 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 624565062 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 624565154 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 624565265 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 624565484 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 624565575 | 
| Memory written | PID: 340 Path: C:\WINDOWS\system32\svchost.exe Base: BADE920 Length: 13 Value: B8 00 00 00 00 50 BA D5 4E AF 0B FF D2 | success or wait | 624573441 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 624573506 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: C10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 624573627 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 624574569 | 
| Memory allocated | PID: 340 Path: C:\WINDOWS\system32\svchost.exe Base: A60000 Length: D6FBD8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 624575014 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 624575373 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 624575694 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 624575785 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 624575921 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 624576009 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 624576114 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 624576323 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 624576410 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 624576592 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: C10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 624576707 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BB94B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 624576965 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 624577145 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 624577235 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 624577575 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 624577882 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 624577972 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 624578108 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 624578196 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 624578301 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 624578508 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 624578596 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 624578778 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: C10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 624578894 | 
| Memory written | PID: 340 Path: C:\WINDOWS\system32\svchost.exe Base: A60000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A | success or wait | 624589100 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 624589654 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BBA7D98 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 624589758 | 
| Section loaded | Path: \KnownDlls\nspr4.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 624590362 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 624591194 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 624591571 | 
| Memory attributes changed | PID: 340 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 624597376 | 
| Memory written | PID: 340 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 5 Value: E9 BF 33 15 84 | success or wait | 624604003 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 624604062 | 
| File opened | Path: C:\WINDOWS\system32\USER32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 624604422 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9c393d | success or wait | 624604736 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 4 Value: D8 00 00 00 | success or wait | 624604829 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@71edc0 | success or wait | 624605572 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 1B A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 624605665 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 F4 05 00 00 E2 02 00 00 00 00 00 17 B2 00 00 00 10 00 00 00 B0 05 00 00 00 41 7E 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 10 09 00 00 04 00 00 76 FC 08 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 39 00 00 | success or wait | 624605775 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1aff012 | success or wait | 624605988 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 83 F2 05 00 00 10 00 00 00 F4 05 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 80 11 00 00 00 10 06 00 00 0C 00 00 00 F8 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 88 A0 02 00 00 30 06 00 00 A2 02 00 | success or wait | 624606079 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ba4b54 | success or wait | 624606265 | 
| Section loaded | Path: C:\WINDOWS\system32\user32.dll Access: query and read Type: commit Baseaddress: C10000 Size: 57344 Protection: readonly Mapped to pid: own pid | success or wait | 624606384 | 
| Process information queried | PID: 400 Info Class: BasicInformation | success or wait | 624607329 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 624608682 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BB93E40 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 624608788 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 624608909 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 624609258 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a79faa | success or wait | 624609569 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 624609660 | 
| Memory allocated | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BAD0000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 624610057 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1e352bf | success or wait | 624610457 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 624610548 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 624610656 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@14d8c01 | success or wait | 624610866 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 624610956 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@22a6bb | success or wait | 624611141 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: C10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 624611258 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 624611746 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 624612674 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 624612791 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 624613580 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BBA89C8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 624613685 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 624613802 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 624614148 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a79faa | success or wait | 624614455 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 624614546 | 
| Memory written | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 625323031 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1e352bf | success or wait | 625323112 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 625323368 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 625323421 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 625323572 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 625323721 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 625323822 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 625323939 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@14d8c01 | success or wait | 625324161 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 625324255 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@22a6bb | success or wait | 625324449 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: C10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 625324573 | 
| Memory written | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BADE920 Length: 13 Value: B8 00 00 00 00 50 BA D5 4E AF 0B FF D2 | success or wait | 625332017 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 625332977 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BBA8118 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 625333088 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 625333236 | 
| Memory allocated | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 10A0000 Length: D6FBD8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 625333821 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 625334202 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 625334544 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 625334637 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 625334781 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 625334872 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 625334982 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 625335227 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 625335319 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 625335509 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: C10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 625335629 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 625336193 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a79faa | success or wait | 625336511 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 625336605 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1e352bf | success or wait | 625336748 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 625336841 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 625336952 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@14d8c01 | success or wait | 625337170 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 625337262 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@22a6bb | success or wait | 625337454 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: C10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 625337576 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 625338772 | 
| Memory written | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 10A0000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A | success or wait | 625347910 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BB8E1F8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 625347968 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 625348497 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 625348877 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a79faa | success or wait | 625349198 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 625349293 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1e352bf | success or wait | 625349435 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 625349529 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 625350046 | 
| Memory written | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 7C90CFEE Length: 5 Value: E9 BF 33 79 84 | success or wait | 625356351 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 625356414 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@14d8c01 | success or wait | 625356641 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 625356736 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@22a6bb | success or wait | 625356928 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: C10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 625357050 | 
| Process information queried | PID: 420 Info Class: BasicInformation | success or wait | 625358594 | 
| Memory allocated | PID: 420 Path: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE Base: BAD0000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 625358846 | 
| Memory attributes changed | PID: 420 Path: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 625358961 | 
| Memory attributes changed | PID: 420 Path: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 625359085 | 
| Memory attributes changed | PID: 420 Path: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 625359198 | 
| Memory written | PID: 420 Path: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 625710618 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 625711388 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BB97290 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 625711498 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 625711773 | 
| File opened | Path: C:\WINDOWS\system32\WS2_32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 625712141 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@f0756d | success or wait | 625712480 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 625712575 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ad4bb0 | success or wait | 625713450 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 63 A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 625713544 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 22 01 00 00 1C 00 00 00 00 00 00 73 12 00 00 00 10 00 00 00 20 01 00 00 00 AB 71 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 70 01 00 00 04 00 00 20 F0 01 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 04 14 00 00 | success or wait | 625713656 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@144426c | success or wait | 625713876 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 53 21 01 00 00 10 00 00 00 22 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 14 09 00 00 00 40 01 00 00 0A 00 00 00 26 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 F8 03 00 00 00 50 01 00 00 04 00 00 | success or wait | 625713969 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@64f150 | success or wait | 625714161 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and read Type: commit Baseaddress: C10000 Size: 20480 Protection: readonly Mapped to pid: own pid | success or wait | 625714283 | 
| Memory written | PID: 420 Path: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE Base: BADE920 Length: 13 Value: B8 00 00 00 00 50 BA D5 4E AF 0B FF D2 | success or wait | 625721234 | 
| Memory allocated | PID: 420 Path: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE Base: 8E0000 Length: D6FBD8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 625721453 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 625722511 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 625722832 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 625722926 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 625723068 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 625724589 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 625724964 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 625725189 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 625725280 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 625725470 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: C10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 625725590 | 
| Memory written | PID: 420 Path: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE Base: 8E0000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A | success or wait | 625736343 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 625736608 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BBA8D30 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 625736719 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 77DEE360 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 625736868 | 
| File opened | Path: C:\WINDOWS\system32\ADVAPI32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 625737266 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11ef9f6 | success or wait | 625737591 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 625738473 | 
| Memory attributes changed | PID: 420 Path: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 625738825 | 
| Memory written | PID: 420 Path: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE Base: 7C90CFEE Length: 5 Value: E9 BF 33 FD 83 | success or wait | 625746721 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@acc399 | success or wait | 625747314 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 48 1D 90 49 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 625747409 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 46 07 00 00 3E 02 00 00 00 00 00 0B 71 00 00 00 10 00 00 00 20 07 00 00 00 DD 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 B0 09 00 00 04 00 00 B8 5B 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 A4 16 00 00 | success or wait | 625747524 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5da364 | success or wait | 625747743 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C9 45 07 00 00 10 00 00 00 46 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 28 46 00 00 00 60 07 00 00 2C 00 00 00 4A 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 80 A9 01 00 00 B0 07 00 00 AA 01 00 | success or wait | 625747836 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@19232d7 | success or wait | 625748027 | 
| Section loaded | Path: C:\WINDOWS\system32\advapi32.dll Access: query and read Type: commit Baseaddress: C10000 Size: 28672 Protection: readonly Mapped to pid: own pid | success or wait | 625748150 | 
| Process information queried | PID: 1840 Info Class: BasicInformation | success or wait | 625748870 | 
| Memory allocated | PID: 1840 Path: C:\WINDOWS\system32\alg.exe Base: BAD0000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 625749147 | 
| Memory attributes changed | PID: 1840 Path: C:\WINDOWS\system32\alg.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 625749286 | 
| Memory attributes changed | PID: 1840 Path: C:\WINDOWS\system32\alg.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 625749447 | 
| Memory attributes changed | PID: 1840 Path: C:\WINDOWS\system32\alg.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 625749587 | 
| Memory written | PID: 1840 Path: C:\WINDOWS\system32\alg.exe Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 626658142 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 626662631 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 626662776 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 626663330 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 626663744 | 
| Memory written | PID: 1840 Path: C:\WINDOWS\system32\alg.exe Base: BADE920 Length: 13 Value: B8 00 00 00 00 50 BA D5 4E AF 0B FF D2 | success or wait | 626672717 | 
| Memory allocated | PID: 1840 Path: C:\WINDOWS\system32\alg.exe Base: 950000 Length: D6FBD8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 626681007 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 77DEE360 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 626682252 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BB97438 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 626683916 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 626684691 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 626685587 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 626685845 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 626686235 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 626686487 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 626687099 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 77AEFF8F Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 626687680 | 
| File opened | Path: C:\WINDOWS\system32\CRYPT32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 626688673 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@147e4f0 | success or wait | 626689520 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 626689779 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1074938 | success or wait | 626691930 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D7 A0 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 626692191 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 44 08 00 00 DC 00 00 00 00 00 00 32 16 00 00 00 10 00 00 00 20 08 00 00 00 A8 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 50 09 00 00 04 00 00 30 C5 09 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 9C 1A 00 00 | success or wait | 626692498 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1580757 | success or wait | 626693102 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C4 43 08 00 00 10 00 00 00 44 08 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 E8 23 00 00 00 60 08 00 00 24 00 00 00 48 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 50 67 00 00 00 90 08 00 00 68 00 00 | success or wait | 626693359 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@4a11a8 | success or wait | 626693886 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and read Type: commit Baseaddress: C90000 Size: 77824 Protection: readonly Mapped to pid: own pid | success or wait | 626694223 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 626695575 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 626696488 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 77AEFF8F Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 626700371 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BB956E0 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 626700673 | 
| Mutant created | Name: \BaseNamedObjects\Global\ch971pGLCYGJFFTTU5XPPGQTZJ8OdYB | success or wait | 626701062 | 
| Thread created | PID: 1552 TID: 1468 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 626703690 | 
| Thread resumed | TID: 1468 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 626704468 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 626706389 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 626706543 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: C10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 626707162 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 626707442 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 626708288 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 626709054 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 626710536 | 
| File opened | Path: C:\WINDOWS\system32\ws2_32.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 626711210 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and write and read and execute and extend size Type: image Baseaddress: C90000 Size: 94208 Protection: readonly Mapped to pid: own pid | image not at base | 626712793 | 
| Thread created | PID: 1552 TID: 220 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 626718427 | 
| Thread resumed | TID: 220 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 626725323 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 626732704 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 626733745 | 
| Memory written | PID: 1840 Path: C:\WINDOWS\system32\alg.exe Base: 950000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A | success or wait | 626752894 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: C94211 Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 626753320 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 626753548 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 626755374 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 626756567 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 626757567 | 
| Memory attributes changed | PID: 1840 Path: C:\WINDOWS\system32\alg.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 626761794 | 
| Memory written | PID: 1840 Path: C:\WINDOWS\system32\alg.exe Base: 7C90CFEE Length: 5 Value: E9 BF 33 04 84 | success or wait | 626776058 | 
| Section loaded | Path: C:\WINDOWS\system32\winrnr.dll Access: write and read and execute Type: commit Baseaddress: BC0000 Size: 20480 Protection: execute Mapped to pid: own pid | success or wait | 626776834 | 
| Section loaded | Path: C:\WINDOWS\system32\winrnr.dll Access: query and write and read and execute Type: image Baseaddress: 76FB0000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 626781291 | 
| Process information queried | PID: 1924 Info Class: BasicInformation | success or wait | 626783717 | 
| Memory allocated | PID: 1924 Path: C:\WINDOWS\system32\wscntfy.exe Base: BAD0000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 626794376 | 
| Memory attributes changed | PID: 1924 Path: C:\WINDOWS\system32\wscntfy.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 626794872 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 626795038 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 626795327 | 
| Memory attributes changed | PID: 1924 Path: C:\WINDOWS\system32\wscntfy.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 626796517 | 
| Memory attributes changed | PID: 1924 Path: C:\WINDOWS\system32\wscntfy.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 626796908 | 
| Memory written | PID: 1924 Path: C:\WINDOWS\system32\wscntfy.exe Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 627556883 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 627562321 | 
| Memory written | PID: 1924 Path: C:\WINDOWS\system32\wscntfy.exe Base: BADE920 Length: 13 Value: B8 00 00 00 00 50 BA D5 4E AF 0B FF D2 | success or wait | 627589329 | 
| File opened | Path: C:\WINDOWS\system32\ws2_32.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 627589558 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and write and read and execute and extend size Type: image Baseaddress: BC0000 Size: 94208 Protection: readonly Mapped to pid: own pid | image not at base | 627590432 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BC4A07 Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 627591241 | 
| Memory allocated | PID: 1924 Path: C:\WINDOWS\system32\wscntfy.exe Base: AE0000 Length: D6FBD8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 627596776 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 627597867 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 627598628 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 627598886 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 627599277 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 627599531 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 627599834 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 627600433 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 627600685 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 627601062 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: BE0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 627601398 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 627609687 | 
| File opened | Path: C:\WINDOWS\system32\ws2_32.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 627610015 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and write and read and execute and extend size Type: image Baseaddress: BC0000 Size: 94208 Protection: readonly Mapped to pid: own pid | image not at base | 627610871 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BC4C27 Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 627611669 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 627614790 | 
| File opened | Path: C:\WINDOWS\system32\ws2_32.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 627615122 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and write and read and execute and extend size Type: image Baseaddress: BC0000 Size: 94208 Protection: readonly Mapped to pid: own pid | image not at base | 627615973 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BC3E2B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 627616760 | 
| Memory written | PID: 1924 Path: C:\WINDOWS\system32\wscntfy.exe Base: AE0000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A | success or wait | 627640527 | 
| Key created | Path: HKEY_USERS\SOFTWARE\Microsoft Windows | success or wait | 627646866 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 627652502 | 
| Memory attributes changed | PID: 1924 Path: C:\WINDOWS\system32\wscntfy.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 627656564 | 
| Memory written | PID: 1924 Path: C:\WINDOWS\system32\wscntfy.exe Base: 7C90CFEE Length: 5 Value: E9 BF 33 1D 84 | success or wait | 627677833 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 627678090 | 
| Process information queried | PID: 288 Info Class: BasicInformation | success or wait | 627682391 | 
| Memory allocated | PID: 288 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 627683137 | 
| Memory attributes changed | PID: 288 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 627683521 | 
| Memory attributes changed | PID: 288 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 627684044 | 
| Memory attributes changed | PID: 288 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 627684434 | 
| Memory written | PID: 288 Path: C:\WINDOWS\system32\svchost.exe Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 628997289 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 628999945 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 629000210 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 629001118 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 629001726 | 
| Memory written | PID: 288 Path: C:\WINDOWS\system32\svchost.exe Base: BADE920 Length: 13 Value: B8 00 00 00 00 50 BA D5 4E AF 0B FF D2 | success or wait | 629069308 | 
| Memory allocated | PID: 288 Path: C:\WINDOWS\system32\svchost.exe Base: 960000 Length: D6FBD8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 629103806 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 629371796 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 629453236 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 629453338 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 629453490 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 629453890 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 629453997 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 629454208 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 629454295 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 629454478 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: BC0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 629454594 | 
| Memory written | PID: 288 Path: C:\WINDOWS\system32\svchost.exe Base: 960000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A | success or wait | 629466843 | 
| Memory attributes changed | PID: 288 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 629467029 | 
| Memory written | PID: 288 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 5 Value: E9 BF 33 05 84 | success or wait | 629474652 | 
| Process information queried | PID: 172 Info Class: BasicInformation | success or wait | 629475067 | 
| Memory allocated | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BAD0000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 629475315 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629475429 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629475589 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629475699 | 
| Memory written | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 630131755 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 630132025 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 630132078 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 630132238 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 630132389 | 
| Memory written | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BADE920 Length: 13 Value: B8 00 00 00 00 50 BA D5 4E AF 0B FF D2 | success or wait | 630139151 | 
| Memory allocated | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: C00000 Length: D6FBD8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 630139256 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 630139656 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 630139923 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 630140017 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 630140163 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 630140254 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 630140377 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 630140579 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 630140692 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 630140888 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: BC0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 630141010 | 
| Memory written | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: C00000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A | success or wait | 630150743 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 630150870 | 
| Memory written | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 7C90CFEE Length: 5 Value: E9 BF 33 2F 84 | success or wait | 630157146 | 
| Process information queried | PID: 1164 Info Class: BasicInformation | success or wait | 630157578 | 
| Memory allocated | PID: 1164 Path: C:\WINDOWS\system32\dllhost.exe Base: BAD0000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 630157840 | 
| Memory attributes changed | PID: 1164 Path: C:\WINDOWS\system32\dllhost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 630157954 | 
| Memory attributes changed | PID: 1164 Path: C:\WINDOWS\system32\dllhost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 630158080 | 
| Memory attributes changed | PID: 1164 Path: C:\WINDOWS\system32\dllhost.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 630158193 | 
| Memory written | PID: 1164 Path: C:\WINDOWS\system32\dllhost.exe Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 631168111 | 
| Memory written | PID: 1164 Path: C:\WINDOWS\system32\dllhost.exe Base: BADE920 Length: 13 Value: B8 00 00 00 00 50 BA D5 4E AF 0B FF D2 | success or wait | 631175551 | 
| Memory allocated | PID: 1164 Path: C:\WINDOWS\system32\dllhost.exe Base: 980000 Length: D6FBD8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 631175655 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 631176052 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 631176408 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 631176502 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 631176741 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 631176833 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 631176943 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 631177161 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 631177251 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 631177444 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: BC0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 631177565 | 
| Memory written | PID: 1164 Path: C:\WINDOWS\system32\dllhost.exe Base: 980000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A | success or wait | 631186968 | 
| Memory attributes changed | PID: 1164 Path: C:\WINDOWS\system32\dllhost.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 631187096 | 
| Memory written | PID: 1164 Path: C:\WINDOWS\system32\dllhost.exe Base: 7C90CFEE Length: 5 Value: E9 BF 33 07 84 | success or wait | 631193963 | 
| Process information queried | PID: 376 Info Class: BasicInformation | success or wait | 631194368 | 
| Memory allocated | PID: 376 Path: C:\WINDOWS\system32\msdtc.exe Base: BAD0000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 631194626 | 
| Memory attributes changed | PID: 376 Path: C:\WINDOWS\system32\msdtc.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 631194741 | 
| Memory attributes changed | PID: 376 Path: C:\WINDOWS\system32\msdtc.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 631194907 | 
| Memory attributes changed | PID: 376 Path: C:\WINDOWS\system32\msdtc.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 631195020 | 
| Memory written | PID: 376 Path: C:\WINDOWS\system32\msdtc.exe Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 631920541 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 631921436 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 631921489 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 631921680 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 631921833 | 
| Memory written | PID: 376 Path: C:\WINDOWS\system32\msdtc.exe Base: BADE920 Length: 13 Value: B8 00 00 00 00 50 BA D5 4E AF 0B FF D2 | success or wait | 631927588 | 
| Memory allocated | PID: 376 Path: C:\WINDOWS\system32\msdtc.exe Base: 7E0000 Length: D6FBD8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 631927753 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 631928450 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 631928714 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 631928816 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 631928985 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 631929076 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 631929186 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 631929430 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 631929533 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 631929776 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: BC0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 631929897 | 
| Memory written | PID: 376 Path: C:\WINDOWS\system32\msdtc.exe Base: 7E0000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A | success or wait | 631941176 | 
| Memory attributes changed | PID: 376 Path: C:\WINDOWS\system32\msdtc.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 631941339 | 
| Memory written | PID: 376 Path: C:\WINDOWS\system32\msdtc.exe Base: 7C90CFEE Length: 5 Value: E9 BF 33 ED 83 | success or wait | 631948092 | 
| Process information queried | PID: 1452 Info Class: BasicInformation | success or wait | 631948494 | 
| Memory allocated | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BAD0000 Length: D6FBA8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 631948747 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 631948862 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 631949029 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 631949142 | 
| Memory written | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 632951568 | 
| Memory written | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BADE920 Length: 13 Value: B8 00 00 00 00 50 BA D5 4E AF 0B FF D2 | success or wait | 632959023 | 
| Memory allocated | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3B0000 Length: D6FBD8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 632959401 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 632959804 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e15497 | success or wait | 632960162 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 632960256 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@178986b | success or wait | 632960714 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 632960806 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 632960917 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5ebc6e | success or wait | 632961135 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 632961226 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a51364 | success or wait | 632961417 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: BC0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 632961540 | 
| Memory written | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3B0000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A | success or wait | 632970902 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 632971084 | 
| Memory written | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 7C90CFEE Length: 5 Value: E9 BF 33 AA 83 | success or wait | 632977210 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 632978201 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 632978591 | 
| Memory allocated | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BC0000 Length: D6FA60 Allocation Type: unknown Protection: page execute and read and write | success or wait | 632986105 | 
| Thread created | PID: 1552 TID: 1616 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 632987197 | 
| Thread resumed | TID: 1616 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 632987493 | 
| Memory allocated | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BD0000 Length: D6FA60 Allocation Type: unknown Protection: page execute and read and write | success or wait | 632987664 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 632988416 | 
| Process information queried | PID: 1552 Info Class: Cookie | success or wait | 632988518 | 
| Thread created | PID: 1552 TID: 1500 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 632990435 | 
| Thread resumed | TID: 1500 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 632990726 | 
| Thread created | PID: 1552 TID: 1652 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 632991403 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 632993232 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 632993283 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 632993437 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 632993587 | 
| Thread resumed | TID: 240 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 632993919 | 
| Thread resumed | TID: 1652 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 632994904 | 
| Thread created | PID: 1552 TID: 1756 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 632996297 | 
| Thread resumed | TID: 1756 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 632996559 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: normal Content Overwritten: null | success or wait | 632998481 | 
| File other op | Path: C:\Recycle.Bin\5CBD14A05E0D693New path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@cd32e5 | success or wait | 632999707 | 
| Thread delayed | Time: -371 TID: 1756 | unknown | 633001153 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 4 Value: 9E 13 6A E8 | success or wait | 633002312 | 
| File opened | Path: C:\Recycle.Bin\B6232F3AC2C.exe Access: read attributes and synchronize and generic write Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 633002651 | 
| File read | Path: C:\Recycle.Bin\B6232F3AC2C.exe Offset: unknown Length: 196096 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 70 72 6F 67 72 61 6D 20 63 61 6E 6E 6F 74 20 62 65 | success or wait | 633003086 | 
| File opened | Path: C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\profiles.ini Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | object name not found | 633176360 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 633247434 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 633280020 | 
| Thread delayed | Time: -922337203685 TID: 1024 | unknown | 633288823 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 633292348 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 633298723 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 633299027 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 633299885 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B1D690 Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633300642 | 
| Thread created | PID: 1552 TID: 2016 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 633731705 | 
| Thread resumed | TID: 2016 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 633732417 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 633746459 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 633770336 | 
| Thread created | PID: 1552 TID: 236 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 634053025 | 
| Thread resumed | TID: 236 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 634053660 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 634057903 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 634082427 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 634112282 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 634112411 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 634112781 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 634113155 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 635230920 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 635231178 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 635231631 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 635232071 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 636349522 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 636349779 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 636350237 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 636350678 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 637468205 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 637468494 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 637469016 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 637469508 | 
| Thread delayed | Time: 0 TID: 116 | success or wait | 638586797 | 
| Thread created | PID: 1552 TID: 2180 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 654443803 | 
| Thread resumed | TID: 2180 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 654445363 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 654452041 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 654470121 | 
| Thread created | PID: 1552 TID: 2216 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 654687809 | 
| Thread resumed | TID: 2216 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 654688491 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 654698656 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 654725678 | 
| Thread created | PID: 1552 TID: 2232 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 654823222 | 
| Thread resumed | TID: 2232 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 654823913 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 654828606 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 654855357 | 
| Thread created | PID: 1552 TID: 2268 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 655746601 | 
| Thread resumed | TID: 2268 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 655747313 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 655750334 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 655779115 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 659885115 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 659886446 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 659887915 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0DEAE Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 659888226 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 659899613 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 659899730 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 659900053 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0D508 Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 659900347 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 659900961 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 659901080 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 659901396 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B1EE89 Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 659901688 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1c882db | success or wait | 659916928 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1070723 | success or wait | 659917380 | 
| File other op | Path: C:\Documents and Settings\Administrator\IETldCacheNew path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@65b778 | success or wait | 659934293 | 
| File other op | Path: C:\Documents and Settings\Administrator\IETldCache\index.datNew path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f02eaa | success or wait | 659938133 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_IETldCache_index.dat_262144 Access: write Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 659938633 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_IETldCache_index.dat_262144 Access: query and write and read Type: commit Baseaddress: 2AA0000 Size: 262144 Protection: read write Mapped to pid: own pid | success or wait | 659939483 | 
| Thread created | PID: 1552 TID: 2672 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 660366303 | 
| Thread resumed | TID: 2672 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 660367030 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 660369912 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 660397552 | 
| Section loaded | Path: \BaseNamedObjects\CTF.AsmListCache.FMPDefaultS-1-5-21-507921405-1960408961-839522115-500 Access: query and write and read and execute and extend size Type: unknown Baseaddress: BE0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 660875763 | 
| Process information queried | PID: 1728 Info Class: BasicInformation | success or wait | 660879109 | 
| Section loaded | Path: \BaseNamedObjects\CTF.AsmListCache.FMPDefaultS-1-5-21-507921405-1960408961-839522115-500 Access: query and write and read and execute and extend size Type: unknown Baseaddress: BE0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 660880950 | 
| Process information queried | PID: 1728 Info Class: BasicInformation | success or wait | 660884069 | 
| Thread created | PID: 1552 TID: 2880 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 666621136 | 
| Thread resumed | TID: 2880 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 666621759 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 666624351 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 666646187 | 
| Thread delayed | Time: -1 TID: 1808 | success or wait | 668618285 | 
| Process information queried | PID: 1552 Info Class: DefaultHardErrorMode | success or wait | 672156086 | 
| Process information queried | PID: 1552 Info Class: DefaultHardErrorMode | success or wait | 672156572 | 
| Thread delayed | Time: -1 TID: 1808 | success or wait | 672676264 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@187b796 | success or wait | 674597089 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@187b796 | success or wait | 674598135 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@126172f | success or wait | 674598579 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1bc2e06 | success or wait | 674599926 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@17193fc | success or wait | 674608608 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1aa8b42 | success or wait | 674609062 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@19cc1e3 | success or wait | 674610460 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7d5b6e | success or wait | 674610905 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@19cc1e3 | success or wait | 674611796 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1fdbe17 | success or wait | 674620187 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1cb1278 | success or wait | 674620635 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1fdbe17 | success or wait | 674621529 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@129aa21 | success or wait | 674622437 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@6076c4 | success or wait | 674622880 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@129aa21 | success or wait | 674624430 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@17193fc | success or wait | 674624887 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@17193fc | success or wait | 674625336 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@115798c | success or wait | 674625782 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@df0c3a | success or wait | 674626699 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@17193fc | success or wait | 674627599 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@17193fc | success or wait | 674628342 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@19bb448 | success or wait | 674635470 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@17193fc | success or wait | 674636926 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@158fd70 | success or wait | 674637363 | 
| Section loaded | Path: C:\WINDOWS\system32\ieframe.dll Access: query and read Type: commit Baseaddress: BE0000 Size: 69632 Protection: readonly Mapped to pid: own pid | success or wait | 674638303 | 
| File other op | Path: C:\WINDOWS\system32\stdole2.tlbNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@166de66 | success or wait | 675494695 | 
| File other op | Path: C:\WINDOWS\system32\stdole2.tlbNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@166de66 | success or wait | 675495874 | 
| File other op | Path: C:\WINDOWS\system32\stdole2.tlbNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@93068a | success or wait | 675496480 | 
| File other op | Path: C:\WINDOWS\system32\stdole2.tlbNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@928095 | success or wait | 675498005 | 
| Section loaded | Path: C:\WINDOWS\system32\stdole2.tlb Access: query and read Type: commit Baseaddress: C10000 Size: 16384 Protection: readonly Mapped to pid: own pid | success or wait | 675532523 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 0 HWNDs: 201D8, 2003E, 20044, 900A4, 900A8, 90098, 90086, 10076, 10074, 10082, 10070, 3004E, 1008E, 201CA, 201D2 | success or wait | 675622887 | 
| Process information queried | PID: 1552 Info Class: DeviceMap | success or wait | 676087318 | 
| Process information queried | PID: 1552 Info Class: DeviceMap | success or wait | 676089554 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 0 HWNDs: 201D8, 2003E, 20044, 900A4, 900A8, 90098, 90086, 10076, 10074, 10082, 10070, 3004E, 1008E, 201CA, 201D2 | success or wait | 676100370 | 
| Process information queried | PID: 1552 Info Class: DefaultHardErrorMode | success or wait | 676236511 | 
| Process information queried | PID: 1552 Info Class: DefaultHardErrorMode | success or wait | 676237050 | 
| Message sent | HWND: 10084 Message: 41A WParam: 1584 LParam: 70536 | error | 676854181 | 
| Process information queried | PID: 2116 Info Class: BasicInformation | success or wait | 676856455 | 
| Memory read | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7FFD4008 Length: 4 Value: 00 00 40 00 | success or wait | 676858225 | 
| Memory read | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7FFD400C Length: 4 Value: 90 1E 25 00 | success or wait | 676859098 | 
| Memory read | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 251EA4 Length: 4 Value: C8 1E 25 00 | success or wait | 676859551 | 
| Memory read | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 251EC0 Length: 80 Value: 18 1F 25 00 9C 1E 25 00 20 1F 25 00 A4 1E 25 00 00 00 00 00 00 00 00 00 00 00 40 00 25 1A 40 00 00 C0 09 00 5E 00 60 00 B4 05 02 00 18 00 1A 00 FA 05 02 00 00 50 00 00 FF FF 00 00 4C 26 25 00 C0 E2 97 7C 2E AD B3 49 00 00 00 00 00 00 00 00 | success or wait | 676863459 | 
| Memory read | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 205B4 Length: 96 Value: 43 00 3A 00 5C 00 50 00 72 00 6F 00 67 00 72 00 61 00 6D 00 20 00 46 00 69 00 6C 00 65 00 73 00 5C 00 49 00 6E 00 74 00 65 00 72 00 6E 00 65 00 74 00 20 00 45 00 78 00 70 00 6C 00 6F 00 72 00 65 00 72 00 5C 00 49 00 45 00 58 00 50 00 4C 00 4F 00 52 00 45 00 2E 00 45 00 58 00 45 00 00 00 | success or wait | 676865292 | 
| Process information queried | PID: 1552 Info Class: DefaultHardErrorMode | success or wait | 676955392 | 
| Process information queried | PID: 1552 Info Class: DefaultHardErrorMode | success or wait | 676959510 | 
| Process information queried | PID: 1552 Info Class: DefaultHardErrorMode | success or wait | 676960091 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\iexplore.exe Access: write and read and execute Type: commit Baseaddress: 2E70000 Size: 638976 Protection: execute Mapped to pid: own pid | success or wait | 676963233 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\iexplore.exe Access: query and read Type: commit Baseaddress: 2E70000 Size: 638976 Protection: readonly Mapped to pid: own pid | success or wait | 676970622 | 
| Process information queried | PID: 1552 Info Class: DefaultHardErrorMode | success or wait | 676974269 | 
| Process information queried | PID: 1552 Info Class: DefaultHardErrorMode | success or wait | 676986555 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\iexplore.exe Access: write and read and execute Type: commit Baseaddress: 2E70000 Size: 638976 Protection: execute Mapped to pid: own pid | success or wait | 676990708 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\iexplore.exe Access: query and read Type: commit Baseaddress: 2E70000 Size: 638976 Protection: readonly Mapped to pid: own pid | success or wait | 677005841 | 
| Process information queried | PID: 1552 Info Class: DefaultHardErrorMode | success or wait | 677012930 | 
| Message sent | HWND: 120118 Message: GETICON WParam: 2 LParam: 0 | success | 677034709 | 
| Message sent | HWND: 120118 Message: GETICON WParam: 0 LParam: 0 | success | 677034850 | 
| Message sent | HWND: 120118 Message: GETICON WParam: 1 LParam: 0 | success | 677037659 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 0 HWNDs: 201D8, 2003E, 20044, 900A4, 900A8, 90098, 90086, 10076, 10074, 10082, 10070, 3004E, 1008E, 201CE, 201CA | success or wait | 677084629 | 
| Key value replaced with new | Path: HKEY_USERS\SessionInformation Name: ProgramCount Type: dword Data: 1 Old data: 0 | success or wait | 677084850 | 
| Message sent | HWND: 10084 Message: 41A WParam: 0 LParam: 0 | error | 677089975 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 0 HWNDs: 201D8, 2003E, 20044, 900A4, 900A8, 90098, 90086, 10076, 10074, 10082, 10070, 3004E, 1008E, 201CE, 201CA | success or wait | 677093140 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 0 HWNDs: 201D8, 2003E, 20044, 900A4, 900A8, 90098, 90086, 10076, 10074, 10082, 10070, 3004E, 1008E, 201CE, 201CA | buffer too small | 680702733 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 0 HWNDs: 2003E, 20044, 201D8, 900A4, 900A8, 90098, 90086, 10076, 10074, 10082, 10070, 3004E, 1008E, 201C6, 201C8, 201C4 | success or wait | 680702913 | 
| Thread created | PID: 1552 TID: 3712 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 680798113 | 
| Thread resumed | TID: 3712 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 680798462 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 680799462 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 680808566 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 0 HWNDs: 2003E, 20044, 201D8, 900A4, 900A8, 90098, 90086, 10076, 10074, 10082, 10070, 3004E, 1008E, 201C6, 201C8 | buffer too small | 684338499 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 0 HWNDs: 2003E, 20044, 201D8, 900A4, 900A8, 90098, 90086, 10076, 10074, 10082, 10070, 3004E, 1008E, 201C6, 201C8, 201C4 | success or wait | 684340236 | 
| Message sent | HWND: 120118 Message: GETICON WParam: 2 LParam: 0 | success | 685680322 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 0 HWNDs: 2003E, 20044, 201D8, 900A4, 900A8, 90098, 90086, 10076, 10074, 10082, 10070, 3004E, 1008E, 201C6, 201C8 | buffer too small | 687918300 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 0 HWNDs: 2003E, 20044, 201D8, 900A4, 900A8, 90098, 90086, 10076, 10074, 10082, 10070, 3004E, 1008E, 201C6, 201C8, 201C4 | success or wait | 687920115 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 0 HWNDs: 2003E, 20044, 201D8, 900A4, 900A8, 90098, 90086, 10076, 10074, 10082, 10070, 3004E, 1008E, 201C6, 201C8 | buffer too small | 692326052 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 0 HWNDs: 2003E, 20044, 201D8, 900A4, 900A8, 90098, 90086, 10076, 10074, 10082, 10070, 3004E, 1008E, 201C6, 201C8, 201C4 | success or wait | 692357350 | 
| Message sent | HWND: 120118 Message: GETICON WParam: 2 LParam: 0 | success | 694071400 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@187b796 | success or wait | 694284425 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@187b796 | success or wait | 694284836 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@126172f | success or wait | 694284996 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1bc2e06 | success or wait | 694285482 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@17193fc | success or wait | 694286181 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1aa8b42 | success or wait | 694286336 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@19cc1e3 | success or wait | 694286820 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7d5b6e | success or wait | 694286975 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@19cc1e3 | success or wait | 694287286 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1fdbe17 | success or wait | 694287601 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1cb1278 | success or wait | 694287755 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1fdbe17 | success or wait | 694288063 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@129aa21 | success or wait | 694288378 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@6076c4 | success or wait | 694288532 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@129aa21 | success or wait | 694288999 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@17193fc | success or wait | 694289157 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@17193fc | success or wait | 694289312 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@115798c | success or wait | 694289465 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@df0c3a | success or wait | 694289782 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@17193fc | success or wait | 694290093 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@17193fc | success or wait | 694290248 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@19bb448 | success or wait | 694290402 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@17193fc | success or wait | 694290875 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@158fd70 | success or wait | 694291025 | 
| Section loaded | Path: C:\WINDOWS\system32\ieframe.dll Access: query and read Type: commit Baseaddress: BE0000 Size: 69632 Protection: readonly Mapped to pid: own pid | success or wait | 694291352 | 
| Message sent | HWND: 120118 Message: GETICON WParam: 2 LParam: 0 | success | 694683181 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 0 HWNDs: 2003E, 20044, 201D8, 900A4, 900A8, 90098, 90086, 10076, 10074, 10082, 10070, 3004E, 1008E, 201C6, 201C8 | buffer too small | 695922759 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 0 HWNDs: 2003E, 20044, 201D8, 900A4, 900A8, 90098, 90086, 10076, 10074, 10082, 10070, 3004E, 1008E, 201C6, 201C8, 201B0 | success or wait | 695923535 | 
| Message sent | HWND: 120118 Message: GETICON WParam: 2 LParam: 0 | success | 697178048 | 
| Thread created | PID: 1552 TID: 2464 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 709527332 | 
| Thread resumed | TID: 2464 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 709527926 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 709528994 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 709538894 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 712834694 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 712834909 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 712835645 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B09088 Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 712836057 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 712837323 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 712837441 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 712838322 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B09088 Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 712838885 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 712842821 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 712842939 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 712843255 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0DEAE Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 712843548 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 712847207 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 712847324 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 712847642 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0D508 Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 712847931 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 712849404 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 712849523 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 712849841 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B1EE89 Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 712850133 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Cookies_index.dat_32768 Access: write Type: unknown Baseaddress: BE0000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 712860187 | 
| Section loaded | Path: \KnownDlls\MPRAPI.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 712880851 | 
| Section loaded | Path: C:\WINDOWS\system32\mprapi.dll Access: query and write and read and execute Type: image Baseaddress: 76D40000 Size: 98304 Protection: read write Mapped to pid: own pid | success or wait | 712881640 | 
| Section loaded | Path: \KnownDlls\ACTIVEDS.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 712883210 | 
| Section loaded | Path: C:\WINDOWS\system32\activeds.dll Access: query and write and read and execute Type: image Baseaddress: 77CC0000 Size: 204800 Protection: read write Mapped to pid: own pid | success or wait | 712884627 | 
| Section loaded | Path: \KnownDlls\adsldpc.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 712886305 | 
| Section loaded | Path: C:\WINDOWS\system32\adsldpc.dll Access: query and write and read and execute Type: image Baseaddress: 76E10000 Size: 151552 Protection: read write Mapped to pid: own pid | success or wait | 712887168 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 718198681 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 718199098 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 718200013 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0BF83 Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 718200847 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 718226153 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 718226482 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 718227338 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 718228134 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 718491876 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 718492205 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 718493075 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 718493926 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 719468101 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 719468437 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 719469331 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 719470154 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 719481382 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 719487483 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 719497797 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 719568689 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 720223335 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 720223680 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 720224553 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 720225456 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 720683575 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 720683905 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 720684767 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 720685574 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 720733161 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 720733492 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 720734352 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 720735151 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 721128132 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 721128473 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 721129386 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 721130222 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 721364860 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 721365162 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 721365980 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 721367180 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 723238479 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 723243367 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 723246077 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 723249269 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 723257538 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 723258518 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 723261630 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 723264003 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 723274453 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 723276857 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 723277479 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 723281043 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 723285420 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 723288522 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 723289874 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 723297617 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 723305454 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 723306391 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 723308494 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 723311687 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 723318089 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 723319728 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 723321897 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 723329418 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 723342502 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 723345668 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 723347670 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 723353142 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 723647985 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 723651108 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 723652120 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 723670024 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 723678252 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 723681091 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 723687713 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 723691205 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 723706812 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 723707140 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 723708521 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 723712525 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 723785630 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 723785758 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 723786077 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 723786371 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 723945901 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 723946018 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 723946343 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 723946634 | 
| Process information queried | PID: 1552 Info Class: DeviceMap | success or wait | 723949719 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 0 HWNDs: 2003E, 20044, 201D8, 900A4, 900A8, 90098, 90086, 10076, 10074, 10082, 10070, 3004E, 1008E, 201C6, 201C8 | buffer too small | 723962435 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 0 HWNDs: 2003E, 20044, 201D8, 900A4, 900A8, 90098, 90086, 10076, 10074, 10082, 10070, 3004E, 1008E, 201C6, 201C8, 40176, 901AA, 201C0 | success or wait | 723962606 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 724085122 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 724085240 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 724085574 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 724085906 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 724226178 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 724226297 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 724226638 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 724226945 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 724232584 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 724232702 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 724233018 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 724233303 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 724382025 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 724382142 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 724382457 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 724382743 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 724551226 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 724551352 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 724551728 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 724552037 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 724631087 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 724631217 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 724631533 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 724631819 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 724933371 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 724933500 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 724933815 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 724934102 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 725012871 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 725012990 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 725013310 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 725013595 | 
| Process information queried | PID: 1552 Info Class: Wow64Information | success or wait | 725270136 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 725270258 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 725270608 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 725270918 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 725350125 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 725350435 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 725350717 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 725458580 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 725458892 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 725459175 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 725656336 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 725656649 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 725656930 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 725751544 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 725751857 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 725752139 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 725884413 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 725884726 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 725885011 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 725980681 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 725980994 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 725981280 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 726117162 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 726117675 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 726117973 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 726118789 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 726119096 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 726119375 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 726199805 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 726200116 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 726200397 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 726225057 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 726225367 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 726225662 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 726341262 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 726341642 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 726375889 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 726376171 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 726455210 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 726455492 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 726475354 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B0654B Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 726475632 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 726476926 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B09088 Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 726477206 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2AF0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 726478093 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 2B09088 Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 726478369 | 
| Thread created | PID: 1552 TID: 3280 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 737665046 | 
| Thread resumed | TID: 3280 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 737668149 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 737674992 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 737694543 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 0 HWNDs: 2003E, 20044, 201D8, 900A4, 900A8, 90098, 90086, 10076, 10074, 10082, 10070, 3004E, 1008E, 201C6, 201C8 | buffer too small | 739368987 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 0 HWNDs: 2003E, 20044, 201D8, 900A4, 900A8, 90098, 90086, 10076, 10074, 10082, 10070, 3004E, 1008E, 201C6, 201C8, 40176, 901AA, 30214 | success or wait | 739369172 | 
| Thread resumed | TID: 3348 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 739527681 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 0 HWNDs: 2003E, 20044, 201D8, 900A4, 900A8, 90098, 90086, 10076, 10074, 10082, 10070, 3004E, 1008E, 201C6, 201C8 | buffer too small | 740020486 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 0 HWNDs: 2003E, 20044, 201D8, 900A4, 900A8, 90098, 90086, 10076, 10074, 10082, 10070, 3004E, 1008E, 201C6, 201C8, 40176, 901AA, 3021C | success or wait | 740020668 | 
| Thread created | PID: 1552 TID: 3460 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 741245896 | 
| Thread resumed | TID: 3460 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 741249603 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 741256078 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 741274088 | 
| Thread created | PID: 1552 TID: 3464 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 741310486 | 
| Thread resumed | TID: 3464 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 741312021 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 741315698 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 741330018 | 
| Thread created | PID: 1552 TID: 3628 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 759531955 | 
| Thread resumed | TID: 3628 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 759535370 | 
| Thread created | PID: 1552 TID: 3632 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 759539111 | 
| Thread resumed | TID: 3632 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 759540778 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 759544661 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 759573892 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 759603411 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 759619256 | 
| Thread created | PID: 1552 TID: 3660 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 760660366 | 
| Thread resumed | TID: 3660 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 760661494 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 760663835 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 760688836 | 
| Thread created | PID: 1552 TID: 3684 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 764014602 | 
| Thread resumed | TID: 3684 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 764017417 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 764020981 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 764037757 | 
| Thread created | PID: 1552 TID: 3760 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 767361226 | 
| Thread resumed | TID: 3760 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 767362375 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 767364952 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 767386942 | 
| Thread created | PID: 1552 TID: 3800 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 774074927 | 
| Thread resumed | TID: 3800 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 774076168 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 774078745 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 774105227 | 
| Thread created | PID: 1552 TID: 3908 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 788226552 | 
| Thread resumed | TID: 3908 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 788227066 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 788229744 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 788255616 | 
| Thread created | PID: 1552 TID: 4004 EIP: 7C8106F9 Imagepath: C:\WINDOWS\explorer.exe | success or wait | 796709507 | 
| Thread resumed | TID: 4004 PID: 1552 Path: C:\WINDOWS\explorer.exe | success or wait | 796711443 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 796714036 | 
| File write | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 796740787 | 
| Sections | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Section Activities: 
 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Process Activities: 
 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Thread Activities: 
 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Memory Activities: 
 
 
 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Section loaded | Path: \KnownDlls\kernel32.dll Access: write and read and execute Type: unknown Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid | success or wait | 602192200 | 
| Process information queried | PID: 188 Info Class: Cookie | success or wait | 602201651 | 
| Section loaded | Path: unknown Access: query and write and read and execute and extend size Type: reserve Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid | success or wait | 602203056 | 
| Section loaded | Path: \NLS\NlsSectionUnicode Access: read Type: unknown Baseaddress: 260000 Size: 90112 Protection: readonly Mapped to pid: own pid | success or wait | 602209649 | 
| Section loaded | Path: \NLS\NlsSectionLocale Access: read Type: unknown Baseaddress: 280000 Size: 266240 Protection: readonly Mapped to pid: own pid | success or wait | 602214613 | 
| Section loaded | Path: \NLS\NlsSectionSortkey Access: query and read Type: unknown Baseaddress: 2D0000 Size: 266240 Protection: readonly Mapped to pid: own pid | success or wait | 602216679 | 
| Section loaded | Path: \NLS\NlsSectionSortTbls Access: read Type: unknown Baseaddress: 320000 Size: 24576 Protection: readonly Mapped to pid: own pid | success or wait | 602217943 | 
| Section loaded | Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 602220448 | 
| Section loaded | Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 602220822 | 
| Process information queried | PID: 188 Info Class: ImageInformation | success or wait | 602225446 | 
| Memory allocated | PID: 188 Path: C:\Recycle.Bin\B6232F3AC2C.exe Base: 330000 Length: 12FE80 Allocation Type: unknown Protection: page read and write | success or wait | 602234445 | 
| Memory allocated | PID: 188 Path: C:\Recycle.Bin\B6232F3AC2C.exe Base: 330000 Length: 12FE84 Allocation Type: unknown Protection: page read and write | success or wait | 602236822 | 
| Memory attributes changed | PID: 188 Path: C:\Recycle.Bin\B6232F3AC2C.exe Base: 401000 Length: 5000 New Protection: page read and write New Protection: page execute read | success or wait | 602237584 | 
| Section loaded | Path: \KnownDlls\Wininet.dll Access: write and read and execute Type: unknown Baseaddress: 3D930000 Size: 942080 Protection: read write Mapped to pid: own pid | success or wait | 602239292 | 
| Section loaded | Path: \KnownDlls\msvcrt.dll Access: write and read and execute Type: unknown Baseaddress: 77C10000 Size: 360448 Protection: read write Mapped to pid: own pid | success or wait | 602242362 | 
| Section loaded | Path: \KnownDlls\SHLWAPI.dll Access: write and read and execute Type: unknown Baseaddress: 77F60000 Size: 483328 Protection: read write Mapped to pid: own pid | success or wait | 602252804 | 
| Section loaded | Path: \KnownDlls\ADVAPI32.dll Access: write and read and execute Type: unknown Baseaddress: 77DD0000 Size: 634880 Protection: read write Mapped to pid: own pid | success or wait | 602254615 | 
| Section loaded | Path: \KnownDlls\RPCRT4.dll Access: write and read and execute Type: unknown Baseaddress: 77E70000 Size: 602112 Protection: read write Mapped to pid: own pid | success or wait | 602263026 | 
| Section loaded | Path: \KnownDlls\Secur32.dll Access: write and read and execute Type: unknown Baseaddress: 77FE0000 Size: 69632 Protection: read write Mapped to pid: own pid | success or wait | 602271100 | 
| Section loaded | Path: \KnownDlls\GDI32.dll Access: write and read and execute Type: unknown Baseaddress: 77F10000 Size: 299008 Protection: read write Mapped to pid: own pid | success or wait | 602279014 | 
| Section loaded | Path: \KnownDlls\USER32.dll Access: write and read and execute Type: unknown Baseaddress: 7E410000 Size: 593920 Protection: read write Mapped to pid: own pid | success or wait | 602282546 | 
| Section loaded | Path: \KnownDlls\Normaliz.dll Access: write and read and execute Type: unknown Baseaddress: 340000 Size: 36864 Protection: read write Mapped to pid: own pid | conflicting addresses | 602295080 | 
| Section loaded | Path: \KnownDlls\urlmon.dll Access: write and read and execute Type: unknown Baseaddress: 78130000 Size: 1257472 Protection: read write Mapped to pid: own pid | success or wait | 602301964 | 
| Section loaded | Path: \KnownDlls\ole32.dll Access: write and read and execute Type: unknown Baseaddress: 774E0000 Size: 1302528 Protection: read write Mapped to pid: own pid | success or wait | 602305172 | 
| Section loaded | Path: \KnownDlls\OLEAUT32.dll Access: write and read and execute Type: unknown Baseaddress: 77120000 Size: 569344 Protection: read write Mapped to pid: own pid | success or wait | 602313549 | 
| Section loaded | Path: \KnownDlls\iertutil.dll Access: write and read and execute Type: unknown Baseaddress: 3DFD0000 Size: 2002944 Protection: read write Mapped to pid: own pid | success or wait | 602325267 | 
| Section loaded | Path: \NLS\NlsSectionCType Access: read Type: unknown Baseaddress: 360000 Size: 12288 Protection: readonly Mapped to pid: own pid | success or wait | 602338054 | 
| Process information queried | PID: 188 Info Class: Cookie | success or wait | 602341099 | 
| Process information queried | PID: 188 Info Class: Cookie | success or wait | 602341382 | 
| Section loaded | Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit Baseaddress: 370000 Size: 110592 Protection: execute Mapped to pid: own pid | success or wait | 602348513 | 
| Section loaded | Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit Baseaddress: 370000 Size: 110592 Protection: execute Mapped to pid: own pid | success or wait | 602351724 | 
| Section loaded | Path: C:\WINDOWS\system32\imm32.dll Access: query and write and read and execute Type: image Baseaddress: 76390000 Size: 118784 Protection: read write Mapped to pid: own pid | success or wait | 602354434 | 
| Section loaded | Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll Access: write and read and execute Type: commit Baseaddress: 920000 Size: 1056768 Protection: execute Mapped to pid: own pid | success or wait | 602423404 | 
| Section loaded | Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll Access: query and write and read and execute Type: image Baseaddress: 773D0000 Size: 1060864 Protection: read write Mapped to pid: own pid | success or wait | 602426692 | 
| Section loaded | Path: C:\WINDOWS\WindowsShell.Manifest Access: write and read and execute Type: commit Baseaddress: 3A0000 Size: 4096 Protection: execute Mapped to pid: own pid | success or wait | 602436869 | 
| Section loaded | Path: C:\WINDOWS\WindowsShell.Manifest Access: query and read Type: commit Baseaddress: 3A0000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 602440689 | 
| Section loaded | Path: C:\WINDOWS\WindowsShell.Manifest Access: read Type: commit Baseaddress: 3A0000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 602443831 | 
| Process information queried | PID: 188 Info Class: Wow64Information | success or wait | 602562764 | 
| Section loaded | Path: \KnownDlls\SHELL32.dll Access: write and read and execute Type: unknown Baseaddress: 7C9C0000 Size: 8482816 Protection: read write Mapped to pid: own pid | success or wait | 602571940 | 
| Section loaded | Path: C:\WINDOWS\system32\shell32.dll Access: read Type: commit Baseaddress: B20000 Size: 8462336 Protection: readonly Mapped to pid: own pid | success or wait | 602585260 | 
| Section loaded | Path: \KnownDlls\comctl32.dll Access: write and read and execute Type: unknown Baseaddress: 5D090000 Size: 630784 Protection: read write Mapped to pid: own pid | success or wait | 602619810 | 
| Section loaded | Path: C:\WINDOWS\system32\comctl32.dll Access: read Type: commit Baseaddress: B20000 Size: 618496 Protection: readonly Mapped to pid: own pid | success or wait | 602632490 | 
| Process information queried | PID: 188 Info Class: SessionInformation | success or wait | 602641863 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Local Settings_Temporary Internet Files_Content.IE5_index.dat_32768 Access: write Type: unknown Baseaddress: 3F0000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 602685727 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Cookies_index.dat_16384 Access: write Type: unknown Baseaddress: B20000 Size: 16384 Protection: read write Mapped to pid: own pid | success or wait | 602691705 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Local Settings_History_History.IE5_index.dat_32768 Access: write Type: unknown Baseaddress: B30000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 602697357 | 
| Section loaded | Path: \KnownDlls\ws2_32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 602796587 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and write and read and execute Type: image Baseaddress: 71AB0000 Size: 94208 Protection: read write Mapped to pid: own pid | success or wait | 602798178 | 
| Section loaded | Path: \KnownDlls\WS2HELP.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 602803221 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2help.dll Access: query and write and read and execute Type: image Baseaddress: 71AA0000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 602804859 | 
| Section loaded | Path: \KnownDlls\VERSION.dll Access: write and read and execute Type: unknown Baseaddress: 77C00000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 602894575 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 602898606 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 602899337 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 602900513 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 602901126 | 
| Section loaded | Path: \BaseNamedObjects\Local\UrlZonesSM_Administrator Access: query and write and read Type: commit Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name exists | 602921265 | 
| Section loaded | Path: \KnownDlls\RASAPI32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 602966406 | 
| Section loaded | Path: C:\WINDOWS\system32\rasapi32.dll Access: query and write and read and execute Type: image Baseaddress: 76EE0000 Size: 245760 Protection: read write Mapped to pid: own pid | success or wait | 602968226 | 
| Section loaded | Path: \KnownDlls\rasman.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 602974387 | 
| Section loaded | Path: C:\WINDOWS\system32\rasman.dll Access: query and write and read and execute Type: image Baseaddress: 76E90000 Size: 73728 Protection: read write Mapped to pid: own pid | success or wait | 602976215 | 
| Section loaded | Path: \KnownDlls\NETAPI32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 602981881 | 
| Section loaded | Path: C:\WINDOWS\system32\netapi32.dll Access: query and write and read and execute Type: image Baseaddress: 5B860000 Size: 348160 Protection: read write Mapped to pid: own pid | success or wait | 602983795 | 
| Section loaded | Path: \KnownDlls\TAPI32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 602995775 | 
| Section loaded | Path: C:\WINDOWS\system32\tapi32.dll Access: query and write and read and execute Type: image Baseaddress: 76EB0000 Size: 192512 Protection: read write Mapped to pid: own pid | success or wait | 602997597 | 
| Section loaded | Path: \KnownDlls\rtutils.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 603005133 | 
| Section loaded | Path: C:\WINDOWS\system32\rtutils.dll Access: query and write and read and execute Type: image Baseaddress: 76E80000 Size: 57344 Protection: read write Mapped to pid: own pid | success or wait | 603007142 | 
| Section loaded | Path: \KnownDlls\WINMM.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 603015534 | 
| Section loaded | Path: C:\WINDOWS\system32\winmm.dll Access: query and write and read and execute Type: image Baseaddress: 76B40000 Size: 184320 Protection: read write Mapped to pid: own pid | success or wait | 603017447 | 
| Section loaded | Path: C:\WINDOWS\system32\tapi32.dll Access: read Type: commit Baseaddress: DD0000 Size: 184320 Protection: readonly Mapped to pid: own pid | success or wait | 603092888 | 
| Section loaded | Path: \KnownDlls\USERENV.dll Access: write and read and execute Type: unknown Baseaddress: 769C0000 Size: 737280 Protection: read write Mapped to pid: own pid | success or wait | 603145822 | 
| Process information queried | PID: 188 Info Class: QuotaLimits | success or wait | 603179979 | 
| Process information queried | PID: 188 Info Class: VmCounters | success or wait | 603180357 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603187778 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603188414 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603188960 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603189562 | 
| Section loaded | Path: \KnownDlls\msapsspc.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 603261303 | 
| Section loaded | Path: C:\WINDOWS\system32\msapsspc.dll Access: query and write and read and execute Type: image Baseaddress: 71E50000 Size: 86016 Protection: read write Mapped to pid: own pid | success or wait | 603263229 | 
| Section loaded | Path: \KnownDlls\MSVCRT40.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 603272044 | 
| Section loaded | Path: C:\WINDOWS\system32\msvcrt40.dll Access: query and write and read and execute Type: image Baseaddress: 78080000 Size: 69632 Protection: read write Mapped to pid: own pid | success or wait | 603273957 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603278346 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603284634 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603286856 | 
| Section loaded | Path: \KnownDlls\schannel.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 603296735 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603299333 | 
| Section loaded | Path: C:\WINDOWS\system32\schannel.dll Access: query and write and read and execute Type: image Baseaddress: 767F0000 Size: 163840 Protection: read write Mapped to pid: own pid | success or wait | 603301174 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603304740 | 
| Section loaded | Path: \KnownDlls\CRYPT32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 603309596 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and write and read and execute Type: image Baseaddress: 77A80000 Size: 610304 Protection: read write Mapped to pid: own pid | success or wait | 603311486 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603314859 | 
| Section loaded | Path: \KnownDlls\MSASN1.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 603320667 | 
| Section loaded | Path: C:\WINDOWS\system32\msasn1.dll Access: query and write and read and execute Type: image Baseaddress: 77B20000 Size: 73728 Protection: read write Mapped to pid: own pid | success or wait | 603326985 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603342188 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603342859 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603346590 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603347203 | 
| Section loaded | Path: \KnownDlls\digest.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 603380255 | 
| Section loaded | Path: C:\WINDOWS\system32\digest.dll Access: query and write and read and execute Type: image Baseaddress: 75B00000 Size: 86016 Protection: read write Mapped to pid: own pid | success or wait | 603382102 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603405625 | 
| Section loaded | Path: \KnownDlls\msnsspc.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 603409042 | 
| Section loaded | Path: C:\WINDOWS\system32\msnsspc.dll Access: query and write and read and execute Type: image Baseaddress: 747B0000 Size: 290816 Protection: read write Mapped to pid: own pid | success or wait | 603410872 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603411933 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603414104 | 
| Section loaded | Path: \KnownDlls\MSVCRT40.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 603417147 | 
| Section loaded | Path: C:\WINDOWS\system32\msvcrt40.dll Access: query and write and read and execute Type: image Baseaddress: 78080000 Size: 69632 Protection: read write Mapped to pid: own pid | success or wait | 603418859 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603424193 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603428844 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603438045 | 
| Section loaded | Path: \KnownDlls\sensapi.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 603454893 | 
| Section loaded | Path: C:\WINDOWS\system32\sensapi.dll Access: query and write and read and execute Type: image Baseaddress: 722B0000 Size: 20480 Protection: read write Mapped to pid: own pid | success or wait | 603460559 | 
| Section loaded | Path: \BaseNamedObjects\SENS Information Cache Access: read Type: unknown Baseaddress: DD0000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 603474471 | 
| Section loaded | Path: C:\WINDOWS\system32\msv1_0.dll Access: write and read and execute Type: commit Baseaddress: E10000 Size: 139264 Protection: execute Mapped to pid: own pid | success or wait | 603488114 | 
| Section loaded | Path: C:\WINDOWS\system32\msv1_0.dll Access: query and write and read and execute Type: image Baseaddress: 77C70000 Size: 151552 Protection: read write Mapped to pid: own pid | success or wait | 603491538 | 
| Section loaded | Path: \KnownDlls\cryptdll.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 603497406 | 
| Section loaded | Path: C:\WINDOWS\system32\cryptdll.dll Access: query and write and read and execute Type: image Baseaddress: 76790000 Size: 49152 Protection: read write Mapped to pid: own pid | success or wait | 603499377 | 
| Section loaded | Path: \KnownDlls\iphlpapi.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 603516322 | 
| Section loaded | Path: C:\WINDOWS\system32\iphlpapi.dll Access: query and write and read and execute Type: image Baseaddress: 76D60000 Size: 102400 Protection: read write Mapped to pid: own pid | success or wait | 603518139 | 
| Section loaded | Path: C:\WINDOWS\system32\mswsock.dll Access: write and read and execute Type: commit Baseaddress: E10000 Size: 245760 Protection: execute Mapped to pid: own pid | success or wait | 603626608 | 
| Section loaded | Path: C:\WINDOWS\system32\mswsock.dll Access: query and write and read and execute Type: image Baseaddress: 71A50000 Size: 258048 Protection: read write Mapped to pid: own pid | success or wait | 603638671 | 
| Section loaded | Path: \KnownDlls\rasadhlp.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 603727659 | 
| Section loaded | Path: C:\WINDOWS\system32\rasadhlp.dll Access: query and write and read and execute Type: image Baseaddress: 76FC0000 Size: 24576 Protection: read write Mapped to pid: own pid | success or wait | 603729433 | 
| Section loaded | Path: C:\Recycle.Bin\B6232F3AC2C.exe Access: query and write and read and execute and extend size Type: image Baseaddress: 76FC0000 Size: 24576 Protection: read write Mapped to pid: own pid | success or wait | 603772615 | 
| Section loaded | Path: \BaseNamedObjects\ShimSharedMemory Access: write Type: unknown Baseaddress: F10000 Size: 57344 Protection: read write Mapped to pid: own pid | success or wait | 603774027 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603806163 | 
| Process information queried | PID: 188 Info Class: DefaultHardErrorMode | success or wait | 603808045 | 
| Section loaded | Path: C:\Recycle.Bin\B6232F3AC2C.exe Access: query and read Type: commit Baseaddress: F20000 Size: 196608 Protection: readonly Mapped to pid: own pid | success or wait | 603808427 | 
| Process created | PID: 1424 Path: C:\Recycle.Bin\B6232F3AC2C.exe Cmdline: C:\Recycle.Bin\B6232F3AC2C.exe Createflags: none | success or wait | 603814675 | 
| Process information queried | PID: 1424 Info Class: BasicInformation | success or wait | 603815698 | 
| Process information queried | PID: 1424 Info Class: BasicInformation | success or wait | 603823103 | 
| Memory allocated | PID: 188 Path: C:\Recycle.Bin\B6232F3AC2C.exe Base: F30000 Length: 12FC98 Allocation Type: unknown Protection: page read and write | success or wait | 605068592 | 
| Memory read | PID: 1424 Path: C:\Recycle.Bin\B6232F3AC2C.exe Base: 7FFDF008 Length: 4 Value: 00 00 40 00 | success or wait | 605068990 | 
| Memory allocated | PID: 1424 Path: C:\Recycle.Bin\B6232F3AC2C.exe Base: 400000 Length: 12FCC8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 605072748 | 
| Memory written | PID: 1424 Path: C:\Recycle.Bin\B6232F3AC2C.exe Base: 400000 Length: 397312 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 03 00 FB 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 D0 01 00 00 10 00 00 00 20 04 00 70 F2 05 00 00 30 04 | success or wait | 605103721 | 
| Memory written | PID: 1424 Path: C:\Recycle.Bin\B6232F3AC2C.exe Base: 7FFDF008 Length: 4 Value: 00 00 40 00 | success or wait | 605135635 | 
| Thread context set | TID: 1368 PID: 1424 DR0: 0 DR1: 0 DR2: 0 DR3: 0 DR7: 0 EIP: 7C810705 EFLAGS: 200 Imagepath: null | success or wait | 605159837 | 
| Thread resumed | TID: 1368 PID: 1424 Path: C:\Recycle.Bin\B6232F3AC2C.exe | success or wait | 605160431 | 
| Sections | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| File Activities: 
 
 
 
 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Section Activities: 
 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Registry Activities: 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Mutant Activities: 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Process Activities: 
 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Memory Activities: 
 
 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| System Activities: 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Section loaded | Path: \KnownDlls\kernel32.dll Access: write and read and execute Type: unknown Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid | success or wait | 605174699 | 
| Process information queried | PID: 1424 Info Class: Cookie | success or wait | 605178152 | 
| Section loaded | Path: unknown Access: query and write and read and execute and extend size Type: reserve Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid | success or wait | 605179067 | 
| Section loaded | Path: \NLS\NlsSectionUnicode Access: read Type: unknown Baseaddress: 260000 Size: 90112 Protection: readonly Mapped to pid: own pid | success or wait | 605183392 | 
| Section loaded | Path: \NLS\NlsSectionLocale Access: read Type: unknown Baseaddress: 280000 Size: 266240 Protection: readonly Mapped to pid: own pid | success or wait | 605184998 | 
| Section loaded | Path: \NLS\NlsSectionSortkey Access: query and read Type: unknown Baseaddress: 2D0000 Size: 266240 Protection: readonly Mapped to pid: own pid | success or wait | 605186360 | 
| Section loaded | Path: \NLS\NlsSectionSortTbls Access: read Type: unknown Baseaddress: 320000 Size: 24576 Protection: readonly Mapped to pid: own pid | success or wait | 605187341 | 
| Section loaded | Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 605188964 | 
| Section loaded | Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 605189336 | 
| Section loaded | Path: \KnownDlls\ADVAPI32.dll Access: write and read and execute Type: unknown Baseaddress: 77DD0000 Size: 634880 Protection: read write Mapped to pid: own pid | success or wait | 605191385 | 
| Section loaded | Path: \KnownDlls\RPCRT4.dll Access: write and read and execute Type: unknown Baseaddress: 77E70000 Size: 602112 Protection: read write Mapped to pid: own pid | success or wait | 605194680 | 
| Section loaded | Path: \KnownDlls\Secur32.dll Access: write and read and execute Type: unknown Baseaddress: 77FE0000 Size: 69632 Protection: read write Mapped to pid: own pid | success or wait | 605198864 | 
| Process information queried | PID: 1424 Info Class: ImageInformation | success or wait | 605205678 | 
| Memory attributes changed | PID: 1424 Path: C:\Recycle.Bin\B6232F3AC2C.exe Base: 400000 Length: 1000 New Protection: page read and write New Protection: page execute and read and write | success or wait | 605315659 | 
| Memory attributes changed | PID: 1424 Path: C:\Recycle.Bin\B6232F3AC2C.exe Base: 400000 Length: 1000 New Protection: page execute and read and write New Protection: page read and write | success or wait | 605317334 | 
| Process information queried | PID: 1424 Info Class: Wow64Information | success or wait | 605319457 | 
| File opened | Path: C:\WINDOWS\system32\kernel32.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 605320692 | 
| Section loaded | Path: C:\WINDOWS\system32\kernel32.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 470000 Size: 1007616 Protection: readonly Mapped to pid: own pid | image not at base | 605322340 | 
| Memory attributes changed | PID: 1424 Path: C:\Recycle.Bin\B6232F3AC2C.exe Base: 4A5FA8 Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 605324154 | 
| Memory attributes changed | PID: 1424 Path: C:\Recycle.Bin\B6232F3AC2C.exe Base: 45615C Length: 1000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 605326269 | 
| Process information queried | PID: 1424 Info Class: Wow64Information | success or wait | 605327077 | 
| File opened | Path: C:\WINDOWS\system32\kernel32.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 605327557 | 
| Section loaded | Path: C:\WINDOWS\system32\kernel32.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 470000 Size: 1007616 Protection: readonly Mapped to pid: own pid | image not at base | 605328574 | 
| Memory attributes changed | PID: 1424 Path: C:\Recycle.Bin\B6232F3AC2C.exe Base: 4A5FA8 Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 605329468 | 
| Memory attributes changed | PID: 1424 Path: C:\Recycle.Bin\B6232F3AC2C.exe Base: 45B098 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 605330581 | 
| Memory allocated | PID: 1424 Path: C:\Recycle.Bin\B6232F3AC2C.exe Base: 330000 Length: 12FFA4 Allocation Type: unknown Protection: page execute and read and write | success or wait | 605330869 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName Name: ComputerName | success or wait | 605332279 | 
| File created | Path: C:\Recycle.Bin\ Access: read data or list directory and synchronize Options: directory file and synchronous io non alert and open for backup ident Attributes: normal Content Overwritten: null | object name collision | 605334185 | 
| Mutant created | Name: \BaseNamedObjects\Global\SystemService | success or wait | 605335940 | 
| Process information queried | PID: 1424 Info Class: Wow64Information | success or wait | 605336574 | 
| File opened | Path: C:\WINDOWS\system32\kernel32.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 605336898 | 
| Section loaded | Path: C:\WINDOWS\system32\kernel32.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 470000 Size: 1007616 Protection: readonly Mapped to pid: own pid | image not at base | 605337740 | 
| Memory attributes changed | PID: 1424 Path: C:\Recycle.Bin\B6232F3AC2C.exe Base: 4A5FA8 Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 605338472 | 
| Memory allocated | PID: 1424 Path: C:\Recycle.Bin\B6232F3AC2C.exe Base: 330000 Length: 12FBF4 Allocation Type: unknown Protection: page execute and read and write | success or wait | 605339589 | 
| Section loaded | Path: \KnownDlls\CRYPT32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 605342330 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and write and read and execute Type: image Baseaddress: 77A80000 Size: 610304 Protection: read write Mapped to pid: own pid | success or wait | 605343910 | 
| Section loaded | Path: \KnownDlls\MSASN1.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 605349463 | 
| Section loaded | Path: C:\WINDOWS\system32\msasn1.dll Access: query and write and read and execute Type: image Baseaddress: 77B20000 Size: 73728 Protection: read write Mapped to pid: own pid | success or wait | 605351157 | 
| Section loaded | Path: \KnownDlls\msvcrt.dll Access: write and read and execute Type: unknown Baseaddress: 77C10000 Size: 360448 Protection: read write Mapped to pid: own pid | success or wait | 605354096 | 
| Section loaded | Path: \KnownDlls\USER32.dll Access: write and read and execute Type: unknown Baseaddress: 7E410000 Size: 593920 Protection: read write Mapped to pid: own pid | success or wait | 605358553 | 
| Section loaded | Path: \KnownDlls\GDI32.dll Access: write and read and execute Type: unknown Baseaddress: 77F10000 Size: 299008 Protection: read write Mapped to pid: own pid | success or wait | 605360215 | 
| Section loaded | Path: \NLS\NlsSectionCType Access: read Type: unknown Baseaddress: 390000 Size: 12288 Protection: readonly Mapped to pid: own pid | success or wait | 605374631 | 
| Process information queried | PID: 1424 Info Class: Cookie | success or wait | 605377769 | 
| Process information queried | PID: 1424 Info Class: Cookie | success or wait | 605378076 | 
| Section loaded | Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit Baseaddress: 3A0000 Size: 110592 Protection: execute Mapped to pid: own pid | success or wait | 605380745 | 
| Section loaded | Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit Baseaddress: 3A0000 Size: 110592 Protection: execute Mapped to pid: own pid | success or wait | 605384059 | 
| Section loaded | Path: C:\WINDOWS\system32\imm32.dll Access: query and write and read and execute Type: image Baseaddress: 76390000 Size: 118784 Protection: read write Mapped to pid: own pid | success or wait | 605386915 | 
| Section loaded | Path: \KnownDlls\WS2_32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 605404726 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and write and read and execute Type: image Baseaddress: 71AB0000 Size: 94208 Protection: read write Mapped to pid: own pid | success or wait | 605406323 | 
| Section loaded | Path: \KnownDlls\WS2HELP.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 605411323 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2help.dll Access: query and write and read and execute Type: image Baseaddress: 71AA0000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 605412940 | 
| Section loaded | Path: \KnownDlls\WININET.dll Access: write and read and execute Type: unknown Baseaddress: 3D930000 Size: 942080 Protection: read write Mapped to pid: own pid | success or wait | 605418647 | 
| Section loaded | Path: \KnownDlls\SHLWAPI.dll Access: write and read and execute Type: unknown Baseaddress: 77F60000 Size: 483328 Protection: read write Mapped to pid: own pid | success or wait | 605423023 | 
| Section loaded | Path: \KnownDlls\Normaliz.dll Access: write and read and execute Type: unknown Baseaddress: 3C0000 Size: 36864 Protection: read write Mapped to pid: own pid | conflicting addresses | 605432351 | 
| Section loaded | Path: \KnownDlls\urlmon.dll Access: write and read and execute Type: unknown Baseaddress: 78130000 Size: 1257472 Protection: read write Mapped to pid: own pid | success or wait | 605439696 | 
| Section loaded | Path: \KnownDlls\ole32.dll Access: write and read and execute Type: unknown Baseaddress: 774E0000 Size: 1302528 Protection: read write Mapped to pid: own pid | success or wait | 605443100 | 
| Section loaded | Path: \KnownDlls\OLEAUT32.dll Access: write and read and execute Type: unknown Baseaddress: 77120000 Size: 569344 Protection: read write Mapped to pid: own pid | success or wait | 605451990 | 
| Section loaded | Path: \KnownDlls\iertutil.dll Access: write and read and execute Type: unknown Baseaddress: 3DFD0000 Size: 2002944 Protection: read write Mapped to pid: own pid | success or wait | 605462674 | 
| Section loaded | Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll Access: write and read and execute Type: commit Baseaddress: 950000 Size: 1056768 Protection: execute Mapped to pid: own pid | success or wait | 605523996 | 
| Section loaded | Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll Access: query and write and read and execute Type: image Baseaddress: 773D0000 Size: 1060864 Protection: read write Mapped to pid: own pid | success or wait | 605527356 | 
| Section loaded | Path: C:\WINDOWS\WindowsShell.Manifest Access: write and read and execute Type: commit Baseaddress: 3E0000 Size: 4096 Protection: execute Mapped to pid: own pid | success or wait | 605565257 | 
| Section loaded | Path: C:\WINDOWS\WindowsShell.Manifest Access: query and read Type: commit Baseaddress: 3E0000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 605596058 | 
| Section loaded | Path: C:\WINDOWS\WindowsShell.Manifest Access: read Type: commit Baseaddress: 3E0000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 605617904 | 
| Section loaded | Path: \KnownDlls\MSIMG32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 606064473 | 
| Section loaded | Path: C:\WINDOWS\system32\msimg32.dll Access: query and write and read and execute Type: image Baseaddress: 76380000 Size: 20480 Protection: read write Mapped to pid: own pid | success or wait | 606067024 | 
| Section loaded | Path: \KnownDlls\SHELL32.dll Access: write and read and execute Type: unknown Baseaddress: 7C9C0000 Size: 8482816 Protection: read write Mapped to pid: own pid | success or wait | 606085725 | 
| Section loaded | Path: C:\WINDOWS\system32\shell32.dll Access: read Type: commit Baseaddress: B50000 Size: 8462336 Protection: readonly Mapped to pid: own pid | success or wait | 606104149 | 
| Section loaded | Path: \KnownDlls\comctl32.dll Access: write and read and execute Type: unknown Baseaddress: 5D090000 Size: 630784 Protection: read write Mapped to pid: own pid | success or wait | 606121485 | 
| Section loaded | Path: C:\WINDOWS\system32\comctl32.dll Access: read Type: commit Baseaddress: B60000 Size: 618496 Protection: readonly Mapped to pid: own pid | success or wait | 606141731 | 
| Process information queried | PID: 1424 Info Class: SessionInformation | success or wait | 606149947 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | object name not found | 606157710 | 
| Process information queried | PID: 1424 Info Class: Wow64Information | success or wait | 606159175 | 
| File opened | Path: C:\WINDOWS\system32\kernel32.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 606159298 | 
| Section loaded | Path: C:\WINDOWS\system32\kernel32.dll Access: query and write and read and execute and extend size Type: image Baseaddress: C10000 Size: 1007616 Protection: readonly Mapped to pid: own pid | image not at base | 606161317 | 
| Memory attributes changed | PID: 1424 Path: C:\Recycle.Bin\B6232F3AC2C.exe Base: C45FA8 Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 606162621 | 
| File created | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic write Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 606165524 | 
| File write | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 606176411 | 
| Process information queried | PID: 1424 Info Class: Wow64Information | success or wait | 606181355 | 
| File opened | Path: C:\WINDOWS\system32\kernel32.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 606181759 | 
| Section loaded | Path: C:\WINDOWS\system32\kernel32.dll Access: query and write and read and execute and extend size Type: image Baseaddress: C10000 Size: 1007616 Protection: readonly Mapped to pid: own pid | image not at base | 606182073 | 
| Memory attributes changed | PID: 1424 Path: C:\Recycle.Bin\B6232F3AC2C.exe Base: C45FA8 Length: 1000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 606186627 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 606190236 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 606198394 | 
| Section loaded | Path: \BaseNamedObjects\DBWIN_BUFFER Access: write Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 606208659 | 
| File opened | Path: \pipe\globpluginsuninstallpipe Access: read attributes and synchronize and generic write Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | object name not found | 606208869 | 
| System info queried | Type: ProcessInformation | success or wait | 606210956 | 
| Section loaded | Path: unknown Access: query and write and read Type: commit Baseaddress: B60000 Size: 16384 Protection: read write Mapped to pid: own pid | success or wait | 606214995 | 
| Process information queried | PID: 1552 Info Class: BasicInformation | success or wait | 606269431 | 
| Memory allocated | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BAD0000 Length: 12F5A8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 606270658 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 606271067 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 606271882 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 606272012 | 
| Memory written | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 606369985 | 
| Memory written | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: BADE920 Length: 13 Value: B8 00 00 7A 0B 50 BA 75 4F AF 0B FF D2 | success or wait | 606377909 | 
| Memory allocated | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: C00000 Length: 12F5D8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 606378014 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 606378400 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13a567 | success or wait | 606378716 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 606378808 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1d03e78 | success or wait | 606379033 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 606379123 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 606379232 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b54dba | success or wait | 606379444 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 606379532 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1020230 | success or wait | 606379718 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: B60000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 606379836 | 
| Memory written | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: C00000 Length: 4096 Value: 64 A1 18 00 00 00 C3 55 8B EC 83 EC 54 83 65 FC 00 64 A1 30 00 00 00 8B 40 0C 8B 40 1C 8B 40 08 68 34 05 74 78 50 E8 83 00 00 00 59 59 89 45 F0 85 C0 74 75 8D 45 AC 89 45 F4 8B 55 F4 C7 02 6B 00 65 00 83 C2 04 C7 02 72 00 6E 00 83 C2 04 C7 02 65 00 6C 00 83 C2 04 C7 02 33 00 32 00 83 C2 04 C7 02 2E 00 64 00 83 C2 04 C7 02 6C 00 6C 00 83 C2 04 83 22 00 8D 45 FC 89 45 EC 8D 45 AC 6A 18 89 45 E8 58 66 89 45 E4 6A 1A 58 66 89 45 E6 8D 45 E4 89 45 F4 8B 45 EC 50 8B 45 F4 50 83 E0 00 50 50 FF 55 F0 89 45 F8 8B 45 FC C9 C3 55 8B EC 51 51 53 8B 5D 08 8B 43 3C 8B 4C 18 78 8B 45 0C C1 E8 10 03 CB 66 85 C0 75 15 0F B7 45 0C 2B 41 10 8B 49 1C 8D 04 81 8B 04 18 03 C3 5B C9 C3 83 65 FC 00 56 8B 71 20 57 8B 79 24 03 F3 03 FB 83 79 18 00 76 3F 8B 06 83 65 F8 00 03 C3 8A | success or wait | 606389178 | 
| Memory attributes changed | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 606389307 | 
| Memory written | PID: 1552 Path: C:\WINDOWS\explorer.exe Base: 7C90CFEE Length: 5 Value: E9 BF 33 2F 84 | success or wait | 606395865 | 
| Process terminated | PID: 1424 Path: C:\Recycle.Bin\B6232F3AC2C.exe | success or wait | 606396266 | 
| Process information queried | PID: 1424 Info Class: Cookie | success or wait | 606399808 | 
| Process information queried | PID: 1424 Info Class: Cookie | success or wait | 606399910 | 
| Sections | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| File Activities: 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Section Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Mutant Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Process Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Thread Activities: 
 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Memory Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 628999368 | 
| Section loaded | Path: C:\WINDOWS\system32\msctf.dll Access: write and read and execute Type: commit Baseaddress: 14A0000 Size: 299008 Protection: execute Mapped to pid: own pid | success or wait | 629003504 | 
| Mutant created | Name: \BaseNamedObjects\zXeRY3a_PtW|00000000 | success or wait | 629005175 | 
| Thread created | PID: 576 TID: 1312 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\winlogon.exe | success or wait | 629008193 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629010703 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 629016427 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 629016768 | 
| Section loaded | Path: \KnownDlls\WININET.dll Access: write and read and execute Type: unknown Baseaddress: 3D930000 Size: 942080 Protection: read write Mapped to pid: own pid | success or wait | 629018005 | 
| Section loaded | Path: \KnownDlls\Normaliz.dll Access: write and read and execute Type: unknown Baseaddress: A80000 Size: 36864 Protection: read write Mapped to pid: own pid | conflicting addresses | 629024598 | 
| Section loaded | Path: \KnownDlls\urlmon.dll Access: write and read and execute Type: unknown Baseaddress: 78130000 Size: 1257472 Protection: read write Mapped to pid: own pid | success or wait | 629031463 | 
| Section loaded | Path: \KnownDlls\iertutil.dll Access: write and read and execute Type: unknown Baseaddress: 3DFD0000 Size: 2002944 Protection: read write Mapped to pid: own pid | success or wait | 629040654 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 629173607 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 629173975 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 629180615 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 629180897 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 629187267 | 
| Section loaded | Path: C:\WINDOWS\system32\msctf.dll Access: write and read and execute Type: commit Baseaddress: 14E0000 Size: 299008 Protection: execute Mapped to pid: own pid | success or wait | 629188900 | 
| Section loaded | Path: \KnownDlls\MSIMG32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 629191670 | 
| Section loaded | Path: C:\WINDOWS\system32\msimg32.dll Access: query and write and read and execute Type: image Baseaddress: 76380000 Size: 20480 Protection: read write Mapped to pid: own pid | success or wait | 629193131 | 
| Thread created | PID: 576 TID: 2028 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\winlogon.exe | success or wait | 629198580 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 629200022 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 629200304 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 629200841 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and write copy | success or wait | 629201659 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 629202647 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11d6070 | success or wait | 629203477 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 629203740 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a65fca | success or wait | 629204126 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 629204384 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 629204691 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1dac8a5 | success or wait | 629205284 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 629205539 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@aad8f9 | success or wait | 629206548 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 14E0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 629206888 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629209604 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BAFEA50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629209899 | 
| Thread created | PID: 576 TID: 1704 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\winlogon.exe | success or wait | 629211461 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 629213017 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 629213300 | 
| Thread created | PID: 576 TID: 1976 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\winlogon.exe | success or wait | 629214955 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 629216333 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 629216617 | 
| Process information queried | PID: 576 Info Class: Wow64Information | success or wait | 629217326 | 
| Process information queried | PID: 576 Info Class: Wow64Information | success or wait | 629217874 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 629218380 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 629218774 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629218954 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 629219952 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11d6070 | success or wait | 629220791 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 629221053 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a65fca | success or wait | 629221436 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 629221693 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 629221999 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1dac8a5 | success or wait | 629222668 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 629222924 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@aad8f9 | success or wait | 629223443 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 1560000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 629223778 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629226537 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BB186C0 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629226831 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629227132 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 629228102 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11d6070 | success or wait | 629228921 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 629229182 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a65fca | success or wait | 629229567 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 629229824 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 629230129 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1dac8a5 | success or wait | 629230723 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 629230978 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@aad8f9 | success or wait | 629231495 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 1560000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 629231830 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629234566 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BB06F28 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629234861 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629235163 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 629236131 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11d6070 | success or wait | 629236953 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 629237214 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a65fca | success or wait | 629237605 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 629237864 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 629238171 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1dac8a5 | success or wait | 629238772 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 629239029 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@aad8f9 | success or wait | 629239555 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 1560000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 629239890 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629242626 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BB04B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629242918 | 
| Process information queried | PID: 576 Info Class: Wow64Information | success or wait | 629243414 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629243674 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 629244646 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11d6070 | success or wait | 629245390 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 629245515 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a65fca | success or wait | 629246265 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 629246525 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 629246831 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1dac8a5 | success or wait | 629247434 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 629247690 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@aad8f9 | success or wait | 629248303 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 1560000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 629248640 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629251384 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BB17D98 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629251678 | 
| Section loaded | Path: \KnownDlls\nspr4.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 629252634 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 629254828 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 629255832 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 629275961 | 
| File opened | Path: C:\WINDOWS\system32\USER32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 629276985 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@8aeedc | success or wait | 629277843 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 4 Value: D8 00 00 00 | success or wait | 629278118 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@147bc27 | success or wait | 629278630 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 1B A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 629278901 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 F4 05 00 00 E2 02 00 00 00 00 00 17 B2 00 00 00 10 00 00 00 B0 05 00 00 00 41 7E 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 10 09 00 00 04 00 00 76 FC 08 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 39 00 00 | success or wait | 629279341 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@91d863 | success or wait | 629279960 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 83 F2 05 00 00 10 00 00 00 F4 05 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 80 11 00 00 00 10 06 00 00 0C 00 00 00 F8 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 88 A0 02 00 00 30 06 00 00 A2 02 00 | success or wait | 629280230 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11570cd | success or wait | 629280684 | 
| Section loaded | Path: C:\WINDOWS\system32\user32.dll Access: query and read Type: commit Baseaddress: 1570000 Size: 57344 Protection: readonly Mapped to pid: own pid | success or wait | 629281031 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629283953 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BB03E40 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629284260 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 629284654 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 629285644 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@a0d37f | success or wait | 629286491 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 629286757 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9d74b8 | success or wait | 629287263 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 629287526 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 629288029 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@159df6c | success or wait | 629288643 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 629288905 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@15b5219 | success or wait | 629289437 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 1570000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 629289777 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629292908 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BB189C8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629293201 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 629293587 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 629294578 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@a0d37f | success or wait | 629295415 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 629295681 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9d74b8 | success or wait | 629296078 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 629296341 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 629296651 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@159df6c | success or wait | 629297256 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 629297517 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@15b5219 | success or wait | 629298048 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 1570000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 629298388 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629301446 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BB18118 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629301936 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 629302325 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 629303315 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@a0d37f | success or wait | 629304156 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 629304422 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9d74b8 | success or wait | 629304818 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 629305081 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 629305391 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@159df6c | success or wait | 629306000 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 629306263 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@15b5219 | success or wait | 629306794 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 1570000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 629307133 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629310348 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BAFE1F8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629310639 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 629311318 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 629312312 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@a0d37f | success or wait | 629313149 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 629313416 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9d74b8 | success or wait | 629313812 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 629314075 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 629314221 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@159df6c | success or wait | 629314440 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 629314535 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@15b5219 | success or wait | 629314727 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 1570000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 629314850 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629315963 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BB07290 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629316089 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 629316439 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 629317164 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 629337706 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 629338783 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@a0d37f | success or wait | 629339637 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 629339905 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9d74b8 | success or wait | 629340302 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 629340565 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 629340877 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@159df6c | success or wait | 629341485 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 629341747 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@15b5219 | success or wait | 629342281 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 1570000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 629342620 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629345998 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BB07A10 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629346293 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 629346651 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 629347653 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@a0d37f | success or wait | 629348494 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 629348761 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9d74b8 | success or wait | 629349157 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 629349423 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 629349734 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@159df6c | success or wait | 629350340 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 629350603 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@15b5219 | success or wait | 629351135 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 1570000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 629351474 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629354639 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BB18B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629355020 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 629355386 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 629356394 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@a0d37f | success or wait | 629357236 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 629357376 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9d74b8 | success or wait | 629358018 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 629358284 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 629358596 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@159df6c | success or wait | 629359203 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 629359466 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@15b5219 | success or wait | 629359998 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 1570000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 629360338 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629365027 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BB05310 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629365329 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 629365690 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 629366684 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@a0d37f | success or wait | 629367526 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 629367793 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9d74b8 | success or wait | 629368190 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 629368454 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 629368766 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@159df6c | success or wait | 629369374 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 629369636 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@15b5219 | success or wait | 629370168 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 1570000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 629370270 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629375027 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BB18ED8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629375320 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 629375677 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 629376680 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@a0d37f | success or wait | 629377588 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 629377855 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9d74b8 | success or wait | 629378253 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 629378515 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 629378830 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@159df6c | success or wait | 629379438 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 629379700 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@15b5219 | success or wait | 629380233 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 1570000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 629380572 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629383794 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BB04D50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629384097 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 629384457 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 629385449 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@a0d37f | success or wait | 629386287 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 629386554 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9d74b8 | success or wait | 629386952 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 629387129 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 629387441 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@159df6c | success or wait | 629388052 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 629388315 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@15b5219 | success or wait | 629388849 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 1570000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 629389188 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629392504 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BB05538 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629392797 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 629393156 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 629394149 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@a0d37f | success or wait | 629394989 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 629395255 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9d74b8 | success or wait | 629395650 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 629395913 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 629396226 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@159df6c | success or wait | 629396834 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 629397099 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@15b5219 | success or wait | 629397631 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 1570000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 629397970 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629401180 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: BAFE698 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629401473 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 629401866 | 
| File opened | Path: C:\WINDOWS\system32\WS2_32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 629402868 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@6b258d | success or wait | 629403708 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 629403975 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@6e7a5b | success or wait | 629404481 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 63 A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 629404745 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 22 01 00 00 1C 00 00 00 00 00 00 73 12 00 00 00 10 00 00 00 20 01 00 00 00 AB 71 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 70 01 00 00 04 00 00 20 F0 01 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 04 14 00 00 | success or wait | 629405251 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1230534 | success or wait | 629405862 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 53 21 01 00 00 10 00 00 00 22 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 14 09 00 00 00 40 01 00 00 0A 00 00 00 26 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 F8 03 00 00 00 50 01 00 00 04 00 00 | success or wait | 629406127 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@2aabf8 | success or wait | 629406657 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and read Type: commit Baseaddress: 1570000 Size: 20480 Protection: readonly Mapped to pid: own pid | success or wait | 629406997 | 
| Memory attributes changed | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 629409500 | 
| File opened | Path: C:\WINDOWS\system32\ADVAPI32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 629411201 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1803641 | success or wait | 629412044 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 629412311 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@69e732 | success or wait | 629412817 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 48 1D 90 49 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 629413082 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 46 07 00 00 3E 02 00 00 00 00 00 0B 71 00 00 00 10 00 00 00 20 07 00 00 00 DD 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 B0 09 00 00 04 00 00 B8 5B 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 A4 16 00 00 | success or wait | 629413801 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c9aff0 | success or wait | 629414420 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C9 45 07 00 00 10 00 00 00 46 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 28 46 00 00 00 60 07 00 00 2C 00 00 00 4A 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 80 A9 01 00 00 B0 07 00 00 AA 01 00 | success or wait | 629414683 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13dd7d1 | success or wait | 629415217 | 
| Section loaded | Path: C:\WINDOWS\system32\advapi32.dll Access: query and read Type: commit Baseaddress: 1570000 Size: 28672 Protection: readonly Mapped to pid: own pid | success or wait | 629415560 | 
| File opened | Path: C:\WINDOWS\system32\CRYPT32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 629420296 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@123fee1 | success or wait | 629421141 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 629421407 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@327cee | success or wait | 629422103 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D7 A0 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 629422368 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 44 08 00 00 DC 00 00 00 00 00 00 32 16 00 00 00 10 00 00 00 20 08 00 00 00 A8 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 50 09 00 00 04 00 00 30 C5 09 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 9C 1A 00 00 | success or wait | 629422681 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@a7f8a4 | success or wait | 629423188 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C4 43 08 00 00 10 00 00 00 44 08 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 E8 23 00 00 00 60 08 00 00 24 00 00 00 48 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 50 67 00 00 00 90 08 00 00 68 00 00 | success or wait | 629423451 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b4fe4d | success or wait | 629423980 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and read Type: commit Baseaddress: 1570000 Size: 77824 Protection: readonly Mapped to pid: own pid | success or wait | 629424322 | 
| Mutant created | Name: \BaseNamedObjects\Global\ch971pGLCYGJFFTTU5XPPGQTZJ8OdYB | object name exists | 629428061 | 
| Thread created | PID: 576 TID: 1300 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\winlogon.exe | success or wait | 629429767 | 
| Thread resumed | TID: 1300 PID: 576 Path: C:\WINDOWS\system32\winlogon.exe | success or wait | 629430770 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 629431411 | 
| Section loaded | Path: C:\WINDOWS\system32\msctf.dll Access: write and read and execute Type: commit Baseaddress: 1AB0000 Size: 299008 Protection: execute Mapped to pid: own pid | success or wait | 629433042 | 
| Thread terminated | TID: 1312 PID: 576 Path: C:\WINDOWS\system32\winlogon.exe | unknown | 629434618 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 629435357 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 629435646 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | object name not found | 629436163 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 629436869 | 
| Section loaded | Path: C:\WINDOWS\system32\msctf.dll Access: write and read and execute Type: commit Baseaddress: 1AB0000 Size: 299008 Protection: execute Mapped to pid: own pid | success or wait | 629438399 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 631168772 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 631168939 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 631169093 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 632952161 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 632959149 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 632959334 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 634056298 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 634056683 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 634057061 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 635174940 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 635175403 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 635175850 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 636296204 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 636296676 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 636297123 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 637412243 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 637412780 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 637413280 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 638530812 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 638531328 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 638531824 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 639649427 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 639649943 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 639650439 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 640768091 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 640768610 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 640769108 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 641886709 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 641887233 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 641887729 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 643005258 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 643005772 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 643006266 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 644128743 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 644132522 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 644135137 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 645242466 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 645242994 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 645243411 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 646361075 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 646361590 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 646362087 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 647479676 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 647480213 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 647480710 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 648598285 | 
| Thread delayed | Time: 0 TID: 2028 | success or wait | 648598803 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 736420791 | 
| Section loaded | Path: C:\WINDOWS\system32\msctf.dll Access: write and read and execute Type: commit Baseaddress: 1A70000 Size: 299008 Protection: execute Mapped to pid: own pid | success or wait | 736436163 | 
| Thread created | PID: 576 TID: 3284 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\winlogon.exe | success or wait | 737659182 | 
| Thread resumed | TID: 3284 PID: 576 Path: C:\WINDOWS\system32\winlogon.exe | success or wait | 737659903 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 737661577 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 737661898 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | success or wait | 737662945 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 737663459 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 737675690 | 
| Memory allocated | PID: 576 Path: C:\WINDOWS\system32\winlogon.exe Base: 1360000 Length: 10CFF30 Allocation Type: unknown Protection: page execute and read and write | success or wait | 737734909 | 
| Thread created | PID: 576 TID: 3276 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\winlogon.exe | success or wait | 737737713 | 
| Thread resumed | TID: 3276 PID: 576 Path: C:\WINDOWS\system32\winlogon.exe | success or wait | 737738510 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 737739436 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 737739744 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 737740218 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 737740455 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 737742204 | 
| Thread created | PID: 576 TID: 3272 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\winlogon.exe | success or wait | 737744436 | 
| Thread resumed | TID: 3272 PID: 576 Path: C:\WINDOWS\system32\winlogon.exe | success or wait | 737745140 | 
| Section loaded | Path: C:\WINDOWS\system32\msctf.dll Access: write and read and execute Type: commit Baseaddress: 1AF0000 Size: 299008 Protection: execute Mapped to pid: own pid | success or wait | 737746371 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 737749002 | 
| Section loaded | Path: C:\WINDOWS\system32\msctf.dll Access: write and read and execute Type: commit Baseaddress: 1AF0000 Size: 299008 Protection: execute Mapped to pid: own pid | success or wait | 737750473 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 737753000 | 
| Process information queried | PID: 576 Info Class: Cookie | success or wait | 737753285 | 
| Sections | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| File Activities: 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Section Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Mutant Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Process Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Thread Activities: 
 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Memory Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Mutant created | Name: \BaseNamedObjects\zXeRY3a_PtW|00000000 | success or wait | 633345671 | 
| Thread created | PID: 676 TID: 1780 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\lsass.exe | success or wait | 633348545 | 
| Section loaded | Path: \KnownDlls\WININET.dll Access: write and read and execute Type: unknown Baseaddress: 3D930000 Size: 942080 Protection: read write Mapped to pid: own pid | success or wait | 633351415 | 
| Mutant created | Name: \BaseNamedObjects\zXeRY3a_PtW|00000000 | object name exists | 633353067 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633353687 | 
| Section loaded | Path: \KnownDlls\Normaliz.dll Access: write and read and execute Type: unknown Baseaddress: A80000 Size: 36864 Protection: read write Mapped to pid: own pid | conflicting addresses | 633358777 | 
| Section loaded | Path: \KnownDlls\urlmon.dll Access: write and read and execute Type: unknown Baseaddress: 78130000 Size: 1257472 Protection: read write Mapped to pid: own pid | success or wait | 633365010 | 
| Section loaded | Path: \KnownDlls\iertutil.dll Access: write and read and execute Type: unknown Baseaddress: 3DFD0000 Size: 2002944 Protection: read write Mapped to pid: own pid | success or wait | 633373153 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633480110 | 
| Section loaded | Path: \KnownDlls\MSIMG32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 633483204 | 
| Section loaded | Path: C:\WINDOWS\system32\msimg32.dll Access: query and write and read and execute Type: image Baseaddress: 76380000 Size: 20480 Protection: read write Mapped to pid: own pid | success or wait | 633489783 | 
| Thread created | PID: 676 TID: 184 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\lsass.exe | success or wait | 633499566 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and write copy | success or wait | 633501058 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 633502261 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633504565 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@73f623 | success or wait | 633505879 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 633506115 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1247c45 | success or wait | 633506463 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 633506694 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 633506971 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5aad2a | success or wait | 633507503 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 633508286 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11ebc46 | success or wait | 633510639 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: CD0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633511009 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633514760 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BAFEA50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633515027 | 
| Thread created | PID: 676 TID: 908 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\lsass.exe | success or wait | 633516441 | 
| Thread created | PID: 676 TID: 1628 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\lsass.exe | success or wait | 633518969 | 
| Process information queried | PID: 676 Info Class: Wow64Information | success or wait | 633520573 | 
| Process information queried | PID: 676 Info Class: Wow64Information | success or wait | 633521067 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 633521523 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 633521883 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633522054 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633522936 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@73f623 | success or wait | 633523688 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 633523923 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1247c45 | success or wait | 633524266 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 633524495 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 633524771 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5aad2a | success or wait | 633525303 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 633525534 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11ebc46 | success or wait | 633526000 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: CD0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633526299 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633528781 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BB186C0 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633529047 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633529319 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633530195 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@73f623 | success or wait | 633530933 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 633531167 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1247c45 | success or wait | 633531510 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 633531741 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 633532016 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5aad2a | success or wait | 633532548 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 633532778 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11ebc46 | success or wait | 633533244 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: CD0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633533608 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633536080 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BB06F28 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633536347 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633536621 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633537497 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@73f623 | success or wait | 633538242 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 633538477 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1247c45 | success or wait | 633538827 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 633539059 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 633539335 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5aad2a | success or wait | 633539874 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 633540105 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11ebc46 | success or wait | 633540493 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: CD0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633540793 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633543255 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BB04B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633543591 | 
| Process information queried | PID: 676 Info Class: Wow64Information | success or wait | 633544043 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633544279 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633545154 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@73f623 | success or wait | 633545903 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 633546138 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1247c45 | success or wait | 633546489 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 633546720 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 633546996 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5aad2a | success or wait | 633547536 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 633547767 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11ebc46 | success or wait | 633548240 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: CD0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633548540 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633551003 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BB17D98 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633551268 | 
| Section loaded | Path: \KnownDlls\nspr4.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 633552149 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 633553858 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 633554763 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633572306 | 
| File opened | Path: C:\WINDOWS\system32\USER32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633573293 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@dad6d0 | success or wait | 633574062 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 4 Value: D8 00 00 00 | success or wait | 633574307 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@14d0183 | success or wait | 633574948 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 1B A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 633575191 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 F4 05 00 00 E2 02 00 00 00 00 00 17 B2 00 00 00 10 00 00 00 B0 05 00 00 00 41 7E 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 10 09 00 00 04 00 00 76 FC 08 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 39 00 00 | success or wait | 633575478 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9e58be | success or wait | 633575947 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 83 F2 05 00 00 10 00 00 00 F4 05 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 80 11 00 00 00 10 06 00 00 0C 00 00 00 F8 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 88 A0 02 00 00 30 06 00 00 A2 02 00 | success or wait | 633576189 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1d43df5 | success or wait | 633576671 | 
| Section loaded | Path: C:\WINDOWS\system32\user32.dll Access: query and read Type: commit Baseaddress: CD0000 Size: 57344 Protection: readonly Mapped to pid: own pid | success or wait | 633576982 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633579610 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BB03E40 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633579888 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633580246 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633581139 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12fcbd8 | success or wait | 633581898 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 633582139 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@f003c1 | success or wait | 633582766 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 633583003 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 633583283 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@186787c | success or wait | 633583831 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 633584066 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150388c | success or wait | 633584545 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: CD0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633584851 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633587674 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BB189C8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633587938 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633588283 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633589173 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12fcbd8 | success or wait | 633589928 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 633590169 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@f003c1 | success or wait | 633590525 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 633590762 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 633591043 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@186787c | success or wait | 633591589 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 633591823 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150388c | success or wait | 633592301 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: CD0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633592605 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633595498 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BB18118 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633595761 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633596109 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633597003 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12fcbd8 | success or wait | 633597756 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 633597997 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@f003c1 | success or wait | 633598353 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 633598590 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 633598871 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@186787c | success or wait | 633599418 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 633599653 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150388c | success or wait | 633600131 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: CD0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633600437 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633603408 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BAFE1F8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633603671 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633604298 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633605192 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12fcbd8 | success or wait | 633605947 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 633606188 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@f003c1 | success or wait | 633606543 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 633606779 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 633607059 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@186787c | success or wait | 633607605 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 633607839 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150388c | success or wait | 633608458 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: CD0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633608767 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633611641 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BB07290 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633611905 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 633612721 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 633614045 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633637124 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633638033 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12fcbd8 | success or wait | 633638799 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 633639039 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@f003c1 | success or wait | 633639395 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 633639631 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 633639910 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@186787c | success or wait | 633640457 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 633640692 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150388c | success or wait | 633641171 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: CD0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633641476 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633644382 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BB07A10 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633644645 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633644967 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633645869 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12fcbd8 | success or wait | 633646625 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 633646865 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@f003c1 | success or wait | 633647220 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 633647457 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 633647657 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@186787c | success or wait | 633648201 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 633648436 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150388c | success or wait | 633648915 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: CD0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633649220 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633652224 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BB18B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633652499 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633652820 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633653725 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12fcbd8 | success or wait | 633654482 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 633654721 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@f003c1 | success or wait | 633655079 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 633655315 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 633655596 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@186787c | success or wait | 633656142 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 633656378 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150388c | success or wait | 633656857 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: CD0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633657161 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633660057 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BB05310 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633660329 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633660651 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633661542 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12fcbd8 | success or wait | 633662294 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 633662533 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@f003c1 | success or wait | 633662889 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 633663125 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 633663405 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@186787c | success or wait | 633663951 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 633664465 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150388c | success or wait | 633664955 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: CD0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633665259 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633668163 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BB18ED8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633668427 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633668749 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633669650 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12fcbd8 | success or wait | 633670405 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 633670644 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@f003c1 | success or wait | 633671000 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 633671235 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 633671516 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@186787c | success or wait | 633672062 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 633672298 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150388c | success or wait | 633672777 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: CD0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633673082 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633675980 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BB04D50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633676252 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633676574 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633677464 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12fcbd8 | success or wait | 633678218 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 633678456 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@f003c1 | success or wait | 633678812 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 633679048 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 633679329 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@186787c | success or wait | 633679874 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 633680109 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150388c | success or wait | 633680588 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: CD0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633680893 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633683706 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BB05538 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633683968 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633684290 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633685180 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12fcbd8 | success or wait | 633685933 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 633686172 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@f003c1 | success or wait | 633686606 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 633686845 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 633687127 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@186787c | success or wait | 633687674 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 633687910 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150388c | success or wait | 633688390 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: CD0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633688694 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633691635 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: BAFE698 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633691897 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633692248 | 
| File opened | Path: C:\WINDOWS\system32\WS2_32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633693145 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b0b0a0 | success or wait | 633693904 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 633694144 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11c0f9c | success or wait | 633694786 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 63 A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 633695023 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 22 01 00 00 1C 00 00 00 00 00 00 73 12 00 00 00 10 00 00 00 20 01 00 00 00 AB 71 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 70 01 00 00 04 00 00 20 F0 01 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 04 14 00 00 | success or wait | 633695303 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@144d9b2 | success or wait | 633695814 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 53 21 01 00 00 10 00 00 00 22 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 14 09 00 00 00 40 01 00 00 0A 00 00 00 26 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 F8 03 00 00 00 50 01 00 00 04 00 00 | success or wait | 633696053 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1304421 | success or wait | 633696534 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and read Type: commit Baseaddress: CD0000 Size: 20480 Protection: readonly Mapped to pid: own pid | success or wait | 633696839 | 
| Memory attributes changed | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633699087 | 
| File opened | Path: C:\WINDOWS\system32\ADVAPI32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633700621 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1c8dc5e | success or wait | 633701380 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 633701618 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1fbc31d | success or wait | 633702257 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 48 1D 90 49 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 633702495 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 46 07 00 00 3E 02 00 00 00 00 00 0B 71 00 00 00 10 00 00 00 20 07 00 00 00 DD 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 B0 09 00 00 04 00 00 B8 5B 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 A4 16 00 00 | success or wait | 633702776 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1c6a7fc | success or wait | 633703321 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C9 45 07 00 00 10 00 00 00 46 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 28 46 00 00 00 60 07 00 00 2C 00 00 00 4A 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 80 A9 01 00 00 B0 07 00 00 AA 01 00 | success or wait | 633703558 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13ebc5c | success or wait | 633704036 | 
| Section loaded | Path: C:\WINDOWS\system32\advapi32.dll Access: query and read Type: commit Baseaddress: CD0000 Size: 28672 Protection: readonly Mapped to pid: own pid | success or wait | 633704341 | 
| File opened | Path: C:\WINDOWS\system32\CRYPT32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633708666 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1c047f0 | success or wait | 633709426 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 633709667 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b2e9be | success or wait | 633710306 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D7 A0 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 633710544 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 44 08 00 00 DC 00 00 00 00 00 00 32 16 00 00 00 10 00 00 00 20 08 00 00 00 A8 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 50 09 00 00 04 00 00 30 C5 09 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 9C 1A 00 00 | success or wait | 633710824 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@fe256 | success or wait | 633711370 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C4 43 08 00 00 10 00 00 00 44 08 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 E8 23 00 00 00 60 08 00 00 24 00 00 00 48 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 50 67 00 00 00 90 08 00 00 68 00 00 | success or wait | 633711607 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d4855d | success or wait | 633712084 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and read Type: commit Baseaddress: CD0000 Size: 77824 Protection: readonly Mapped to pid: own pid | success or wait | 633712389 | 
| Mutant created | Name: \BaseNamedObjects\Global\ch971pGLCYGJFFTTU5XPPGQTZJ8OdYB | object name exists | 633715670 | 
| Thread created | PID: 676 TID: 984 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\lsass.exe | success or wait | 633717222 | 
| Thread resumed | TID: 984 PID: 676 Path: C:\WINDOWS\system32\lsass.exe | success or wait | 633718181 | 
| Thread terminated | TID: 1780 PID: 676 Path: C:\WINDOWS\system32\lsass.exe | unknown | 633718761 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | success or wait | 633719590 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 633721924 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 633771494 | 
| Memory allocated | PID: 676 Path: C:\WINDOWS\system32\lsass.exe Base: AF0000 Length: F2FF30 Allocation Type: unknown Protection: page execute and read and write | success or wait | 633801868 | 
| Thread created | PID: 676 TID: 864 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\lsass.exe | success or wait | 633803647 | 
| Thread resumed | TID: 864 PID: 676 Path: C:\WINDOWS\system32\lsass.exe | success or wait | 633805136 | 
| Process information queried | PID: 676 Info Class: Cookie | success or wait | 633809510 | 
| Process information queried | PID: 676 Info Class: Cookie | success or wait | 633810498 | 
| Thread created | PID: 676 TID: 1620 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\lsass.exe | success or wait | 633815299 | 
| Thread resumed | TID: 1620 PID: 676 Path: C:\WINDOWS\system32\lsass.exe | success or wait | 633815997 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 634615667 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 634616131 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 634616578 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 635734242 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 635734708 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 635735155 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 636857416 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 636857963 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 636858462 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 637972311 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 637972840 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 637973336 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 639090116 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 639090633 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 639091127 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 640208713 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 640209228 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 640209725 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 641327368 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 641327949 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 641328448 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 642445935 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 642446455 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 642446949 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 643564600 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 643565212 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 643565711 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 644683189 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 644683731 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 644684230 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 645801787 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 645802298 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 645802795 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 646923115 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 646923631 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 646924126 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 648041834 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 648042364 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 648042858 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 649157581 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 649158094 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 649158585 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 651317588 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 651330609 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 651335548 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 652404902 | 
| Thread delayed | Time: 0 TID: 184 | success or wait | 652408923 | 
| Process information queried | PID: 2116 Info Class: SessionInformation | success or wait | 656113333 | 
| File other op | Path: \lsassNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7fc620 | success or wait | 667295261 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 667564189 | 
| File other op | Path: \lsassNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7fc620 | success or wait | 676778338 | 
| File other op | Path: \lsassNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7fc620 | success or wait | 688289612 | 
| Thread created | PID: 676 TID: 3452 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\lsass.exe | success or wait | 741221115 | 
| Thread resumed | TID: 3452 PID: 676 Path: C:\WINDOWS\system32\lsass.exe | success or wait | 741236943 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | success or wait | 741244025 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 741244501 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 741257072 | 
| Thread resumed | TID: 3512 PID: 676 Path: C:\WINDOWS\system32\lsass.exe | success or wait | 745283642 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745316278 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745316890 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745317487 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745318047 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@a877c0 | success or wait | 745330484 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@4de8d8 | success or wait | 745331087 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745376038 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745377610 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745379785 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745385464 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745385997 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745391540 | 
| Section loaded | Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-507921405-1960408961-839522115-500\3451b0ec-3405-40b2-a0c3-2aff95c811f5 Access: query and read Type: commit Baseaddress: B00000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 745406358 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745416223 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745416875 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745417464 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745418063 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745465349 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745466981 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745468867 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745475473 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745476051 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745481894 | 
| Section loaded | Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Protect\CREDHIST Access: query and read Type: commit Baseaddress: B00000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 745487218 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745599777 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745600376 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745600926 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745601485 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745648331 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745649886 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745652381 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745658154 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745658690 | 
| Process information queried | PID: 676 Info Class: DefaultHardErrorMode | success or wait | 745664240 | 
| Sections | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| File Activities: 
 
 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Section Activities: 
 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Mutant Activities: 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Process Activities: 
 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Thread Activities: 
 
 
 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Memory Activities: 
 
 
 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Mutant created | Name: \BaseNamedObjects\zXeRY3a_PtW|00000000 | success or wait | 649675319 | 
| Thread created | PID: 836 TID: 1264 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 649682536 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 649685221 | 
| Section loaded | Path: \KnownDlls\WININET.dll Access: write and read and execute Type: unknown Baseaddress: 3D930000 Size: 942080 Protection: read write Mapped to pid: own pid | success or wait | 649687815 | 
| Mutant created | Name: \BaseNamedObjects\zXeRY3a_PtW|00000000 | success or wait | 649691797 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 649695019 | 
| Section loaded | Path: \KnownDlls\Normaliz.dll Access: write and read and execute Type: unknown Baseaddress: F00000 Size: 36864 Protection: read write Mapped to pid: own pid | conflicting addresses | 649715205 | 
| Section loaded | Path: \KnownDlls\urlmon.dll Access: write and read and execute Type: unknown Baseaddress: 78130000 Size: 1257472 Protection: read write Mapped to pid: own pid | success or wait | 651311725 | 
| Section loaded | Path: \KnownDlls\iertutil.dll Access: write and read and execute Type: unknown Baseaddress: 3DFD0000 Size: 2002944 Protection: read write Mapped to pid: own pid | success or wait | 651527095 | 
| Section loaded | Path: \KnownDlls\MSIMG32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 651823870 | 
| Section loaded | Path: C:\WINDOWS\system32\msimg32.dll Access: query and write and read and execute Type: image Baseaddress: 76380000 Size: 20480 Protection: read write Mapped to pid: own pid | success or wait | 651840075 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\iexplore.exe Access: query and write and read and execute and extend size Type: image Baseaddress: 76380000 Size: 20480 Protection: read write Mapped to pid: own pid | success or wait | 651857368 | 
| Thread created | PID: 836 TID: 2052 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 651866026 | 
| Section loaded | Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 2510000 Size: 1208320 Protection: readonly Mapped to pid: own pid | success or wait | 651868808 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and write copy | success or wait | 651873319 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 651874704 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 651878401 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1e89539 | success or wait | 651879954 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 651881071 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 651885681 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9d0366 | success or wait | 651886310 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 651887869 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 651889671 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 651890930 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@4a553f | success or wait | 651891343 | 
| Process information queried | PID: 836 Info Class: DeviceMap | success or wait | 651892215 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 651892427 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@22b7f8 | success or wait | 651894260 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: FC0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 651901523 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 651914373 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BAFEA50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 651914990 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 651926604 | 
| Thread created | PID: 836 TID: 2056 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 651931212 | 
| Section loaded | Path: C:\WINDOWS\system32\ir50_qcx.dll Access: write and read and execute Type: commit Baseaddress: 2680000 Size: 184320 Protection: execute Mapped to pid: own pid | success or wait | 651932173 | 
| Thread created | PID: 836 TID: 2060 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 651940810 | 
| Process information queried | PID: 836 Info Class: Wow64Information | success or wait | 651948495 | 
| Process information queried | PID: 836 Info Class: Wow64Information | success or wait | 651948633 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 651948818 | 
| Section loaded | Path: C:\WINDOWS\system32\ir50_qcx.dll Access: query and read Type: commit Baseaddress: 2680000 Size: 184320 Protection: readonly Mapped to pid: own pid | success or wait | 651949618 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 651951278 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 651952553 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 651956711 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 651959442 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1e89539 | success or wait | 651963582 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 651963943 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 651964685 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9d0366 | success or wait | 651965976 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 651969106 | 
| Section loaded | Path: C:\WINDOWS\system32\ir50_qcx.dll Access: write and read and execute Type: commit Baseaddress: 2680000 Size: 184320 Protection: execute Mapped to pid: own pid | success or wait | 651969554 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 651970490 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@4a553f | success or wait | 651972291 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 651974150 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@22b7f8 | success or wait | 651975846 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 2680000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 651977573 | 
| Section loaded | Path: C:\WINDOWS\system32\ir50_qcx.dll Access: query and read Type: commit Baseaddress: 2690000 Size: 184320 Protection: readonly Mapped to pid: own pid | success or wait | 651979287 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 651991371 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652030597 | 
| Section loaded | Path: C:\WINDOWS\system32\ir50_qc.dll Access: write and read and execute Type: commit Baseaddress: 2680000 Size: 200704 Protection: execute Mapped to pid: own pid | success or wait | 652036953 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652039154 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BB186C0 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652040376 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652041964 | 
| Section loaded | Path: C:\WINDOWS\system32\ir50_qc.dll Access: query and read Type: commit Baseaddress: 2680000 Size: 200704 Protection: readonly Mapped to pid: own pid | success or wait | 652047506 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652051085 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652057849 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1e89539 | success or wait | 652058045 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 652059951 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9d0366 | success or wait | 652060684 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 652065558 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652066228 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 652067884 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@4a553f | success or wait | 652070341 | 
| Section loaded | Path: C:\WINDOWS\system32\ir50_qc.dll Access: write and read and execute Type: commit Baseaddress: 2680000 Size: 200704 Protection: execute Mapped to pid: own pid | success or wait | 652071371 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 652075855 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@22b7f8 | success or wait | 652077496 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 26C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652079403 | 
| Section loaded | Path: C:\WINDOWS\system32\ir50_qc.dll Access: query and read Type: commit Baseaddress: 2680000 Size: 200704 Protection: readonly Mapped to pid: own pid | success or wait | 652080140 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652091232 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652094539 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652098871 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BB06F28 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652099976 | 
| Section loaded | Path: C:\WINDOWS\system32\ir50_32.dll Access: write and read and execute Type: commit Baseaddress: 2680000 Size: 757760 Protection: execute Mapped to pid: own pid | success or wait | 652101127 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652101380 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652130696 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1e89539 | success or wait | 652132610 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 652134677 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9d0366 | success or wait | 652170340 | 
| Section loaded | Path: C:\WINDOWS\system32\ir50_32.dll Access: query and read Type: commit Baseaddress: 2680000 Size: 757760 Protection: readonly Mapped to pid: own pid | success or wait | 652171950 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 652172331 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 652190299 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652193177 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@4a553f | success or wait | 652193432 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 652200741 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652201441 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@22b7f8 | success or wait | 652204636 | 
| Section loaded | Path: C:\WINDOWS\system32\ir50_32.dll Access: write and read and execute Type: commit Baseaddress: 2680000 Size: 757760 Protection: execute Mapped to pid: own pid | success or wait | 652205780 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 2680000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652206257 | 
| Section loaded | Path: C:\WINDOWS\system32\ir50_32.dll Access: query and read Type: commit Baseaddress: 2680000 Size: 757760 Protection: readonly Mapped to pid: own pid | success or wait | 652216019 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652222110 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BB04B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652224693 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652226860 | 
| Process information queried | PID: 836 Info Class: Wow64Information | success or wait | 652227295 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652232906 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652234060 | 
| Section loaded | Path: C:\WINDOWS\system32\ir41_qcx.dll Access: write and read and execute Type: commit Baseaddress: 2680000 Size: 339968 Protection: execute Mapped to pid: own pid | success or wait | 652239726 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652247484 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1e89539 | success or wait | 652249734 | 
| Section loaded | Path: C:\WINDOWS\system32\ir41_qcx.dll Access: query and read Type: commit Baseaddress: 2680000 Size: 339968 Protection: readonly Mapped to pid: own pid | success or wait | 652250348 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 652253510 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9d0366 | success or wait | 652254965 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 652255863 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652258916 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 652259095 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@4a553f | success or wait | 652261763 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 652265380 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652265974 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@22b7f8 | success or wait | 652267160 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 2680000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652269049 | 
| Section loaded | Path: C:\WINDOWS\system32\ir41_qcx.dll Access: write and read and execute Type: commit Baseaddress: 2680000 Size: 339968 Protection: execute Mapped to pid: own pid | success or wait | 652269771 | 
| Section loaded | Path: C:\WINDOWS\system32\ir41_qcx.dll Access: query and read Type: commit Baseaddress: 2680000 Size: 339968 Protection: readonly Mapped to pid: own pid | success or wait | 652281206 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652283385 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BB17D98 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652284693 | 
| Section loaded | Path: \KnownDlls\nspr4.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 652287371 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652288007 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 652292043 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652292692 | 
| Section loaded | Path: C:\WINDOWS\system32\ir41_qc.dll Access: write and read and execute Type: commit Baseaddress: 2680000 Size: 122880 Protection: execute Mapped to pid: own pid | success or wait | 652297435 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 652313847 | 
| Section loaded | Path: C:\WINDOWS\system32\ir41_qc.dll Access: query and read Type: commit Baseaddress: 2680000 Size: 122880 Protection: readonly Mapped to pid: own pid | success or wait | 652331229 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652338686 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652342561 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652349026 | 
| File opened | Path: C:\WINDOWS\system32\USER32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652350327 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@15c0729 | success or wait | 652352349 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 4 Value: D8 00 00 00 | success or wait | 652354190 | 
| Section loaded | Path: C:\WINDOWS\system32\ir41_qc.dll Access: write and read and execute Type: commit Baseaddress: 2680000 Size: 122880 Protection: execute Mapped to pid: own pid | success or wait | 652354754 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@da1c9f | success or wait | 652358068 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 1B A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 652359132 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 F4 05 00 00 E2 02 00 00 00 00 00 17 B2 00 00 00 10 00 00 00 B0 05 00 00 00 41 7E 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 10 09 00 00 04 00 00 76 FC 08 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 39 00 00 | success or wait | 652361037 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@18d3d6c | success or wait | 652365483 | 
| Section loaded | Path: C:\WINDOWS\system32\ir41_qc.dll Access: query and read Type: commit Baseaddress: 2680000 Size: 122880 Protection: readonly Mapped to pid: own pid | success or wait | 652365933 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 83 F2 05 00 00 10 00 00 00 F4 05 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 80 11 00 00 00 10 06 00 00 0C 00 00 00 F8 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 88 A0 02 00 00 30 06 00 00 A2 02 00 | success or wait | 652366895 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1bbad6f | success or wait | 652368518 | 
| Section loaded | Path: C:\WINDOWS\system32\user32.dll Access: query and read Type: commit Baseaddress: 2680000 Size: 57344 Protection: readonly Mapped to pid: own pid | success or wait | 652370264 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652373721 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652377358 | 
| Section loaded | Path: C:\WINDOWS\system32\ir41_32.ax Access: write and read and execute Type: commit Baseaddress: 2680000 Size: 851968 Protection: execute Mapped to pid: own pid | success or wait | 652383782 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652388141 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BB03E40 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652390741 | 
| Section loaded | Path: C:\WINDOWS\system32\ir41_32.ax Access: query and read Type: commit Baseaddress: 2680000 Size: 851968 Protection: readonly Mapped to pid: own pid | success or wait | 652394436 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652394715 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652400697 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652401930 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@778590 | success or wait | 652406854 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652418099 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652418405 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e1ccdf | success or wait | 652420713 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652422302 | 
| Section loaded | Path: C:\WINDOWS\system32\ir41_32.ax Access: write and read and execute Type: commit Baseaddress: 2680000 Size: 851968 Protection: execute Mapped to pid: own pid | success or wait | 652423101 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652425697 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@51762a | success or wait | 652427335 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652428342 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24c3aa | success or wait | 652431736 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 2750000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652456210 | 
| Section loaded | Path: C:\WINDOWS\system32\ir41_32.ax Access: query and read Type: commit Baseaddress: 2680000 Size: 851968 Protection: readonly Mapped to pid: own pid | success or wait | 652458978 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652468300 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652472985 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652473327 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BB189C8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652477386 | 
| Section loaded | Path: C:\WINDOWS\system32\ir32_32.dll Access: write and read and execute Type: commit Baseaddress: 2680000 Size: 200704 Protection: execute Mapped to pid: own pid | success or wait | 652478719 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652479114 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652485774 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@778590 | success or wait | 652487850 | 
| Section loaded | Path: C:\WINDOWS\system32\ir32_32.dll Access: query and read Type: commit Baseaddress: 2680000 Size: 200704 Protection: readonly Mapped to pid: own pid | success or wait | 652488633 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652493077 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e1ccdf | success or wait | 652494145 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652495175 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652499280 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652499469 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@51762a | success or wait | 652501830 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652521668 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652522538 | 
| Section loaded | Path: C:\WINDOWS\system32\ir32_32.dll Access: write and read and execute Type: commit Baseaddress: 2680000 Size: 200704 Protection: execute Mapped to pid: own pid | success or wait | 652526493 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24c3aa | success or wait | 652527961 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 2680000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652530079 | 
| Section loaded | Path: C:\WINDOWS\system32\ir32_32.dll Access: query and read Type: commit Baseaddress: 2680000 Size: 200704 Protection: readonly Mapped to pid: own pid | success or wait | 652540089 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652542407 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652548936 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BB18118 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652552698 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652553969 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652559412 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\iexplore.exe Access: write and read and execute Type: commit Baseaddress: 2680000 Size: 638976 Protection: execute Mapped to pid: own pid | success or wait | 652562995 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652573967 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@778590 | success or wait | 652578395 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\iexplore.exe Access: query and read Type: commit Baseaddress: 2680000 Size: 638976 Protection: readonly Mapped to pid: own pid | success or wait | 652578808 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652582142 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e1ccdf | success or wait | 652584741 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652601637 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652602013 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652603320 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@51762a | success or wait | 652604819 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652611719 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652613088 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24c3aa | success or wait | 652615331 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 2720000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652616352 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\iexplore.exe Access: write and read and execute Type: commit Baseaddress: 2680000 Size: 638976 Protection: execute Mapped to pid: own pid | success or wait | 652620415 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\iexplore.exe Access: query and read Type: commit Baseaddress: 2680000 Size: 638976 Protection: readonly Mapped to pid: own pid | success or wait | 652632142 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652633490 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BAFE1F8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652637358 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652639021 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652641896 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652649228 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@778590 | success or wait | 652651126 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652653821 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e1ccdf | success or wait | 652654527 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652656727 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652656968 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652658782 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@51762a | success or wait | 652660343 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652662304 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652663931 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24c3aa | success or wait | 652665896 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 2510000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652666958 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652679448 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BB07290 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652700869 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 652703127 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 652705012 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652743783 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652749634 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@778590 | success or wait | 652752263 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652753999 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e1ccdf | success or wait | 652755585 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652758969 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652760231 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@51762a | success or wait | 652762352 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652765648 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24c3aa | success or wait | 652767178 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 2510000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652768743 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652785185 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BB07A10 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652786397 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652787647 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652791655 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@778590 | success or wait | 652796759 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652798187 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e1ccdf | success or wait | 652799582 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652800981 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652802118 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@51762a | success or wait | 652803636 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652806726 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24c3aa | success or wait | 652808034 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 2510000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652809533 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652825466 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BB18B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652826577 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652827447 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652827892 | 
| Process information queried | PID: 836 Info Class: DefaultHardErrorMode | success or wait | 652832536 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\iexplore.exe Access: query and read Type: commit Baseaddress: 2510000 Size: 638976 Protection: readonly Mapped to pid: own pid | success or wait | 652834039 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652835086 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@778590 | success or wait | 652861192 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652863279 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e1ccdf | success or wait | 652865316 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652867432 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652869017 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@51762a | success or wait | 652870388 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652874213 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24c3aa | success or wait | 652875791 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 2520000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652876953 | 
| Process created | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Cmdline: C:\Program Files\Internet Explorer\IEXPLORE.EXE -Embedding Createflags: none | success or wait | 652882920 | 
| Process information queried | PID: 2116 Info Class: BasicInformation | success or wait | 652887737 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652894111 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BB05310 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652895426 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652897046 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652907644 | 
| Process information queried | PID: 2116 Info Class: BasicInformation | success or wait | 652924556 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@778590 | success or wait | 652949524 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652950508 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e1ccdf | success or wait | 652954332 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652956984 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652958390 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@51762a | success or wait | 652964693 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 652964985 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652971377 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24c3aa | success or wait | 652972838 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 2520000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652974059 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 653000185 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BB18ED8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 653004003 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 653014049 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 653030471 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 653031410 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 653033737 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@778590 | success or wait | 653036212 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 653036934 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e1ccdf | success or wait | 653038503 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 653040197 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 653040954 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@51762a | success or wait | 653041926 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 653044051 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24c3aa | success or wait | 653044975 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 2520000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 653045700 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 653055762 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BB04D50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 653056363 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 653057298 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 653061428 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@778590 | success or wait | 653063624 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 653064187 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e1ccdf | success or wait | 653065804 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 653067778 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 653070217 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@51762a | success or wait | 653100063 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 653118604 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24c3aa | success or wait | 653120765 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 2520000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 653122853 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 653142319 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BB05538 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 653142945 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 653146843 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 654314148 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 654327844 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 654330879 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 654335725 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@778590 | success or wait | 654338900 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 654344229 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e1ccdf | success or wait | 654354016 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 654362590 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 654366828 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@51762a | success or wait | 654378599 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 654387232 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24c3aa | success or wait | 654388454 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 2520000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 654393955 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 654419531 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: BAFE698 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 654424451 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 654426091 | 
| File opened | Path: c:\windows\system32\WS2_32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 654429827 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a9dc55 | success or wait | 654431490 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 654436645 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c069ec | success or wait | 654438422 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 63 A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 654440261 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 22 01 00 00 1C 00 00 00 00 00 00 73 12 00 00 00 10 00 00 00 20 01 00 00 00 AB 71 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 70 01 00 00 04 00 00 20 F0 01 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 04 14 00 00 | success or wait | 654442973 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@6a086a | success or wait | 654445600 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 53 21 01 00 00 10 00 00 00 22 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 14 09 00 00 00 40 01 00 00 0A 00 00 00 26 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 F8 03 00 00 00 50 01 00 00 04 00 00 | success or wait | 654447407 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@14e8936 | success or wait | 654453025 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and read Type: commit Baseaddress: 2520000 Size: 20480 Protection: readonly Mapped to pid: own pid | success or wait | 654479371 | 
| Process information queried | PID: 2116 Info Class: ImageFileName | success or wait | 654513501 | 
| Process information queried | PID: 836 Info Class: DeviceMap | success or wait | 654516629 | 
| Memory attributes changed | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 654521746 | 
| Process information queried | PID: 836 Info Class: DeviceMap | success or wait | 654522648 | 
| Memory read | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7FFDF000 Length: 2860 Value: FF FF FF FF 00 00 14 00 00 20 13 00 00 00 00 00 00 1E 00 00 00 00 00 00 00 F0 FD 7F 00 00 00 00 44 08 00 00 54 08 00 00 00 00 00 00 00 00 00 00 00 40 FD 7F 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 09 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | success or wait | 654528158 | 
| Memory read | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7FFD4000 Length: 488 Value: 00 00 00 00 FF FF FF FF 00 00 40 00 00 00 00 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 FB 7F 00 10 FC 7F 00 20 FD 7F 01 00 00 00 00 00 00 00 00 00 00 00 00 80 9B 07 6D E8 FF FF 00 00 10 00 00 20 00 00 00 00 01 00 00 10 00 00 00 00 00 00 7C 03 00 00 10 42 FD 7F 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 05 00 00 00 01 00 00 00 28 0A 00 03 02 00 00 00 02 00 00 00 05 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | success or wait | 654532765 | 
| Memory read | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 40003C Length: 4 Value: E0 00 00 00 | success or wait | 654534931 | 
| Memory read | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 4000F8 Length: 24 Value: 0B 01 08 00 00 A0 00 00 00 04 09 00 00 00 00 00 25 1A 00 00 00 10 00 00 | success or wait | 654536295 | 
| Memory allocated | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BAD0000 Length: ADF3F8 Allocation Type: unknown Protection: page execute and read and write | success or wait | 654538934 | 
| File opened | Path: C:\WINDOWS\system32\ADVAPI32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 654539919 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11258b2 | success or wait | 654541870 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 654542952 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 654543418 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 654544352 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@17d2d70 | success or wait | 654545181 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BAD0000 Length: 4E000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 654545926 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 48 1D 90 49 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 654548208 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 46 07 00 00 3E 02 00 00 00 00 00 0B 71 00 00 00 10 00 00 00 20 07 00 00 00 DD 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 B0 09 00 00 04 00 00 B8 5B 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 A4 16 00 00 | success or wait | 654549440 | 
| Memory written | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 654570682 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1325573 | success or wait | 654573994 | 
| Memory read | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 401A25 Length: 5 Value: E8 87 FD FF FF | success or wait | 654575024 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BAFE048 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 654577724 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C9 45 07 00 00 10 00 00 00 46 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 28 46 00 00 00 60 07 00 00 2C 00 00 00 4A 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 80 A9 01 00 00 B0 07 00 00 AA 01 00 | success or wait | 654577993 | 
| Memory written | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BAFE048 Length: 421 Value: 25 1A 40 00 9B 61 AF 0B E8 87 FD FF FF 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 05 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 E9 71 47 6F 0B 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73 5C 49 6E 74 65 72 6E 65 74 20 45 78 70 6C 6F 72 65 72 5C 69 65 78 70 6C 6F 72 65 2E 65 78 65 00 78 70 6C 6F 72 65 72 5C 69 65 78 70 6C 6F 72 65 2E 65 78 65 00 23 15 00 00 00 00 00 F9 8B 00 00 00 00 00 00 FF FF FF FF FF FF FF 7F 01 00 00 00 02 00 00 00 F4 01 | success or wait | 654594019 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1882c1a | success or wait | 654594240 | 
| Section loaded | Path: C:\WINDOWS\system32\advapi32.dll Access: query and read Type: commit Baseaddress: 2520000 Size: 28672 Protection: readonly Mapped to pid: own pid | success or wait | 654595113 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 401A25 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 654598215 | 
| Memory written | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 401A25 Length: 5 Value: E9 71 47 6F 0B | success or wait | 654614194 | 
| Thread resumed | TID: 2132 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 654618099 | 
| File opened | Path: c:\windows\system32\CRYPT32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 654629735 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1079724 | success or wait | 654634609 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 654635712 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@153c017 | success or wait | 654637660 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D7 A0 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 654643278 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 44 08 00 00 DC 00 00 00 00 00 00 32 16 00 00 00 10 00 00 00 20 08 00 00 00 A8 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 50 09 00 00 04 00 00 30 C5 09 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 9C 1A 00 00 | success or wait | 654644032 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@16827b5 | success or wait | 654650303 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C4 43 08 00 00 10 00 00 00 44 08 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 E8 23 00 00 00 60 08 00 00 24 00 00 00 48 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 50 67 00 00 00 90 08 00 00 68 00 00 | success or wait | 654653972 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1071537 | success or wait | 654654855 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and read Type: commit Baseaddress: 2520000 Size: 77824 Protection: readonly Mapped to pid: own pid | success or wait | 654656414 | 
| Mutant created | Name: \BaseNamedObjects\Global\ch971pGLCYGJFFTTU5XPPGQTZJ8OdYB | object name exists | 654671140 | 
| Thread created | PID: 836 TID: 2212 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 654678040 | 
| Thread resumed | TID: 2212 PID: 836 Path: C:\WINDOWS\system32\svchost.exe | success or wait | 654681354 | 
| Thread terminated | TID: 1264 PID: 836 Path: C:\WINDOWS\system32\svchost.exe | unknown | 654682806 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | success or wait | 654684055 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 654685232 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 654728985 | 
| Memory allocated | PID: 836 Path: C:\WINDOWS\system32\svchost.exe Base: EC0000 Length: 255FF30 Allocation Type: unknown Protection: page execute and read and write | success or wait | 654762481 | 
| Thread created | PID: 836 TID: 2220 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 654771477 | 
| Thread resumed | TID: 2220 PID: 836 Path: C:\WINDOWS\system32\svchost.exe | success or wait | 654773402 | 
| Process information queried | PID: 836 Info Class: Cookie | success or wait | 654775373 | 
| Process information queried | PID: 836 Info Class: Cookie | success or wait | 654776451 | 
| Thread created | PID: 836 TID: 2224 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 654782793 | 
| Thread resumed | TID: 2224 PID: 836 Path: C:\WINDOWS\system32\svchost.exe | success or wait | 654784083 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 655438417 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 655442369 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 655445885 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 656546535 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 656550647 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 656552818 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 658015942 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 658020785 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 658023408 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 659113709 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 659115184 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 659116629 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 660235647 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 660240095 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 660242959 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 661933320 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 661938744 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 661941447 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 663478683 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 663493561 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 663497349 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 664601044 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 664606031 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 664609325 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 665717247 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 665721800 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 665724282 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 666835789 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 666839340 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 666843111 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 667951466 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 667953392 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 667954502 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 669225706 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 669227919 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 669229471 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 670300498 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 670302702 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 670303805 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 672104166 | 
| Thread delayed | Time: 0 TID: 2052 | success or wait | 672109799 | 
| Thread created | PID: 836 TID: 3624 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 759512463 | 
| Thread resumed | TID: 3624 PID: 836 Path: C:\WINDOWS\system32\svchost.exe | success or wait | 759528487 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | pipe not available | 759533855 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | success or wait | 759537052 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 759540492 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 759545589 | 
| Sections | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| File Activities: 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Section Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Mutant Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Process Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Thread Activities: 
 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Memory Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Mutant created | Name: \BaseNamedObjects\zXeRY3a_PtW|00000000 | success or wait | 649532522 | 
| Thread created | PID: 912 TID: 1852 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 649535525 | 
| Section loaded | Path: \KnownDlls\CRYPT32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 649538461 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and write and read and execute Type: image Baseaddress: 77A80000 Size: 610304 Protection: read write Mapped to pid: own pid | success or wait | 649539898 | 
| Mutant created | Name: \BaseNamedObjects\zXeRY3a_PtW|00000000 | object name exists | 649541700 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 649542435 | 
| Section loaded | Path: \KnownDlls\MSASN1.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 649545452 | 
| Section loaded | Path: C:\WINDOWS\system32\msasn1.dll Access: query and write and read and execute Type: image Baseaddress: 77B20000 Size: 73728 Protection: read write Mapped to pid: own pid | success or wait | 649546937 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 649561851 | 
| Section loaded | Path: \KnownDlls\WININET.dll Access: write and read and execute Type: unknown Baseaddress: 3D930000 Size: 942080 Protection: read write Mapped to pid: own pid | success or wait | 649563504 | 
| Section loaded | Path: \KnownDlls\Normaliz.dll Access: write and read and execute Type: unknown Baseaddress: B80000 Size: 36864 Protection: read write Mapped to pid: own pid | conflicting addresses | 649616049 | 
| Section loaded | Path: \KnownDlls\urlmon.dll Access: write and read and execute Type: unknown Baseaddress: 78130000 Size: 1257472 Protection: read write Mapped to pid: own pid | success or wait | 649639393 | 
| Section loaded | Path: \KnownDlls\iertutil.dll Access: write and read and execute Type: unknown Baseaddress: 3DFD0000 Size: 2002944 Protection: read write Mapped to pid: own pid | success or wait | 649672116 | 
| Section loaded | Path: \KnownDlls\MSIMG32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 651684813 | 
| Section loaded | Path: C:\WINDOWS\system32\msimg32.dll Access: query and write and read and execute Type: image Baseaddress: 76380000 Size: 20480 Protection: read write Mapped to pid: own pid | success or wait | 651705460 | 
| Thread created | PID: 912 TID: 1812 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 651741306 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and write copy | success or wait | 651751328 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 651752744 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 651754737 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ae9ef9 | success or wait | 651762833 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 651763093 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@147164d | success or wait | 651763702 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 651763959 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 651764263 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@942eb | success or wait | 651764849 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 651768010 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@85b8d | success or wait | 651769532 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: DB0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 651770423 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 651830070 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BAFEA50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 651836960 | 
| Thread created | PID: 912 TID: 1072 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 651843971 | 
| Thread created | PID: 912 TID: 1340 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 651856703 | 
| Process information queried | PID: 912 Info Class: Wow64Information | success or wait | 651863088 | 
| Process information queried | PID: 912 Info Class: Wow64Information | success or wait | 651863226 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 651863408 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 651865147 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 651868106 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 651869696 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ae9ef9 | success or wait | 651871655 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 651877371 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@147164d | success or wait | 651879071 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 651880403 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 651881869 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@942eb | success or wait | 651884056 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 651885332 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@85b8d | success or wait | 651887113 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: E30000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 651888968 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 651906418 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BB186C0 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 651907304 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 651909384 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 651916776 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ae9ef9 | success or wait | 651920410 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 651921192 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@147164d | success or wait | 651925846 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 651929375 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 651931710 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@942eb | success or wait | 651933855 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 651936944 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@85b8d | success or wait | 651938340 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: E30000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 651939785 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 651957197 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BB06F28 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 651959825 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 651964157 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 651968932 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ae9ef9 | success or wait | 651973174 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 651974736 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@147164d | success or wait | 651976445 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 651979547 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 651980840 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@942eb | success or wait | 651982468 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 651983706 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@85b8d | success or wait | 651988045 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: E30000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 651990778 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652052088 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BB04B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652053690 | 
| Process information queried | PID: 912 Info Class: Wow64Information | success or wait | 652056455 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652060229 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652062865 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ae9ef9 | success or wait | 652063719 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 652065115 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@147164d | success or wait | 652070148 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 652071634 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 652073715 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@942eb | success or wait | 652075191 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 652080988 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@85b8d | success or wait | 652083614 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: E30000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652084288 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652102055 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BB17D98 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652103608 | 
| Section loaded | Path: \KnownDlls\nspr4.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 652105523 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 652110318 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 652112906 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652204394 | 
| File opened | Path: C:\WINDOWS\system32\USER32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652209615 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b29562 | success or wait | 652211444 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 4 Value: D8 00 00 00 | success or wait | 652218425 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@6d70fc | success or wait | 652220333 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 1B A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 652221477 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 F4 05 00 00 E2 02 00 00 00 00 00 17 B2 00 00 00 10 00 00 00 B0 05 00 00 00 41 7E 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 10 09 00 00 04 00 00 76 FC 08 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 39 00 00 | success or wait | 652222945 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@114b3af | success or wait | 652224500 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 83 F2 05 00 00 10 00 00 00 F4 05 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 80 11 00 00 00 10 06 00 00 0C 00 00 00 F8 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 88 A0 02 00 00 30 06 00 00 A2 02 00 | success or wait | 652227091 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@20e54a | success or wait | 652233690 | 
| Section loaded | Path: C:\WINDOWS\system32\user32.dll Access: query and read Type: commit Baseaddress: E30000 Size: 57344 Protection: readonly Mapped to pid: own pid | success or wait | 652235032 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652251930 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BB03E40 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652253771 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652255138 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652261359 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ad637e | success or wait | 652262535 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652270654 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f07e8 | success or wait | 652272215 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652273405 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652275150 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@100271a | success or wait | 652276535 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652277449 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10725b4 | success or wait | 652280015 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: E30000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652281597 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652300859 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BB189C8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652304561 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652304958 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652305944 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ad637e | success or wait | 652306789 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652313562 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f07e8 | success or wait | 652330196 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652331984 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652336568 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@100271a | success or wait | 652338928 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652339936 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10725b4 | success or wait | 652342767 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: E30000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652344767 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652363380 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BB18118 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652365209 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652366688 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652374025 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ad637e | success or wait | 652377715 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652379367 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f07e8 | success or wait | 652380884 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652384567 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652386088 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@100271a | success or wait | 652387952 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652392715 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10725b4 | success or wait | 652394976 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: E30000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652396395 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652422531 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BAFE1F8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652423797 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652425498 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652431514 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ad637e | success or wait | 652456514 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652457986 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f07e8 | success or wait | 652460289 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652463598 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652465262 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@100271a | success or wait | 652467432 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652474044 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10725b4 | success or wait | 652476653 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: E30000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652477767 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652493720 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BB07290 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652494634 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 652496779 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 652502013 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652552347 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652558815 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ad637e | success or wait | 652560832 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652562388 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f07e8 | success or wait | 652566518 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652567328 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652568108 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@100271a | success or wait | 652569961 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652570703 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10725b4 | success or wait | 652571242 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: E30000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652571581 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652604591 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BB07A10 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652610860 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652613530 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652619776 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ad637e | success or wait | 652624085 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652625756 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f07e8 | success or wait | 652627054 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652628374 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652633156 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@100271a | success or wait | 652634848 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652636308 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10725b4 | success or wait | 652638513 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: E30000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652639734 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652660149 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BB18B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652663123 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652664312 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652668778 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ad637e | success or wait | 652670644 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652674394 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f07e8 | success or wait | 652676525 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652677382 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652679620 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@100271a | success or wait | 652692764 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652699330 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10725b4 | success or wait | 652702366 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: E30000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652704604 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652735979 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BB05310 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652739205 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652743943 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652748088 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ad637e | success or wait | 652750028 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652754806 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f07e8 | success or wait | 652756288 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652757774 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652760432 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@100271a | success or wait | 652762540 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652763933 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10725b4 | success or wait | 652765900 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: E30000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652767442 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652784015 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BB18ED8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652785406 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652786627 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652792773 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ad637e | success or wait | 652794799 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652798779 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f07e8 | success or wait | 652800072 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652801230 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652804591 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@100271a | success or wait | 652806310 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652807615 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10725b4 | success or wait | 652809231 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: E30000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652810697 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652826195 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BB04D50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652827617 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652829246 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652835875 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ad637e | success or wait | 652860078 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 652860322 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652862948 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f07e8 | success or wait | 652865089 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652866052 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652870148 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@100271a | success or wait | 652871835 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652872881 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10725b4 | success or wait | 652874800 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: E30000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652876226 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652892554 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BB05538 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652894313 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652895627 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652907909 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ad637e | success or wait | 652924997 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652948931 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f07e8 | success or wait | 652950217 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652954012 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652955517 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@100271a | success or wait | 652957205 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652958660 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 652970382 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10725b4 | success or wait | 652970739 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 652971622 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: E30000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652972444 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652990922 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BAFE698 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652994193 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652999679 | 
| File opened | Path: c:\windows\system32\WS2_32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 653031268 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@3c855e | success or wait | 653032646 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 653034326 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@157fe3d | success or wait | 653035447 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 63 A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 653036424 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 22 01 00 00 1C 00 00 00 00 00 00 73 12 00 00 00 10 00 00 00 20 01 00 00 00 AB 71 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 70 01 00 00 04 00 00 20 F0 01 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 04 14 00 00 | success or wait | 653039207 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f49401 | success or wait | 653040010 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 53 21 01 00 00 10 00 00 00 22 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 14 09 00 00 00 40 01 00 00 0A 00 00 00 26 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 F8 03 00 00 00 50 01 00 00 04 00 00 | success or wait | 653040780 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@20e746 | success or wait | 653042856 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and read Type: commit Baseaddress: E30000 Size: 20480 Protection: readonly Mapped to pid: own pid | success or wait | 653043542 | 
| Memory attributes changed | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 653051925 | 
| File opened | Path: C:\WINDOWS\system32\ADVAPI32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 653058843 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@2fbd59 | success or wait | 653060021 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 653062015 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@383efa | success or wait | 653063420 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 48 1D 90 49 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 653064016 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 46 07 00 00 3E 02 00 00 00 00 00 0B 71 00 00 00 10 00 00 00 20 07 00 00 00 DD 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 B0 09 00 00 04 00 00 B8 5B 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 A4 16 00 00 | success or wait | 653066369 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@aecfd3 | success or wait | 653067403 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C9 45 07 00 00 10 00 00 00 46 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 28 46 00 00 00 60 07 00 00 2C 00 00 00 4A 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 80 A9 01 00 00 B0 07 00 00 AA 01 00 | success or wait | 653068070 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ce3561 | success or wait | 653115663 | 
| Section loaded | Path: C:\WINDOWS\system32\advapi32.dll Access: query and read Type: commit Baseaddress: E30000 Size: 28672 Protection: readonly Mapped to pid: own pid | success or wait | 653118317 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 654314000 | 
| File opened | Path: C:\WINDOWS\system32\CRYPT32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 654326089 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 654327552 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 654330734 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12a801 | success or wait | 654331270 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 654336175 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d41115 | success or wait | 654344543 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D7 A0 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 654354196 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 44 08 00 00 DC 00 00 00 00 00 00 32 16 00 00 00 10 00 00 00 20 08 00 00 00 A8 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 50 09 00 00 04 00 00 30 C5 09 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 9C 1A 00 00 | success or wait | 654354801 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ad98e6 | success or wait | 654366415 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C4 43 08 00 00 10 00 00 00 44 08 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 E8 23 00 00 00 60 08 00 00 24 00 00 00 48 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 50 67 00 00 00 90 08 00 00 68 00 00 | success or wait | 654375269 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1112776 | success or wait | 654379644 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and read Type: commit Baseaddress: E30000 Size: 77824 Protection: readonly Mapped to pid: own pid | success or wait | 654380421 | 
| Mutant created | Name: \BaseNamedObjects\Global\ch971pGLCYGJFFTTU5XPPGQTZJ8OdYB | object name exists | 654420668 | 
| Thread created | PID: 912 TID: 2176 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 654434287 | 
| Thread resumed | TID: 2176 PID: 912 Path: C:\WINDOWS\system32\svchost.exe | success or wait | 654436284 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | success or wait | 654437852 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 654439680 | 
| Thread terminated | TID: 1852 PID: 912 Path: C:\WINDOWS\system32\svchost.exe | unknown | 654440773 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 654480884 | 
| Memory allocated | PID: 912 Path: C:\WINDOWS\system32\svchost.exe Base: BF0000 Length: E6FF30 Allocation Type: unknown Protection: page execute and read and write | success or wait | 654519115 | 
| Thread created | PID: 912 TID: 2184 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 654525457 | 
| Thread resumed | TID: 2184 PID: 912 Path: C:\WINDOWS\system32\svchost.exe | success or wait | 654527606 | 
| Process information queried | PID: 912 Info Class: Cookie | success or wait | 654534666 | 
| Process information queried | PID: 912 Info Class: Cookie | success or wait | 654536030 | 
| Thread created | PID: 912 TID: 2188 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 654542433 | 
| Thread resumed | TID: 2188 PID: 912 Path: C:\WINDOWS\system32\svchost.exe | success or wait | 654545436 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 655438029 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 655441852 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 655445381 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 656546389 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 656550355 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 656552673 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 658015797 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 658020493 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 658023264 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 659113599 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 659114988 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 659116452 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 660235500 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 660239801 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 660242813 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 661933188 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 661938481 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 661941316 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 663478550 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 663493297 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 663497217 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 664600899 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 664605741 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 664608900 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 665717127 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 665721560 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 665724163 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 666835546 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 666838902 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 666842696 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 667951412 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 667953286 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 667954450 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 669225652 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 669227812 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 669229405 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 670300445 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 670302596 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 670303752 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 672104034 | 
| Thread delayed | Time: 0 TID: 1812 | success or wait | 672109536 | 
| Thread created | PID: 912 TID: 3620 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 759510412 | 
| Thread resumed | TID: 3620 PID: 912 Path: C:\WINDOWS\system32\svchost.exe | success or wait | 759527747 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | success or wait | 759530048 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 759532672 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 759632773 | 
| Sections | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| File Activities: 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Section Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Mutant Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Process Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Thread Activities: 
 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Memory Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Process information queried | PID: 1052 Info Class: ImageFileName | info length mismatch | 633315413 | 
| Process information queried | PID: 1052 Info Class: ImageFileName | success or wait | 633315712 | 
| Mutant created | Name: \BaseNamedObjects\zXeRY3a_PtW|00000000 | success or wait | 633317253 | 
| Thread created | PID: 996 TID: 2024 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 633324651 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633329318 | 
| Section loaded | Path: \KnownDlls\MSIMG32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 633331367 | 
| Section loaded | Path: C:\WINDOWS\system32\msimg32.dll Access: query and write and read and execute Type: image Baseaddress: 76380000 Size: 20480 Protection: read write Mapped to pid: own pid | success or wait | 633336378 | 
| Thread created | PID: 996 TID: 868 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 633819917 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and write copy | success or wait | 633822040 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 633824394 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633825180 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@153f920 | success or wait | 633826174 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 633826411 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@8e00d | success or wait | 633826757 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 633827414 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 633827695 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ada4af | success or wait | 633828233 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 633828466 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@170376 | success or wait | 633830182 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 2150000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633830494 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633839666 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BAFEA50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633842002 | 
| Thread created | PID: 996 TID: 1716 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 633848769 | 
| Thread created | PID: 996 TID: 1344 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 633855084 | 
| Process information queried | PID: 996 Info Class: Wow64Information | success or wait | 633856857 | 
| Process information queried | PID: 996 Info Class: Wow64Information | success or wait | 633857353 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 633857811 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 633858171 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633858342 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633859229 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@153f920 | success or wait | 633859985 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 633860220 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@8e00d | success or wait | 633860566 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 633860798 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 633861074 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ada4af | success or wait | 633861608 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 633861839 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@170376 | success or wait | 633862304 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 24B0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633862607 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633865018 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BB186C0 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633865285 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633865559 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633866526 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@153f920 | success or wait | 633867272 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 633867508 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@8e00d | success or wait | 633867853 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 633868084 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 633868359 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ada4af | success or wait | 633868894 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 633869125 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@170376 | success or wait | 633869591 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 24B0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633869895 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633872369 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BB06F28 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633872636 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633872910 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633873787 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@153f920 | success or wait | 633874629 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 633874865 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@8e00d | success or wait | 633875218 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 633875450 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 633875726 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ada4af | success or wait | 633876268 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 633876500 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@170376 | success or wait | 633876973 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 24B0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633877276 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633879743 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BB04B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633880009 | 
| Process information queried | PID: 996 Info Class: Wow64Information | success or wait | 633880459 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633880693 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633881572 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@153f920 | success or wait | 633882320 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 633882558 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@8e00d | success or wait | 633882909 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 633883141 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 633883417 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ada4af | success or wait | 633884028 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 633884260 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@170376 | success or wait | 633884737 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 24B0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633885040 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633887510 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BB17D98 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633887738 | 
| Section loaded | Path: \KnownDlls\nspr4.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 633889149 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 633891324 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 633892184 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633908411 | 
| File opened | Path: C:\WINDOWS\system32\USER32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633909335 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e46007 | success or wait | 633910104 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 4 Value: D8 00 00 00 | success or wait | 633910352 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@15c90f4 | success or wait | 633910915 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 1B A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 633911159 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 F4 05 00 00 E2 02 00 00 00 00 00 17 B2 00 00 00 10 00 00 00 B0 05 00 00 00 41 7E 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 10 09 00 00 04 00 00 76 FC 08 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 39 00 00 | success or wait | 633911446 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@3087f9 | success or wait | 633912000 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 83 F2 05 00 00 10 00 00 00 F4 05 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 80 11 00 00 00 10 06 00 00 0C 00 00 00 F8 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 88 A0 02 00 00 30 06 00 00 A2 02 00 | success or wait | 633912243 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@2efae4 | success or wait | 633912726 | 
| Section loaded | Path: C:\WINDOWS\system32\user32.dll Access: query and read Type: commit Baseaddress: 24B0000 Size: 57344 Protection: readonly Mapped to pid: own pid | success or wait | 633913038 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633915596 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BB03E40 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633915871 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633916183 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633917073 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@59aa86 | success or wait | 633917831 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 633918072 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ca677f | success or wait | 633918627 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 633918865 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 633919146 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@50d7c5 | success or wait | 633919693 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 633919930 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@185c6ac | success or wait | 633920409 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 24B0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633920717 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633923618 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BB189C8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633923880 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633924183 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633925087 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@59aa86 | success or wait | 633925843 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 633926084 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ca677f | success or wait | 633926442 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 633926680 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 633926961 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@50d7c5 | success or wait | 633927506 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 633927744 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@185c6ac | success or wait | 633928222 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 24B0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633928527 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633931425 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BB18118 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633931694 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633931999 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633932890 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@59aa86 | success or wait | 633933643 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 633933883 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ca677f | success or wait | 633934159 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 633934397 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 633934676 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@50d7c5 | success or wait | 633935225 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 633935462 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@185c6ac | success or wait | 633935940 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 24B0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633936247 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633939230 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BAFE1F8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633939490 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633940036 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633940937 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@59aa86 | success or wait | 633941693 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 633941932 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ca677f | success or wait | 633942289 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 633942527 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 633942808 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@50d7c5 | success or wait | 633943355 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 633943593 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@185c6ac | success or wait | 633944214 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 24B0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633944526 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633947421 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BB07290 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633947692 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 633948511 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 633949408 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633968287 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633969191 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@59aa86 | success or wait | 633969880 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 633970122 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ca677f | success or wait | 633970480 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 633970718 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 633971000 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@50d7c5 | success or wait | 633971548 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 633971785 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@185c6ac | success or wait | 633972266 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 24B0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633972573 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633975615 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BB07A10 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633975876 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633976155 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633977055 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@59aa86 | success or wait | 633977810 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 633978051 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ca677f | success or wait | 633978407 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 633978644 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 633978925 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@50d7c5 | success or wait | 633979470 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 633979707 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@185c6ac | success or wait | 633980185 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 24B0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633980495 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633983396 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BB18B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633983668 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633983945 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633984844 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@59aa86 | success or wait | 633985595 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 633985835 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ca677f | success or wait | 633986193 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 633986429 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 633986711 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@50d7c5 | success or wait | 633987257 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 633987494 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@185c6ac | success or wait | 633987974 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 24B0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633988279 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633991176 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BB05310 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633991446 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633991724 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 633992615 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@59aa86 | success or wait | 633993366 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 633993608 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ca677f | success or wait | 633993964 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 633994201 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 633994482 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@50d7c5 | success or wait | 633995028 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 633995265 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@185c6ac | success or wait | 633995743 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 24B0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 633996048 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633999022 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BB18ED8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 633999283 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 633999563 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 634000783 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@59aa86 | success or wait | 634001544 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 634001784 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ca677f | success or wait | 634002141 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 634002378 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 634002658 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@50d7c5 | success or wait | 634003204 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 634003441 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@185c6ac | success or wait | 634003920 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 24B0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 634004227 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 634007060 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BB04D50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 634007330 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 634007611 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 634008588 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@59aa86 | success or wait | 634009348 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 634009589 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ca677f | success or wait | 634009944 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 634010182 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 634010460 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@50d7c5 | success or wait | 634011007 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 634011244 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@185c6ac | success or wait | 634011723 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 24B0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 634012030 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 634014932 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BB05538 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 634015204 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 634015485 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 634016385 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@59aa86 | success or wait | 634017137 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 634017377 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ca677f | success or wait | 634017733 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 634017970 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 634018251 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@50d7c5 | success or wait | 634018799 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 634019036 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@185c6ac | success or wait | 634019516 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 24B0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 634019823 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 634022718 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: BAFE698 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 634022988 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 634023445 | 
| File opened | Path: c:\windows\system32\WS2_32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 634024351 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b664bb | success or wait | 634025108 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 634025348 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@18f57d2 | success or wait | 634025977 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 63 A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 634026215 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 22 01 00 00 1C 00 00 00 00 00 00 73 12 00 00 00 10 00 00 00 20 01 00 00 00 AB 71 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 70 01 00 00 04 00 00 20 F0 01 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 04 14 00 00 | success or wait | 634026498 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ceb670 | success or wait | 634027044 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 53 21 01 00 00 10 00 00 00 22 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 14 09 00 00 00 40 01 00 00 0A 00 00 00 26 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 F8 03 00 00 00 50 01 00 00 04 00 00 | success or wait | 634027282 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@2b7711 | success or wait | 634027761 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and read Type: commit Baseaddress: 24B0000 Size: 20480 Protection: readonly Mapped to pid: own pid | success or wait | 634028066 | 
| Memory attributes changed | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 634030319 | 
| File opened | Path: C:\WINDOWS\system32\ADVAPI32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 634031914 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@196076f | success or wait | 634032802 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 634033041 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c221d7 | success or wait | 634033667 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 48 1D 90 49 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 634033906 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 46 07 00 00 3E 02 00 00 00 00 00 0B 71 00 00 00 10 00 00 00 20 07 00 00 00 DD 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 B0 09 00 00 04 00 00 B8 5B 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 A4 16 00 00 | success or wait | 634034188 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13be416 | success or wait | 634034736 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C9 45 07 00 00 10 00 00 00 46 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 28 46 00 00 00 60 07 00 00 2C 00 00 00 4A 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 80 A9 01 00 00 B0 07 00 00 AA 01 00 | success or wait | 634034975 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@fb8e1e | success or wait | 634035452 | 
| Section loaded | Path: C:\WINDOWS\system32\advapi32.dll Access: query and read Type: commit Baseaddress: 24B0000 Size: 28672 Protection: readonly Mapped to pid: own pid | success or wait | 634035758 | 
| File opened | Path: c:\windows\system32\CRYPT32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 634040254 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12f8a71 | success or wait | 634041017 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 634041178 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@2a15d6 | success or wait | 634041806 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D7 A0 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 634042045 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 44 08 00 00 DC 00 00 00 00 00 00 32 16 00 00 00 10 00 00 00 20 08 00 00 00 A8 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 50 09 00 00 04 00 00 30 C5 09 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 9C 1A 00 00 | success or wait | 634042328 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ffce21 | success or wait | 634042874 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C4 43 08 00 00 10 00 00 00 44 08 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 E8 23 00 00 00 60 08 00 00 24 00 00 00 48 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 50 67 00 00 00 90 08 00 00 68 00 00 | success or wait | 634043112 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@360733 | success or wait | 634043589 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and read Type: commit Baseaddress: 24B0000 Size: 77824 Protection: readonly Mapped to pid: own pid | success or wait | 634043897 | 
| Mutant created | Name: \BaseNamedObjects\Global\ch971pGLCYGJFFTTU5XPPGQTZJ8OdYB | object name exists | 634047269 | 
| Thread created | PID: 996 TID: 524 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 634048867 | 
| Thread resumed | TID: 524 PID: 996 Path: C:\WINDOWS\system32\svchost.exe | success or wait | 634049785 | 
| Thread terminated | TID: 2024 PID: 996 Path: C:\WINDOWS\system32\svchost.exe | unknown | 634050420 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | success or wait | 634051375 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 634054662 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 634083047 | 
| Memory allocated | PID: 996 Path: C:\WINDOWS\system32\svchost.exe Base: 1A80000 Length: 24EFF30 Allocation Type: unknown Protection: page execute and read and write | success or wait | 634109427 | 
| Thread created | PID: 996 TID: 1580 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 634115673 | 
| Thread resumed | TID: 1580 PID: 996 Path: C:\WINDOWS\system32\svchost.exe | success or wait | 634116438 | 
| Process information queried | PID: 996 Info Class: Cookie | success or wait | 634117668 | 
| Process information queried | PID: 996 Info Class: Cookie | success or wait | 634117888 | 
| Thread created | PID: 996 TID: 2032 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 634120028 | 
| Thread resumed | TID: 2032 PID: 996 Path: C:\WINDOWS\system32\svchost.exe | success or wait | 634120720 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 634895289 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 634951425 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 634951878 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 636014578 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 636070087 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 636070541 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 637132630 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 637188754 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 637189261 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 638254098 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 638307321 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 638307821 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 639372832 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 639425911 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 639426459 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 640488408 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 640547608 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 640548110 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 641609846 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 641663146 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 641663648 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 642725593 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 642781747 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 642782251 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 643844238 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 643903057 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 643903559 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 644962822 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 645019736 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 645020247 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 646081413 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 646137558 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 646138058 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 647200064 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 647258896 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 647259398 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 648318628 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 648374798 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 648375299 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 649437271 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 649496173 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 649496670 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 651318294 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 651330915 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 651335695 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 652405050 | 
| Thread delayed | Time: 0 TID: 868 | success or wait | 652409215 | 
| Process information queried | PID: 1052 Info Class: ImageFileName | info length mismatch | 657033616 | 
| Process information queried | PID: 1052 Info Class: ImageFileName | success or wait | 657033942 | 
| Process information queried | PID: 1052 Info Class: ImageFileName | info length mismatch | 659981786 | 
| Process information queried | PID: 1052 Info Class: ImageFileName | success or wait | 659981902 | 
| Process information queried | PID: 2116 Info Class: SessionInformation | success or wait | 662608218 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 668016620 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 677743058 | 
| File other op | Path: \ROUTERNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@112ce69 | success or wait | 678033880 | 
| File other op | Path: \ROUTERNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@112ce69 | success or wait | 680055935 | 
| Process information queried | PID: 1052 Info Class: ImageFileName | info length mismatch | 680669019 | 
| Process information queried | PID: 1052 Info Class: ImageFileName | success or wait | 680669133 | 
| Process information queried | PID: 1052 Info Class: ImageFileName | info length mismatch | 685230643 | 
| Process information queried | PID: 1052 Info Class: ImageFileName | success or wait | 685230970 | 
| Process information queried | PID: 1052 Info Class: ImageFileName | info length mismatch | 688216941 | 
| Process information queried | PID: 1052 Info Class: ImageFileName | success or wait | 688217279 | 
| Section loaded | Path: C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf Access: query and read Type: commit Baseaddress: 1AA0000 Size: 57344 Protection: readonly Mapped to pid: own pid | success or wait | 694406510 | 
| Process information queried | PID: 1052 Info Class: ImageFileName | info length mismatch | 700066425 | 
| Process information queried | PID: 1052 Info Class: ImageFileName | success or wait | 700066755 | 
| Process information queried | PID: 1052 Info Class: ImageFileName | info length mismatch | 707356139 | 
| Process information queried | PID: 1052 Info Class: ImageFileName | success or wait | 707356254 | 
| Process information queried | PID: 1052 Info Class: ImageFileName | info length mismatch | 723357744 | 
| Process information queried | PID: 1052 Info Class: ImageFileName | success or wait | 723359659 | 
| Thread created | PID: 996 TID: 3456 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 741222880 | 
| Thread resumed | TID: 3456 PID: 996 Path: C:\WINDOWS\system32\svchost.exe | success or wait | 741237736 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | pipe not available | 741252593 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | success or wait | 741308372 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 741308806 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 741337877 | 
| Process information queried | PID: 1052 Info Class: ImageFileName | info length mismatch | 772468759 | 
| Process information queried | PID: 1052 Info Class: ImageFileName | success or wait | 772469090 | 
| Process information queried | PID: 1052 Info Class: ImageFileName | info length mismatch | 772563100 | 
| Process information queried | PID: 1052 Info Class: ImageFileName | success or wait | 772563428 | 
| Thread resumed | TID: 3968 PID: 996 Path: C:\WINDOWS\system32\svchost.exe | success or wait | 796100405 | 
| Sections | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| File Activities: 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Section Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Mutant Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Process Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Thread Activities: 
 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Memory Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Mutant created | Name: \BaseNamedObjects\zXeRY3a_PtW|00000000 | success or wait | 651703449 | 
| Thread created | PID: 1052 TID: 1088 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 651712380 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 651718905 | 
| Section loaded | Path: \KnownDlls\CRYPT32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 651724610 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and write and read and execute Type: image Baseaddress: 77A80000 Size: 610304 Protection: read write Mapped to pid: own pid | success or wait | 651728931 | 
| Section loaded | Path: \KnownDlls\MSASN1.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 651753985 | 
| Section loaded | Path: C:\WINDOWS\system32\msasn1.dll Access: query and write and read and execute Type: image Baseaddress: 77B20000 Size: 73728 Protection: read write Mapped to pid: own pid | success or wait | 651756949 | 
| Section loaded | Path: \KnownDlls\WININET.dll Access: write and read and execute Type: unknown Baseaddress: 3D930000 Size: 942080 Protection: read write Mapped to pid: own pid | success or wait | 651780472 | 
| Section loaded | Path: \KnownDlls\Normaliz.dll Access: write and read and execute Type: unknown Baseaddress: 8A0000 Size: 36864 Protection: read write Mapped to pid: own pid | conflicting addresses | 651849463 | 
| Section loaded | Path: \KnownDlls\urlmon.dll Access: write and read and execute Type: unknown Baseaddress: 78130000 Size: 1257472 Protection: read write Mapped to pid: own pid | success or wait | 651892717 | 
| Section loaded | Path: \KnownDlls\iertutil.dll Access: write and read and execute Type: unknown Baseaddress: 3DFD0000 Size: 2002944 Protection: read write Mapped to pid: own pid | success or wait | 651937267 | 
| Section loaded | Path: \KnownDlls\MSIMG32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 652176123 | 
| Section loaded | Path: C:\WINDOWS\system32\msimg32.dll Access: query and write and read and execute Type: image Baseaddress: 76380000 Size: 20480 Protection: read write Mapped to pid: own pid | success or wait | 652190651 | 
| Thread created | PID: 1052 TID: 2072 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 652232548 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 652237729 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and write copy | success or wait | 652238958 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652244035 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b2fd30 | success or wait | 652246124 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 652247214 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10c81a6 | success or wait | 652250851 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 652252150 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 652253226 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13f866 | success or wait | 652254768 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 652255648 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1192b0c | success or wait | 652257250 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 950000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652266539 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652277111 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BAFEA50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652278625 | 
| Thread created | PID: 1052 TID: 2076 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 652293389 | 
| Thread created | PID: 1052 TID: 2080 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 652303761 | 
| Process information queried | PID: 1052 Info Class: Wow64Information | success or wait | 652309276 | 
| Process information queried | PID: 1052 Info Class: Wow64Information | success or wait | 652309821 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 652310371 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 652310770 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652310960 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652311935 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b2fd30 | success or wait | 652312763 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 652332184 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10c81a6 | success or wait | 652333755 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 652335422 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 652336765 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13f866 | success or wait | 652339119 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 652340136 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1192b0c | success or wait | 652343986 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 9D0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652349260 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652364237 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BB186C0 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652367656 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652369413 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652378153 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b2fd30 | success or wait | 652379912 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 652382297 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10c81a6 | success or wait | 652384063 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 652385486 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 652388769 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13f866 | success or wait | 652391000 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 652392507 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1192b0c | success or wait | 652396947 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 9D0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652398102 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652423464 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BB06F28 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652426350 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652427652 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652456627 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b2fd30 | success or wait | 652459584 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 652461269 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10c81a6 | success or wait | 652462525 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 652465463 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 652467607 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13f866 | success or wait | 652472808 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 652474585 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1192b0c | success or wait | 652476851 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 9D0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652478094 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652493909 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BB04B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652494938 | 
| Process information queried | PID: 1052 Info Class: Wow64Information | success or wait | 652497135 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652522998 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652528830 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b2fd30 | success or wait | 652530865 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 652531949 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10c81a6 | success or wait | 652538925 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 652540432 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 652542135 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13f866 | success or wait | 652543893 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 652546704 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1192b0c | success or wait | 652551941 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 9D0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652553138 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652567541 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BB17D98 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652568318 | 
| Section loaded | Path: \KnownDlls\nspr4.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 652575240 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 652579176 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 652581313 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652615516 | 
| File opened | Path: C:\WINDOWS\system32\USER32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652620779 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@15960fd | success or wait | 652625081 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 4 Value: D8 00 00 00 | success or wait | 652627641 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@eec35c | success or wait | 652629985 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 1B A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 652631726 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 F4 05 00 00 E2 02 00 00 00 00 00 17 B2 00 00 00 10 00 00 00 B0 05 00 00 00 41 7E 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 10 09 00 00 04 00 00 76 FC 08 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 39 00 00 | success or wait | 652634075 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@15bf05f | success or wait | 652635646 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 83 F2 05 00 00 10 00 00 00 F4 05 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 80 11 00 00 00 10 06 00 00 0C 00 00 00 F8 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 88 A0 02 00 00 30 06 00 00 A2 02 00 | success or wait | 652636830 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@101f8f4 | success or wait | 652639377 | 
| Section loaded | Path: C:\WINDOWS\system32\user32.dll Access: query and read Type: commit Baseaddress: 9D0000 Size: 57344 Protection: readonly Mapped to pid: own pid | success or wait | 652641439 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652661409 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BB03E40 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652663422 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652664646 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652671589 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7f65f2 | success or wait | 652673247 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652675103 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1fe0dcb | success or wait | 652676904 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652677901 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652692541 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@3b96bb | success or wait | 652693468 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652700228 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24e39f | success or wait | 652706260 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9D0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652722556 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652737909 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BB189C8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652739404 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652744141 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652751371 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7f65f2 | success or wait | 652753349 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652756474 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1fe0dcb | success or wait | 652757963 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652759196 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652760630 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@3b96bb | success or wait | 652762741 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652764135 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24e39f | success or wait | 652768449 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9D0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652769847 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652784212 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BB18118 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652787291 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652788766 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652795109 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7f65f2 | success or wait | 652797558 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652800592 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1fe0dcb | success or wait | 652801898 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652803385 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652804795 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@3b96bb | success or wait | 652806511 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652807819 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24e39f | success or wait | 652810994 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9D0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652812484 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652826396 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BAFE1F8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652829445 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652831571 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652861473 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7f65f2 | success or wait | 652863583 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652865763 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1fe0dcb | success or wait | 652867244 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652868844 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652870563 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@3b96bb | success or wait | 652872379 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 652873380 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24e39f | success or wait | 652875993 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9D0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 652877173 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652892791 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BB07290 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 652895817 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 652897503 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 652906064 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 652970948 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 652977649 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7f65f2 | success or wait | 652979658 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 652980869 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1fe0dcb | success or wait | 652982910 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 652991936 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 652993472 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@3b96bb | success or wait | 652994431 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 653003812 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24e39f | success or wait | 653004760 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9D0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 653029490 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 653041142 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BB07A10 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 653042081 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 653043033 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 653046324 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7f65f2 | success or wait | 653049132 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 653049775 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1fe0dcb | success or wait | 653050672 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 653053018 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 653053615 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@3b96bb | success or wait | 653054555 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 653056581 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24e39f | success or wait | 653057486 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9D0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 653058160 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 653068382 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BB18B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 653070937 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 653115157 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 653124518 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7f65f2 | success or wait | 653128449 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 653129056 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1fe0dcb | success or wait | 653130840 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 653135613 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 653137125 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@3b96bb | success or wait | 653138058 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 653147028 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24e39f | success or wait | 653147918 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9D0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 653148592 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 654312408 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 654326236 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 654330000 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 654362249 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BB05310 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 654378790 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 654379845 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 654388035 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7f65f2 | success or wait | 654389252 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 654403900 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1fe0dcb | success or wait | 654405273 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 654405863 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 654411300 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@3b96bb | success or wait | 654413210 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 654413757 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24e39f | success or wait | 654421030 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9D0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 654424126 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 654437350 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BB18ED8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 654441986 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 654443286 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 654450705 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7f65f2 | success or wait | 654452714 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 654509961 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1fe0dcb | success or wait | 654511429 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 654512960 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 654518752 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@3b96bb | success or wait | 654520444 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 654521558 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24e39f | success or wait | 654523071 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9D0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 654524221 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 654543196 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BB04D50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 654545613 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 654547629 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 654574562 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7f65f2 | success or wait | 654576930 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 654594433 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1fe0dcb | success or wait | 654595415 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 654596208 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 654596922 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@3b96bb | success or wait | 654597936 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 654615400 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24e39f | success or wait | 654616379 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9D0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 654617373 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 654638519 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BB05538 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 654638811 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 654639170 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 654642134 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7f65f2 | success or wait | 654651110 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 654651808 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1fe0dcb | success or wait | 654653492 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 654654178 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 654655042 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@3b96bb | success or wait | 654656720 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 654659444 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@24e39f | success or wait | 654660682 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9D0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 654661326 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 654674507 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: BAFE698 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 654675520 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 654676525 | 
| File opened | Path: c:\windows\system32\WS2_32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 654679140 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1dc0d09 | success or wait | 654679984 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 654680249 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1dbd515 | success or wait | 654680950 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 63 A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 654684454 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 22 01 00 00 1C 00 00 00 00 00 00 73 12 00 00 00 10 00 00 00 20 01 00 00 00 AB 71 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 70 01 00 00 04 00 00 20 F0 01 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 04 14 00 00 | success or wait | 654685555 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1826710 | success or wait | 654686813 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 53 21 01 00 00 10 00 00 00 22 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 14 09 00 00 00 40 01 00 00 0A 00 00 00 26 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 F8 03 00 00 00 50 01 00 00 04 00 00 | success or wait | 654692292 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@3c8087 | success or wait | 654692829 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and read Type: commit Baseaddress: 9D0000 Size: 20480 Protection: readonly Mapped to pid: own pid | success or wait | 654693843 | 
| Memory attributes changed | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 654759618 | 
| File opened | Path: C:\WINDOWS\system32\ADVAPI32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 654770009 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a30a0 | success or wait | 654771670 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 654775111 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@16e7212 | success or wait | 654776297 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 48 1D 90 49 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 654777533 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 46 07 00 00 3E 02 00 00 00 00 00 0B 71 00 00 00 10 00 00 00 20 07 00 00 00 DD 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 B0 09 00 00 04 00 00 B8 5B 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 A4 16 00 00 | success or wait | 654779317 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@3278f | success or wait | 654780252 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C9 45 07 00 00 10 00 00 00 46 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 28 46 00 00 00 60 07 00 00 2C 00 00 00 4A 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 80 A9 01 00 00 B0 07 00 00 AA 01 00 | success or wait | 654781342 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11a4131 | success or wait | 654785682 | 
| Section loaded | Path: C:\WINDOWS\system32\advapi32.dll Access: query and read Type: commit Baseaddress: 9D0000 Size: 28672 Protection: readonly Mapped to pid: own pid | success or wait | 654787093 | 
| File opened | Path: C:\WINDOWS\system32\CRYPT32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 654796411 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ae3614 | success or wait | 654797262 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 654800201 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@16070f0 | success or wait | 654800602 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D7 A0 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 654800865 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 44 08 00 00 DC 00 00 00 00 00 00 32 16 00 00 00 10 00 00 00 20 08 00 00 00 A8 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 50 09 00 00 04 00 00 30 C5 09 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 9C 1A 00 00 | success or wait | 654801176 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@96a680 | success or wait | 654801778 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C4 43 08 00 00 10 00 00 00 44 08 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 E8 23 00 00 00 60 08 00 00 24 00 00 00 48 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 50 67 00 00 00 90 08 00 00 68 00 00 | success or wait | 654802040 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@8d2e37 | success or wait | 654806205 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and read Type: commit Baseaddress: 9D0000 Size: 77824 Protection: readonly Mapped to pid: own pid | success or wait | 654806566 | 
| Mutant created | Name: \BaseNamedObjects\Global\ch971pGLCYGJFFTTU5XPPGQTZJ8OdYB | object name exists | 654812893 | 
| Thread created | PID: 1052 TID: 2228 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 654816990 | 
| Thread resumed | TID: 2228 PID: 1052 Path: C:\WINDOWS\system32\svchost.exe | success or wait | 654817689 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | success or wait | 654818991 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 654820431 | 
| Thread terminated | TID: 1088 PID: 1052 Path: C:\WINDOWS\system32\svchost.exe | unknown | 654822318 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 654856168 | 
| Memory allocated | PID: 1052 Path: C:\WINDOWS\system32\svchost.exe Base: 860000 Length: A0FF30 Allocation Type: unknown Protection: page execute and read and write | success or wait | 654893073 | 
| Thread created | PID: 1052 TID: 2236 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 654895456 | 
| Thread resumed | TID: 2236 PID: 1052 Path: C:\WINDOWS\system32\svchost.exe | success or wait | 654899284 | 
| Process information queried | PID: 1052 Info Class: Cookie | success or wait | 654901545 | 
| Process information queried | PID: 1052 Info Class: Cookie | success or wait | 654902330 | 
| Thread created | PID: 1052 TID: 2240 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 654906684 | 
| Thread resumed | TID: 2240 PID: 1052 Path: C:\WINDOWS\system32\svchost.exe | success or wait | 654907376 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 655434913 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 655439090 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 655442875 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 656545514 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 656549007 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 656551938 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 658014869 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 658019145 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 658022487 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 659112959 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 659114011 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 659115553 | 
| Thread resumed | TID: 2652 PID: 1052 Path: C:\WINDOWS\system32\svchost.exe | success or wait | 659953336 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 660234619 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 660238449 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 660241809 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 661932397 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 661937265 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 661940657 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 663477694 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 663491667 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 663496551 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 664600014 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 664604331 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 664608164 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 665716404 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 665720357 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 665723560 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 666834101 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 666836717 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 666840630 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 667951090 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 667952765 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 667954183 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 669225332 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 669227335 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 669229104 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 670300125 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 670302060 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 670303485 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 672103236 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 672108313 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 672112091 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 673267379 | 
| Thread delayed | Time: 0 TID: 2072 | success or wait | 673302576 | 
| Thread created | PID: 1052 TID: 3644 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\svchost.exe | success or wait | 760656097 | 
| Thread resumed | TID: 3644 PID: 1052 Path: C:\WINDOWS\system32\svchost.exe | success or wait | 760656790 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | success or wait | 760658515 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 760661052 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 760690646 | 
| Thread resumed | TID: 3876 PID: 1052 Path: C:\WINDOWS\system32\svchost.exe | success or wait | 783735532 | 
| Sections | ||||||||||||||||||||
| 
 | ||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Sections | ||||||||||||||||||||
| 
 | ||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Sections | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| File Activities: 
 
 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Section Activities: 
 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Mutant Activities: 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Process Activities: 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Thread Activities: 
 
 
 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Memory Activities: 
 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| User Activities: 
 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Mutant created | Name: \BaseNamedObjects\zXeRY3a_PtW|00000000 | success or wait | 659498723 | 
| Thread created | PID: 1728 TID: 2628 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\ctfmon.exe | success or wait | 659504405 | 
| Section loaded | Path: \KnownDlls\CRYPT32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 659507094 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and write and read and execute Type: image Baseaddress: 77A80000 Size: 610304 Protection: read write Mapped to pid: own pid | success or wait | 659511188 | 
| Mutant created | Name: \BaseNamedObjects\zXeRY3a_PtW|00000000 | object name exists | 659516357 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 659516608 | 
| Section loaded | Path: \KnownDlls\MSASN1.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 659520578 | 
| Section loaded | Path: C:\WINDOWS\system32\msasn1.dll Access: query and write and read and execute Type: image Baseaddress: 77B20000 Size: 73728 Protection: read write Mapped to pid: own pid | success or wait | 659521116 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 659532298 | 
| Section loaded | Path: \KnownDlls\WS2_32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 659532608 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and write and read and execute Type: image Baseaddress: 71AB0000 Size: 94208 Protection: read write Mapped to pid: own pid | success or wait | 659533129 | 
| Section loaded | Path: \KnownDlls\WS2HELP.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 659539397 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2help.dll Access: query and write and read and execute Type: image Baseaddress: 71AA0000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 659539944 | 
| Section loaded | Path: \KnownDlls\WININET.dll Access: write and read and execute Type: unknown Baseaddress: 3D930000 Size: 942080 Protection: read write Mapped to pid: own pid | success or wait | 659547539 | 
| Section loaded | Path: \KnownDlls\Normaliz.dll Access: write and read and execute Type: unknown Baseaddress: A50000 Size: 36864 Protection: read write Mapped to pid: own pid | conflicting addresses | 659556058 | 
| Section loaded | Path: \KnownDlls\urlmon.dll Access: write and read and execute Type: unknown Baseaddress: 78130000 Size: 1257472 Protection: read write Mapped to pid: own pid | success or wait | 659566788 | 
| Section loaded | Path: \KnownDlls\iertutil.dll Access: write and read and execute Type: unknown Baseaddress: 3DFD0000 Size: 2002944 Protection: read write Mapped to pid: own pid | success or wait | 659576520 | 
| Section loaded | Path: \KnownDlls\MSIMG32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 659647757 | 
| Section loaded | Path: C:\WINDOWS\system32\msimg32.dll Access: query and write and read and execute Type: image Baseaddress: 76380000 Size: 20480 Protection: read write Mapped to pid: own pid | success or wait | 659648295 | 
| Thread created | PID: 1728 TID: 2636 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\ctfmon.exe | success or wait | 659654507 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 659655779 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and write copy | success or wait | 659656000 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 659656893 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@17ff60e | success or wait | 659657236 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 659657334 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f33aef | success or wait | 659657836 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 659658139 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 659658271 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a23566 | success or wait | 659658497 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 659658590 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5fe568 | success or wait | 659658841 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: B10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 659659697 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 659663960 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BAFEA50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 659664067 | 
| Thread created | PID: 1728 TID: 2640 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\ctfmon.exe | success or wait | 659667504 | 
| Thread created | PID: 1728 TID: 2644 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\ctfmon.exe | success or wait | 659668518 | 
| Process information queried | PID: 1728 Info Class: Wow64Information | success or wait | 659670475 | 
| Process information queried | PID: 1728 Info Class: Wow64Information | success or wait | 659670706 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 659670889 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 659671034 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 659671103 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 659671460 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@17ff60e | success or wait | 659673151 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 659673349 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f33aef | success or wait | 659674945 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 659675039 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 659675150 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a23566 | success or wait | 659675362 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 659675454 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5fe568 | success or wait | 659675654 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: B10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 659677492 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 659680545 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BB186C0 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 659680674 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 659682075 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 659682431 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@17ff60e | success or wait | 659682744 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 659682852 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f33aef | success or wait | 659684729 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 659684821 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 659684932 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a23566 | success or wait | 659685143 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 659685235 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5fe568 | success or wait | 659685435 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: B10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 659688198 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 659884437 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BB06F28 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 659886342 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 659888509 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 659888869 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@17ff60e | success or wait | 659889220 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 659889426 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f33aef | success or wait | 659891883 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 659892286 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 659894976 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a23566 | success or wait | 659897112 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 659897671 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5fe568 | success or wait | 659898875 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: B10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 659899019 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 659907216 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BB04B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 659907756 | 
| Process information queried | PID: 1728 Info Class: Wow64Information | success or wait | 659911877 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 659912029 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 659912376 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@17ff60e | success or wait | 659913444 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 659915582 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f33aef | success or wait | 659915729 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 659918143 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 659933266 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a23566 | success or wait | 659935366 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 659935461 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5fe568 | success or wait | 659936775 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: B10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 659937973 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 659950732 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BB17D98 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 659951447 | 
| Section loaded | Path: \KnownDlls\nspr4.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 659953429 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 659954346 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 659954885 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 659976870 | 
| File opened | Path: C:\WINDOWS\system32\USER32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 659978555 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ce487b | success or wait | 659979548 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 4 Value: D8 00 00 00 | success or wait | 659983017 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f897a7 | success or wait | 659983775 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 1B A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 659984355 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 F4 05 00 00 E2 02 00 00 00 00 00 17 B2 00 00 00 10 00 00 00 B0 05 00 00 00 41 7E 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 10 09 00 00 04 00 00 76 FC 08 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 39 00 00 | success or wait | 659988625 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ac8210 | success or wait | 659990320 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 83 F2 05 00 00 10 00 00 00 F4 05 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 80 11 00 00 00 10 06 00 00 0C 00 00 00 F8 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 88 A0 02 00 00 30 06 00 00 A2 02 00 | success or wait | 659991436 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@8ee94b | success or wait | 659992011 | 
| Section loaded | Path: C:\WINDOWS\system32\user32.dll Access: query and read Type: commit Baseaddress: B10000 Size: 57344 Protection: readonly Mapped to pid: own pid | success or wait | 659992631 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660000626 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BB03E40 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660004597 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 660006198 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 660007419 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@766e80 | success or wait | 660007727 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 660007819 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150c800 | success or wait | 660008065 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 660008281 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 660011101 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7a9fa7 | success or wait | 660011447 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 660012063 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@87c7a8 | success or wait | 660013672 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: B10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 660013980 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660017522 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BB189C8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660019774 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 660019913 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 660020257 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@766e80 | success or wait | 660020575 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 660023136 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150c800 | success or wait | 660023278 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 660023369 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 660023475 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7a9fa7 | success or wait | 660023685 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 660023808 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@87c7a8 | success or wait | 660026474 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: B10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 660026593 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660030556 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BB18118 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660030658 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 660030793 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 660033386 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@766e80 | success or wait | 660033693 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 660033786 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150c800 | success or wait | 660033923 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 660034052 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 660036430 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7a9fa7 | success or wait | 660036641 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 660036732 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@87c7a8 | success or wait | 660036915 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: B10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 660037033 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660040552 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BAFE1F8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660043087 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 660043645 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 660044002 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@766e80 | success or wait | 660044345 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 660046646 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150c800 | success or wait | 660046785 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 660046877 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 660046983 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7a9fa7 | success or wait | 660047193 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 660047317 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@87c7a8 | success or wait | 660049852 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: B10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 660049971 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660053565 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BB07290 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660053667 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 660053992 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 660054391 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 660065829 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 660066205 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@766e80 | success or wait | 660068235 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 660068328 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150c800 | success or wait | 660068508 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 660070285 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 660070395 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7a9fa7 | success or wait | 660070644 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 660072409 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@87c7a8 | success or wait | 660073544 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: B10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 660073992 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660087013 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BB07A10 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660087305 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 660087663 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 660088787 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@766e80 | success or wait | 660094631 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 660094896 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150c800 | success or wait | 660095290 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 660095551 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 660095861 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7a9fa7 | success or wait | 660096589 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 660101415 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@87c7a8 | success or wait | 660101952 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: B10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 660102291 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660111894 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BB18B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660112199 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 660113723 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 660114832 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@766e80 | success or wait | 660115682 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 660115949 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150c800 | success or wait | 660117535 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 660117805 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 660118117 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7a9fa7 | success or wait | 660118877 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 660122915 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@87c7a8 | success or wait | 660123454 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: B10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 660123795 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660134518 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BB05310 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660134821 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 660135275 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 660142841 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@766e80 | success or wait | 660144687 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 660144952 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150c800 | success or wait | 660145348 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 660145609 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 660145918 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7a9fa7 | success or wait | 660146630 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 660153367 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@87c7a8 | success or wait | 660153905 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: B10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 660154244 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660174271 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BB18ED8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660174565 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 660175013 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 660184027 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@766e80 | success or wait | 660184863 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 660185129 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150c800 | success or wait | 660185523 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 660185785 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 660187223 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7a9fa7 | success or wait | 660187836 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 660188097 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@87c7a8 | success or wait | 660194131 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: B10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 660194473 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660204154 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BB04D50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660204453 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 660204810 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 660211314 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@766e80 | success or wait | 660212162 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 660217263 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150c800 | success or wait | 660217665 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 660217927 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 660218237 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7a9fa7 | success or wait | 660218841 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 660219101 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@87c7a8 | success or wait | 660226374 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: B10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 660226715 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660249829 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BB05538 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660250123 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 660250483 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 660257396 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@766e80 | success or wait | 660258664 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 660259296 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@150c800 | success or wait | 660259696 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 660259958 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 660260283 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7a9fa7 | success or wait | 660260888 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 660261149 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@87c7a8 | success or wait | 660265343 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: B10000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 660269535 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660278604 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: BAFE698 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660278899 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 660279469 | 
| File opened | Path: C:\WINDOWS\system32\WS2_32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 660280462 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@450fe6 | success or wait | 660281319 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 660281669 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@16c634 | success or wait | 660282290 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 63 A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 660282552 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 22 01 00 00 1C 00 00 00 00 00 00 73 12 00 00 00 10 00 00 00 20 01 00 00 00 AB 71 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 70 01 00 00 04 00 00 20 F0 01 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 04 14 00 00 | success or wait | 660282863 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12e8204 | success or wait | 660283467 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 53 21 01 00 00 10 00 00 00 22 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 14 09 00 00 00 40 01 00 00 0A 00 00 00 26 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 F8 03 00 00 00 50 01 00 00 04 00 00 | success or wait | 660283728 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5a0faf | success or wait | 660284255 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and read Type: commit Baseaddress: B10000 Size: 20480 Protection: readonly Mapped to pid: own pid | success or wait | 660284592 | 
| Memory attributes changed | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 660286882 | 
| File opened | Path: C:\WINDOWS\system32\ADVAPI32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 660288985 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@bbe4cf | success or wait | 660289835 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 660290102 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ab0eef | success or wait | 660290715 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 48 1D 90 49 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 660290977 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 46 07 00 00 3E 02 00 00 00 00 00 0B 71 00 00 00 10 00 00 00 20 07 00 00 00 DD 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 B0 09 00 00 04 00 00 B8 5B 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 A4 16 00 00 | success or wait | 660291287 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1618248 | success or wait | 660291890 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C9 45 07 00 00 10 00 00 00 46 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 28 46 00 00 00 60 07 00 00 2C 00 00 00 4A 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 80 A9 01 00 00 B0 07 00 00 AA 01 00 | success or wait | 660292153 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b05409 | success or wait | 660292751 | 
| Section loaded | Path: C:\WINDOWS\system32\advapi32.dll Access: query and read Type: commit Baseaddress: B10000 Size: 28672 Protection: readonly Mapped to pid: own pid | success or wait | 660293090 | 
| File opened | Path: C:\WINDOWS\system32\CRYPT32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 660303977 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5d529e | success or wait | 660306114 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 660306388 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@db19d3 | success or wait | 660307006 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D7 A0 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 660318703 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 44 08 00 00 DC 00 00 00 00 00 00 32 16 00 00 00 10 00 00 00 20 08 00 00 00 A8 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 50 09 00 00 04 00 00 30 C5 09 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 9C 1A 00 00 | success or wait | 660322980 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7c7d85 | success or wait | 660323593 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C4 43 08 00 00 10 00 00 00 44 08 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 E8 23 00 00 00 60 08 00 00 24 00 00 00 48 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 50 67 00 00 00 90 08 00 00 68 00 00 | success or wait | 660324092 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@114d739 | success or wait | 660334922 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and read Type: commit Baseaddress: CB0000 Size: 77824 Protection: readonly Mapped to pid: own pid | success or wait | 660335267 | 
| Mutant created | Name: \BaseNamedObjects\Global\ch971pGLCYGJFFTTU5XPPGQTZJ8OdYB | object name exists | 660350832 | 
| Thread created | PID: 1728 TID: 2668 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\ctfmon.exe | success or wait | 660352545 | 
| Thread resumed | TID: 2668 PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe | success or wait | 660361038 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | success or wait | 660363340 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 660364488 | 
| Thread terminated | TID: 2628 PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe | unknown | 660364641 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 660370428 | 
| Memory allocated | PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe Base: B10000 Length: 14EFF30 Allocation Type: unknown Protection: page execute and read and write | success or wait | 660441528 | 
| Thread created | PID: 1728 TID: 2676 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\ctfmon.exe | success or wait | 660472989 | 
| Thread resumed | TID: 2676 PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe | success or wait | 660473702 | 
| Process information queried | PID: 1728 Info Class: Cookie | success or wait | 660475863 | 
| Process information queried | PID: 1728 Info Class: Cookie | success or wait | 660477176 | 
| Thread created | PID: 1728 TID: 2680 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\ctfmon.exe | success or wait | 660481965 | 
| Thread resumed | TID: 2680 PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe | success or wait | 660482673 | 
| Section loaded | Path: \BaseNamedObjects\CTF.AsmListCache.FMPDefaultS-1-5-21-507921405-1960408961-839522115-500 Access: query and write and read and execute and extend size Type: unknown Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 660623193 | 
| Section loaded | Path: \BaseNamedObjects\CTF.AsmListCache.FMPDefaultS-1-5-21-507921405-1960408961-839522115-500 Access: query and write and read and execute and extend size Type: unknown Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 660626616 | 
| Process information queried | PID: 1728 Info Class: DefaultHardErrorMode | success or wait | 660686616 | 
| Process information queried | PID: 1728 Info Class: DefaultHardErrorMode | success or wait | 660728966 | 
| Section loaded | Path: C:\WINDOWS\ime\sptip.dll Access: write and read and execute Type: commit Baseaddress: D60000 Size: 253952 Protection: execute Mapped to pid: own pid | success or wait | 660730485 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 660738102 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 660738515 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 660738930 | 
| Section loaded | Path: C:\WINDOWS\ime\sptip.dll Access: query and read Type: commit Baseaddress: D60000 Size: 253952 Protection: readonly Mapped to pid: own pid | success or wait | 660751209 | 
| Section loaded | Path: \BaseNamedObjects\CTF.AsmListCache.FMPDefaultS-1-5-21-507921405-1960408961-839522115-500 Access: query and write and read Type: commit Baseaddress: 3A0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 660870428 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 661935535 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 661939267 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 661941708 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 663478949 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 663494089 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 663497612 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 664601339 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 664606611 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 664609619 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 665717543 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 665722278 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 665724520 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 666836271 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 666840215 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 666844004 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 667951573 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 667953604 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 667954609 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 669225812 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 669228505 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 669229576 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 670300605 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 670302914 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 670303911 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 672104432 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 672110323 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 672113156 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 673268576 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 673304570 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 673308318 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 674386676 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 674391853 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 674394618 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 675505575 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 675511205 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 675514351 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 676724203 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 676726926 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 676728076 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI..IEKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677220706 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 854 HWNDs: 201C6, 201C8, 201C0, 201C4, 201CA, 14014E, 1F0150, 1E010E, 1C014C, 120118, 201CC, 301D0, D0100, 1200DC, E0146 | success or wait | 677247510 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 854 HWNDs: 201C6, 201C8, 201C0, 201C4, 201CA, 14014E, 1F0150, 1E010E, 1C014C, 120118, 201CC, 301D0, D0100, 1200DC, E0146 | success or wait | 677494281 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.B.FMKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677687490 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.C.FMKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677691171 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.D.FMKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677691825 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.E.FNKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677694565 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.F.FNKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677697714 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.G.FNKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677698168 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.H.FNKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677700833 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.I.FNKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677701393 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.J.FNKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677704627 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.K.FNKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677714278 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.L.FNKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677742595 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.M.EOKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677756894 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.N.EOKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677765087 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.O.EOKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677775177 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.P.EOKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677784445 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.AB.EOKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677791734 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 677795276 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 677797412 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 677798518 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.BB.EPKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677801678 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.CB.EPKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677806312 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.HC.EPKBFB Access: query and write and read Type: commit Baseaddress: C20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677809441 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.IC.EPKBFB Access: query and write and read Type: commit Baseaddress: CB0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677809879 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.JC.EPKBFB Access: query and write and read Type: commit Baseaddress: CC0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677810261 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.KC.EPKBFB Access: query and write and read Type: commit Baseaddress: CD0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677810641 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.LC.EPKBFB Access: query and write and read Type: commit Baseaddress: D60000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677811020 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.MC.EPKBFB Access: query and write and read Type: commit Baseaddress: D70000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677811397 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.NC.EPKBFB Access: query and write and read Type: commit Baseaddress: D80000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677811774 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.OC.EPKBFB Access: query and write and read Type: commit Baseaddress: D90000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677812152 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.PC.EPKBFB Access: query and write and read Type: commit Baseaddress: E60000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677812530 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: 854 HWNDs: 201C6, 201C8, 201C4, 201C0, 201CA, 14014E, 1F0150, 1E010E, 1C014C, 120118, 201CC, 301D0, D0100, 1200DC, E0146 | success or wait | 678224531 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 680019393 | 
| Thread delayed | Time: 0 TID: 2636 | success or wait | 680022141 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL..KHLEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 14B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 722273414 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: B94 HWNDs: 201D8, 40176, 901AA, 4017C, 30188, 7015C, 201B0, 201CE, 201D2, 201D4, 60156, 601DC, 1, 1200DC, E0146 | success or wait | 723228290 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.B.DKMEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 14B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723669475 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.C.DKMEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 14B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723681796 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.D.DKMEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 14B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723690062 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.E.DKMEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 14B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723703059 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.F.DKMEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 14B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723707905 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.G.DKMEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 14B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723711945 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.H.DKMEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 14B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723716637 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.I.BPMEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 14B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723717098 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.J.BPMEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 14B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723718779 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.K.ABNEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 14B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723721849 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.L.ABNEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 14B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723752461 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.M.ABNEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 14B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723762735 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.N.ACNEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 14B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723772253 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.O.ACNEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 14B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723779493 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.P.ACNEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 14B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723791935 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.AB.ACNEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 14B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723801807 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.BB.ACNEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 14B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723809415 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.CB.ACNEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 14B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723818163 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.AD.ACNEFB Access: query and write and read Type: commit Baseaddress: 14B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723823076 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.BD.PCNEFB Access: query and write and read Type: commit Baseaddress: 14C0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723825061 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.CD.PCNEFB Access: query and write and read Type: commit Baseaddress: 14D0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723825443 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.DD.PCNEFB Access: query and write and read Type: commit Baseaddress: 14E0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723825810 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.ED.PCNEFB Access: query and write and read Type: commit Baseaddress: 1530000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723827752 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.FD.PCNEFB Access: query and write and read Type: commit Baseaddress: 1540000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723830735 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.GD.PCNEFB Access: query and write and read Type: commit Baseaddress: 1550000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723831110 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.HD.PCNEFB Access: query and write and read Type: commit Baseaddress: 1560000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723834397 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.ID.PCNEFB Access: query and write and read Type: commit Baseaddress: 1570000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723834775 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.Shared.SFM.EFI Access: query and write and read and execute and extend size Type: unknown Baseaddress: 1580000 Size: 524288 Protection: read write Mapped to pid: own pid | success or wait | 724141214 | 
| Windows enumerated | Desktop: 0 Parent: 0 Enum Children: false TID: B94 HWNDs: 201D8, 40176, 901AA, 201CE, 4017C, 30188, 7015C, 201B0, 201D2, 201D4, 60156, 601DC, 1, 1200DC, E0146 | success or wait | 724159131 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.Shared.SFM.EJL Access: query and write and read and execute and extend size Type: unknown Baseaddress: EF0000 Size: 524288 Protection: read write Mapped to pid: own pid | success or wait | 737420622 | 
| Thread created | PID: 1728 TID: 3756 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\ctfmon.exe | success or wait | 767340408 | 
| Thread resumed | TID: 3756 PID: 1728 Path: C:\WINDOWS\system32\ctfmon.exe | success or wait | 767356542 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | success or wait | 767359345 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 767361930 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 767393317 | 
| Sections | ||||||||||||||||||||
| 
 | ||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Sections | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| File Activities: 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Section Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Mutant Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Process Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Thread Activities: 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Memory Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Section loaded | Path: \KnownDlls\WININET.dll Access: write and read and execute Type: unknown Baseaddress: 3D930000 Size: 942080 Protection: read write Mapped to pid: own pid | success or wait | 677029736 | 
| Section loaded | Path: \KnownDlls\Normaliz.dll Access: write and read and execute Type: unknown Baseaddress: 10B0000 Size: 36864 Protection: read write Mapped to pid: own pid | conflicting addresses | 677120253 | 
| Section loaded | Path: \KnownDlls\urlmon.dll Access: write and read and execute Type: unknown Baseaddress: 78130000 Size: 1257472 Protection: read write Mapped to pid: own pid | success or wait | 677527679 | 
| Section loaded | Path: \KnownDlls\iertutil.dll Access: write and read and execute Type: unknown Baseaddress: 3DFD0000 Size: 2002944 Protection: read write Mapped to pid: own pid | success or wait | 677827657 | 
| Section loaded | Path: \KnownDlls\MSIMG32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 680689240 | 
| Section loaded | Path: C:\WINDOWS\system32\msimg32.dll Access: query and write and read and execute Type: image Baseaddress: 76380000 Size: 20480 Protection: read write Mapped to pid: own pid | success or wait | 680691266 | 
| Thread created | PID: 400 TID: 3696 EIP: 7C8106F9 Imagepath: C:\Program Files\Java\jre6\bin\jqs.exe | success or wait | 680697889 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 680698703 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and write copy | success or wait | 680698913 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 680699261 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@bed64 | success or wait | 680699559 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 680699650 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10e6c5e | success or wait | 680700489 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 680700579 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 680700688 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1eca460 | success or wait | 680700893 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 680700981 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11bd50e | success or wait | 680701294 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 10E0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 680701413 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680705380 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BAFEA50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680705484 | 
| Thread created | PID: 400 TID: 3700 EIP: 7C8106F9 Imagepath: C:\Program Files\Java\jre6\bin\jqs.exe | success or wait | 680706032 | 
| Thread created | PID: 400 TID: 3704 EIP: 7C8106F9 Imagepath: C:\Program Files\Java\jre6\bin\jqs.exe | success or wait | 680707052 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 680707825 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 680708016 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 680708209 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 680708347 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680708413 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 680708759 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@bed64 | success or wait | 680709078 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 680709176 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10e6c5e | success or wait | 680709322 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 680709410 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 680709516 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1eca460 | success or wait | 680709720 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 680709808 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11bd50e | success or wait | 680709987 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 10E0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 680710103 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680711068 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BB186C0 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680711170 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680711275 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 680711613 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@bed64 | success or wait | 680711908 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 680711998 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10e6c5e | success or wait | 680712131 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 680712220 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 680712325 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1eca460 | success or wait | 680712530 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 680712618 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11bd50e | success or wait | 680712797 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 10E0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 680712913 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680713864 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BB06F28 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680713966 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680714072 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 680714408 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@bed64 | success or wait | 680714702 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 680714792 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10e6c5e | success or wait | 680714928 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 680715016 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 680715122 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1eca460 | success or wait | 680715329 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 680715418 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11bd50e | success or wait | 680715599 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 10E0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 680715715 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680716666 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BB04B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680716768 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 680716938 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680717028 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 680717366 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@bed64 | success or wait | 680717662 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 680717752 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10e6c5e | success or wait | 680717887 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 680717976 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 680718081 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1eca460 | success or wait | 680718289 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 680718377 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11bd50e | success or wait | 680718573 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 10E0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 680718953 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680719951 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BB17D98 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680720053 | 
| Section loaded | Path: \KnownDlls\nspr4.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 680720718 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 680721587 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 680722085 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 680729109 | 
| File opened | Path: C:\WINDOWS\system32\USER32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 680729473 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@40bf04 | success or wait | 680729781 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 4 Value: D8 00 00 00 | success or wait | 680729876 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@bccad2 | success or wait | 680730721 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 1B A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 680730815 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 F4 05 00 00 E2 02 00 00 00 00 00 17 B2 00 00 00 10 00 00 00 B0 05 00 00 00 41 7E 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 10 09 00 00 04 00 00 76 FC 08 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 39 00 00 | success or wait | 680730925 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@a7d5af | success or wait | 680731137 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 83 F2 05 00 00 10 00 00 00 F4 05 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 80 11 00 00 00 10 06 00 00 0C 00 00 00 F8 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 88 A0 02 00 00 30 06 00 00 A2 02 00 | success or wait | 680731229 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@be0ffe | success or wait | 680731416 | 
| Section loaded | Path: C:\WINDOWS\system32\user32.dll Access: query and read Type: commit Baseaddress: 10E0000 Size: 57344 Protection: readonly Mapped to pid: own pid | success or wait | 680731536 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680733787 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BB03E40 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680733895 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 680734033 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 680734388 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c08c5 | success or wait | 680734693 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 680734785 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13fb15 | success or wait | 680735543 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 680735634 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 680735742 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1c94ff3 | success or wait | 680735952 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 680736042 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a014e1 | success or wait | 680736226 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 10E0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 680736343 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680738752 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BB189C8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680738853 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 680738987 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 680739341 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c08c5 | success or wait | 680739644 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 680739736 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13fb15 | success or wait | 680739874 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 680739964 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 680740072 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1c94ff3 | success or wait | 680740281 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 680740371 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a014e1 | success or wait | 680740555 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 10E0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 680740672 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680742441 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BB18118 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680742542 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 680742676 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 680743028 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c08c5 | success or wait | 680743329 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 680743421 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13fb15 | success or wait | 680743558 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 680743648 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 680743755 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1c94ff3 | success or wait | 680743965 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 680744055 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a014e1 | success or wait | 680744239 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 10E0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 680744357 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680745696 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BAFE1F8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680745800 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 680746255 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 680746631 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c08c5 | success or wait | 680746932 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 680747024 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13fb15 | success or wait | 680747161 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 680747252 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 680747359 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1c94ff3 | success or wait | 680747568 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 680747658 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a014e1 | success or wait | 680747842 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 10E0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 680747960 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680749686 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BB07290 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680749787 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 680750110 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 680750465 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 680758101 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 680758459 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c08c5 | success or wait | 680758764 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 680758856 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13fb15 | success or wait | 680758993 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 680759084 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 680759191 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1c94ff3 | success or wait | 680759401 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 680759491 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a014e1 | success or wait | 680759675 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 10E0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 680759793 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680760919 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BB07A10 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680761020 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 680761144 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 680761498 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c08c5 | success or wait | 680761797 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 680761889 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13fb15 | success or wait | 680762026 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 680762116 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 680762224 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1c94ff3 | success or wait | 680762433 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 680762524 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a014e1 | success or wait | 680762708 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 10E0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 680762825 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680763948 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BB18B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680764052 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 680764176 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 680764528 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c08c5 | success or wait | 680764827 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 680764919 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13fb15 | success or wait | 680765056 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 680765147 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 680765254 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1c94ff3 | success or wait | 680765464 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 680765554 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a014e1 | success or wait | 680765738 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 10E0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 680765855 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680767624 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BB05310 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680767727 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 680767852 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 680768204 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c08c5 | success or wait | 680768505 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 680768597 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13fb15 | success or wait | 680768735 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 680768825 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 680768933 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1c94ff3 | success or wait | 680769143 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 680769233 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a014e1 | success or wait | 680769417 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 10E0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 680769535 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680771350 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BB18ED8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680771450 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 680771574 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 680771928 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c08c5 | success or wait | 680772229 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 680772321 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13fb15 | success or wait | 680772459 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 680772549 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 680772657 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1c94ff3 | success or wait | 680772866 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 680772957 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a014e1 | success or wait | 680773141 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 10E0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 680773258 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680774398 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BB04D50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680774502 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 680774627 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 680774976 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c08c5 | success or wait | 680775275 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 680775367 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13fb15 | success or wait | 680775505 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 680775595 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 680775703 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1c94ff3 | success or wait | 680775913 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 680776003 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a014e1 | success or wait | 680776187 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 10E0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 680776305 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680777425 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BB05538 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680777526 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 680777650 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 680777999 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c08c5 | success or wait | 680778298 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 680778390 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13fb15 | success or wait | 680778528 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 680778619 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 680778726 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1c94ff3 | success or wait | 680778936 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 680779027 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a014e1 | success or wait | 680779211 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 10E0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 680779329 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680780480 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BAFE698 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680780580 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 680780719 | 
| File opened | Path: C:\WINDOWS\system32\WS2_32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 680781064 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@baecb8 | success or wait | 680781363 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 680781456 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b4c69 | success or wait | 680782355 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 63 A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 680782447 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 22 01 00 00 1C 00 00 00 00 00 00 73 12 00 00 00 10 00 00 00 20 01 00 00 00 AB 71 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 70 01 00 00 04 00 00 20 F0 01 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 04 14 00 00 | success or wait | 680782555 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1c5ab93 | success or wait | 680782764 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 53 21 01 00 00 10 00 00 00 22 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 14 09 00 00 00 40 01 00 00 0A 00 00 00 26 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 F8 03 00 00 00 50 01 00 00 04 00 00 | success or wait | 680782854 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@837311 | success or wait | 680783038 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and read Type: commit Baseaddress: 10E0000 Size: 20480 Protection: readonly Mapped to pid: own pid | success or wait | 680783156 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680785411 | 
| Memory attributes changed | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: BB18D30 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 680785538 | 
| File opened | Path: C:\WINDOWS\system32\ADVAPI32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 680786049 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f78541 | success or wait | 680786355 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 680786448 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@14d9f9f | success or wait | 680787272 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 48 1D 90 49 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 680787365 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 46 07 00 00 3E 02 00 00 00 00 00 0B 71 00 00 00 10 00 00 00 20 07 00 00 00 DD 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 B0 09 00 00 04 00 00 B8 5B 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 A4 16 00 00 | success or wait | 680787473 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12abadc | success or wait | 680787683 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C9 45 07 00 00 10 00 00 00 46 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 28 46 00 00 00 60 07 00 00 2C 00 00 00 4A 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 80 A9 01 00 00 B0 07 00 00 AA 01 00 | success or wait | 680787773 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@51f982 | success or wait | 680787957 | 
| Section loaded | Path: C:\WINDOWS\system32\advapi32.dll Access: query and read Type: commit Baseaddress: 10E0000 Size: 28672 Protection: readonly Mapped to pid: own pid | success or wait | 680788075 | 
| File opened | Path: C:\WINDOWS\system32\CRYPT32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 680791530 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1d3ce2c | success or wait | 680791836 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 680791928 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@84e723 | success or wait | 680792751 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D7 A0 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 680792842 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 44 08 00 00 DC 00 00 00 00 00 00 32 16 00 00 00 10 00 00 00 20 08 00 00 00 A8 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 50 09 00 00 04 00 00 30 C5 09 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 9C 1A 00 00 | success or wait | 680792950 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@162bd90 | success or wait | 680793159 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C4 43 08 00 00 10 00 00 00 44 08 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 E8 23 00 00 00 60 08 00 00 24 00 00 00 48 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 50 67 00 00 00 90 08 00 00 68 00 00 | success or wait | 680793280 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@18b41da | success or wait | 680793466 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and read Type: commit Baseaddress: 10E0000 Size: 77824 Protection: readonly Mapped to pid: own pid | success or wait | 680793584 | 
| Mutant created | Name: \BaseNamedObjects\Global\ch971pGLCYGJFFTTU5XPPGQTZJ8OdYB | object name exists | 680796145 | 
| Thread created | PID: 400 TID: 3708 EIP: 7C8106F9 Imagepath: C:\Program Files\Java\jre6\bin\jqs.exe | success or wait | 680796746 | 
| Thread resumed | TID: 3708 PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe | success or wait | 680797004 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | success or wait | 680797427 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 680808812 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 680808985 | 
| Memory allocated | PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe Base: 10E0000 Length: 17AFF30 Allocation Type: unknown Protection: page execute and read and write | success or wait | 680820808 | 
| Thread created | PID: 400 TID: 3716 EIP: 7C8106F9 Imagepath: C:\Program Files\Java\jre6\bin\jqs.exe | success or wait | 680821471 | 
| Thread resumed | TID: 3716 PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe | success or wait | 680821718 | 
| Process information queried | PID: 400 Info Class: Cookie | success or wait | 680822130 | 
| Process information queried | PID: 400 Info Class: Cookie | success or wait | 681037057 | 
| Thread created | PID: 400 TID: 3732 EIP: 7C8106F9 Imagepath: C:\Program Files\Java\jre6\bin\jqs.exe | success or wait | 681069668 | 
| Thread resumed | TID: 3732 PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe | success or wait | 681069930 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 681765051 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 681824126 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 681824622 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 682883656 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 682939866 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 682940365 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 684002280 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 684058393 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 684058894 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 685120684 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 685179389 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 685179883 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 686239489 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 686295633 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 686296131 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 687358142 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 687414259 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 687414759 | 
| File opened | Path: C:\Program Files\Java\jre6\bin\client\classes.jsa Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 688179871 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\client\classes.jsa Access: query and read Type: commit Baseaddress: 18B0000 Size: 13369344 Protection: readonly Mapped to pid: own pid | success or wait | 688180771 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 688182292 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 688184102 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 688194590 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 688292005 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 688292492 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 688318440 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 688318926 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 688477211 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 688532431 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 688532932 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 689268761 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 689270742 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 689279975 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 689305129 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 689305599 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 689337174 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 689337642 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\content-types.properties Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 689366828 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\content-types.propertiesNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1df2ecc | success or wait | 689368828 | 
| File read | Path: C:\Program Files\Java\jre6\lib\content-types.properties Offset: unknown Length: 5501 Value: 23 73 75 6E 2E 6E 65 74 2E 77 77 77 20 4D 49 4D 45 20 63 6F 6E 74 65 6E 74 2D 74 79 70 65 73 20 74 61 62 6C 65 3B 20 76 65 72 73 69 6F 6E 20 25 49 25 2C 20 25 47 25 0A 23 0A 23 20 50 72 6F 70 65 72 74 79 20 66 69 65 6C 64 73 3A 0A 23 0A 23 20 20 20 3C 64 65 73 63 72 69 70 74 69 6F 6E 3E 20 3A 3A 3D | success or wait | 689369101 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\deploy.jar Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 689382010 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\deploy.jarNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@179688d | success or wait | 689383642 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 4096 Value: 50 4B 03 04 0A 00 00 00 00 00 2A 99 42 3E 00 00 00 00 00 00 00 00 00 00 00 00 09 00 00 00 4D 45 54 41 2D 49 4E 46 2F 50 4B 03 04 0A 00 00 00 00 00 2A 99 42 3E 6F 39 92 05 47 00 00 00 47 00 00 00 14 00 00 00 4D 45 54 41 2D 49 4E 46 2F 4D 41 4E 49 46 45 53 54 2E 4D 46 4D 61 6E 69 66 65 73 74 2D 56 65 | success or wait | 689383910 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\deploy.jarNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1bf404f | success or wait | 689395360 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 65536 Value: 00 10 6A 61 76 61 2F 6C 61 6E 67 2F 53 74 72 69 6E 67 01 00 16 6A 61 76 61 2F 6C 61 6E 67 2F 53 74 72 69 6E 67 42 75 66 66 65 72 01 00 10 6A 61 76 61 2F 6C 61 6E 67 2F 53 79 73 74 65 6D 01 00 0C 6A 61 76 61 2F 6E 65 74 2F 55 52 4C 01 00 06 6C 65 6E 67 74 68 01 00 0A 6F 70 65 6E 53 74 72 65 61 6D 01 | success or wait | 689395625 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 65536 Value: 72 73 52 65 71 07 00 07 07 00 09 07 00 0A 07 00 0B 07 00 11 07 00 12 07 00 13 07 00 14 07 00 15 07 00 16 07 00 17 07 00 18 01 00 26 4C 63 6F 6D 2F 73 75 6E 2F 64 65 70 6C 6F 79 2F 63 61 63 68 65 2F 43 61 63 68 65 64 4A 61 72 46 69 6C 65 31 34 3B 01 00 20 4C 63 6F 6D 2F 73 75 6E 2F 64 65 70 6C 6F 79 | success or wait | 689488745 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 65536 Value: BE A2 00 5E 01 3A 09 01 3A 0A 2B 15 08 32 C1 02 D7 99 00 0C 2B 15 08 32 C0 02 D7 3A 09 15 08 04 60 2B BE A2 00 1D 2B 15 08 04 60 32 C1 02 D7 99 00 11 2B 15 08 04 60 32 C0 02 D7 3A 0A A7 00 07 19 09 3A 0A 19 07 19 09 B6 05 D8 57 19 09 19 0A B8 05 2B 9A 00 06 A7 00 09 84 08 01 A7 FF A1 15 08 2B BE A2 | success or wait | 689564685 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 689667461 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 689669459 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 689670412 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 65536 Value: 2E 73 65 63 75 72 69 74 79 2E 76 61 6C 69 64 61 74 69 6F 6E 2E 63 72 6C 2E 75 72 6C 01 00 23 64 65 70 6C 6F 79 6D 65 6E 74 2E 73 65 63 75 72 69 74 79 2E 76 61 6C 69 64 61 74 69 6F 6E 2E 6F 63 73 70 01 00 2D 64 65 70 6C 6F 79 6D 65 6E 74 2E 73 65 63 75 72 69 74 79 2E 76 61 6C 69 64 61 74 69 6F 6E 2E | success or wait | 689670752 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 65536 Value: 0A 00 5C 00 89 0A 00 5C 00 8F 0A 00 5C 00 94 0B 00 56 00 7E 0B 00 56 00 86 0B 00 59 00 87 0B 00 59 00 90 0B 00 5A 00 7F 0B 00 5A 00 85 01 00 04 43 6F 64 65 01 00 0A 45 78 63 65 70 74 69 6F 6E 73 01 00 0C 49 6E 6E 65 72 43 6C 61 73 73 65 73 01 00 08 4A 61 72 46 69 6C 65 32 00 20 00 4C 00 52 00 00 00 | success or wait | 689770114 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 65536 Value: 50 5F 4D 49 4D 45 5F 54 59 50 45 01 00 1E 4C 6F 6F 6B 69 6E 67 20 75 70 20 6E 61 74 69 76 65 20 6C 69 62 72 61 72 79 20 69 6E 3A 20 01 00 12 4E 41 54 49 56 45 5F 43 4F 4E 54 45 4E 54 5F 42 49 54 01 00 07 4E 45 54 57 4F 52 4B 01 00 12 4E 4F 52 4D 41 4C 5F 43 4F 4E 54 45 4E 54 5F 42 49 54 01 00 44 4E | success or wait | 689852208 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 690769694 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 690770136 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 690770548 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 65536 Value: 2B C7 00 05 01 B0 2B B6 01 28 4E 2D 12 10 B6 01 1A 99 00 70 2B B6 01 29 3A 04 19 04 10 2F B6 01 19 36 05 15 05 02 A0 00 1E BB 00 94 59 BB 00 A2 59 B7 01 1F 12 08 B6 01 23 2B B6 01 22 B6 01 20 B7 01 05 BF 19 04 84 05 01 15 05 B6 01 18 10 2F A0 00 06 A7 FF F1 BB 00 A7 59 BB 00 A2 59 B7 01 1F 12 11 B6 | success or wait | 690929695 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 36864 Value: 6E 67 2F 53 74 72 69 6E 67 3B 29 5A 01 00 18 28 4C 6A 61 76 61 2F 6C 61 6E 67 2F 54 68 72 6F 77 61 62 6C 65 3B 29 56 01 00 3E 28 4C 6A 61 76 61 2F 69 6F 2F 46 69 6C 65 3B 4C 63 6F 6D 2F 73 75 6E 2F 64 65 70 6C 6F 79 2F 6E 65 74 2F 70 72 6F 78 79 2F 42 72 6F 77 73 65 72 50 72 6F 78 79 49 6E 66 6F 3B | success or wait | 691156868 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\deploy.jarNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11733a5 | success or wait | 691213121 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 4096 Value: 61 6E 67 2F 43 6C 61 73 73 3B 01 00 15 4C 6A 61 76 61 78 2F 73 77 69 6E 67 2F 4A 42 75 74 74 6F 6E 3B 01 00 18 4C 6A 61 76 61 78 2F 73 77 69 6E 67 2F 4A 43 6F 6D 70 6F 6E 65 6E 74 3B 01 00 14 4C 6A 61 76 61 78 2F 73 77 69 6E 67 2F 4A 4C 61 62 65 6C 3B 01 00 14 4C 6A 61 76 61 78 2F 73 77 69 6E 67 2F | success or wait | 691213387 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\deploy.jarNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@3f983f | success or wait | 691222040 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 65536 Value: 77 69 6E 67 2F 4A 42 75 74 74 6F 6E 3B 01 00 14 4C 6A 61 76 61 78 2F 73 77 69 6E 67 2F 4A 50 61 6E 65 6C 3B 01 00 18 4C 6A 61 76 61 78 2F 73 77 69 6E 67 2F 4A 54 65 78 74 46 69 65 6C 64 3B 01 00 2A 4C 6A 61 76 61 78 2F 73 77 69 6E 67 2F 74 72 65 65 2F 44 65 66 61 75 6C 74 54 72 65 65 43 65 6C 6C 52 | success or wait | 691222309 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 65536 Value: 00 26 46 69 6E 64 20 74 68 65 20 76 61 6C 69 64 20 72 6F 6F 74 20 43 41 20 69 6E 20 63 61 63 65 72 74 73 20 66 69 6C 65 01 00 17 46 69 6E 64 69 6E 67 20 69 6E 66 6F 72 6D 61 74 69 6F 6E 20 2E 2E 2E 01 00 06 46 69 6E 69 73 68 01 00 58 46 6F 72 20 6D 6F 72 65 20 69 6E 66 6F 72 6D 61 74 69 6F 6E 20 61 | success or wait | 691307746 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 4096 Value: 72 69 74 79 2E 70 6F 6C 69 63 69 65 73 2E 61 64 76 61 6E 63 65 64 2E 74 65 78 74 01 00 1D 73 65 63 75 72 69 74 79 2E 70 6F 6C 69 63 69 65 73 2E 62 6F 72 64 65 72 2E 74 65 78 74 01 00 1B 73 65 63 75 72 69 74 79 2E 70 6F 6C 69 63 69 65 73 2E 64 65 73 63 2E 74 65 78 74 01 00 1F 73 65 63 75 72 69 74 79 | success or wait | 691391248 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\deploy.jarNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1246bec | success or wait | 691393666 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 4096 Value: 67 68 74 20 28 63 29 20 32 30 31 31 20 4F 72 61 63 6C 65 20 61 6E 64 2F 6F 72 20 69 74 73 20 61 66 66 69 6C 69 61 74 65 73 2E 2E 01 00 06 46 54 50 EF BC 9A 01 00 07 48 54 54 50 EF BC 9A 01 00 31 4A 4E 4C 50 20 E6 AA 94 E4 B8 AD E7 9A 84 20 4A 41 52 20 E8 B3 87 E6 BA 90 E6 9C AA E4 BB A5 E7 9B B8 E5 | success or wait | 691394020 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\deploy.jarNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@2957a4 | success or wait | 691404122 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 20480 Value: 03 13 0D 41 53 59 04 13 0A F8 53 53 59 11 03 BD 05 BD 13 89 59 03 13 0D 1D 53 59 04 13 10 BD 53 53 59 11 03 BE 05 BD 13 89 59 03 13 0D 1E 53 59 04 13 0A F7 53 53 59 11 03 BF 05 BD 13 89 59 03 13 0C FB 53 59 04 13 12 9E 53 53 59 11 03 C0 05 BD 13 89 59 03 13 0C FC 53 59 04 13 13 7C 53 53 59 11 03 C1 | success or wait | 691404422 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\deploy.jarNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@38ebc3 | success or wait | 691435757 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 45056 Value: 58 1A 26 C7 16 63 E5 58 35 56 8F 35 63 1D 58 37 76 15 1B C0 9E 61 EF 08 24 02 8B 80 13 EC 08 5E 84 10 C2 6C 82 90 90 47 58 4C 58 43 A8 25 EC 23 B4 12 BA 08 57 09 83 84 31 C2 27 22 93 A8 4F B4 25 7A 12 F9 C4 78 62 3A B1 90 58 46 AC 26 EE 21 1E 21 9E 25 5E 27 0E 13 5F 93 48 24 0E C9 92 E4 4E 0A 21 25 | success or wait | 691436023 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\deploy.jarNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@fe7a67 | success or wait | 691507243 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 12288 Value: 25 00 00 80 83 00 00 F9 FF 00 00 80 E9 00 00 75 30 00 00 EA 60 00 00 3A 98 00 00 17 6F 92 5F C5 46 00 00 03 2F 49 44 41 54 78 DA B4 96 CF 6F 54 55 14 C7 3F 77 66 1C 4B DB 97 0E AD A5 B5 2D 0D 35 64 42 C4 95 09 2B 57 2E 31 46 5D 74 6F 58 D6 84 BF C0 B8 32 2C 65 21 46 96 98 10 5D 18 58 F8 23 26 9A 18 | success or wait | 691507623 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\deploy.jarNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11633fd | success or wait | 691527528 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 8192 Value: 8B 0E 58 D2 76 00 40 7E F3 2D 8C 1A 0B 91 00 10 67 34 32 79 F7 00 00 93 BF F9 8F 40 2B 01 00 CD 97 A4 E3 00 00 BC E8 18 5C A8 94 17 4C C6 08 00 00 44 A0 81 2A B0 41 07 0C C1 14 AC C0 0E 9C C1 1D BC C0 17 02 61 06 44 40 0C 24 C0 3C 10 42 06 E4 80 1C 0A A1 18 96 41 19 54 C0 3A D8 04 B5 B0 03 1A A0 11 | success or wait | 691529191 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\deploy.jarNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@af683a | success or wait | 691540586 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 53248 Value: 65 01 00 0C 49 6E 6E 65 72 43 6C 61 73 73 65 73 00 30 00 06 00 07 00 00 00 00 00 02 00 00 00 02 00 08 00 01 00 0B 00 00 00 13 00 03 00 03 00 00 00 07 2A 2B 2C B7 00 0A B1 00 00 00 00 00 01 00 04 00 01 00 01 00 0B 00 00 00 0E 00 01 00 03 00 00 00 02 03 AC 00 00 00 00 00 01 00 0C 00 00 00 0A 00 01 00 | success or wait | 691540847 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 692347777 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 692360991 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 692366325 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\deploy.jarNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1e3bd51 | success or wait | 692412643 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 12288 Value: 64 65 70 6C 6F 79 2F 73 65 63 75 72 69 74 79 2F 41 75 74 68 4B 65 79 3B 29 4C 63 6F 6D 2F 73 75 6E 2F 64 65 70 6C 6F 79 2F 73 65 63 75 72 69 74 79 2F 43 72 65 64 65 6E 74 69 61 6C 49 6E 66 6F 3B 01 00 4C 28 4C 63 6F 6D 2F 73 75 6E 2F 64 65 70 6C 6F 79 2F 73 65 63 75 72 69 74 79 2F 41 75 74 68 4B 65 | success or wait | 692708124 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\deploy.jarNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@a211cf | success or wait | 692715320 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 65536 Value: 6F 2F 46 69 6C 65 3B 29 56 0C 00 43 00 11 0C 00 28 00 15 0C 00 44 00 15 0C 00 48 00 5F 0C 00 26 00 60 0C 00 13 00 61 0C 00 29 00 62 0C 00 10 00 0B 0C 00 28 00 0C 0C 00 2B 00 0C 0C 00 44 00 0C 0C 00 2E 00 0D 0C 00 30 00 63 0C 00 2A 00 64 0C 00 31 00 65 0C 00 32 00 65 0C 00 33 00 65 0C 00 49 00 65 0C | success or wait | 692716404 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 65536 Value: B6 01 50 3A 1E 19 1D 01 B6 01 50 3A 1F 19 1A 19 1E B6 01 4A 9A 00 10 19 1A 19 1F B6 01 4A 9A 00 06 A7 00 CE 04 BD 00 B6 59 03 19 0B 53 3A 20 2D 12 0F 19 20 B6 01 44 3A 21 04 BD 00 BB 59 03 19 09 15 0A 32 53 3A 22 19 21 2B 19 22 B6 01 51 C0 00 AA C0 00 AA 3A 23 BB 00 CA 59 B7 01 5A 3A 24 03 36 25 15 | success or wait | 692780508 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 65536 Value: 6C 6F 79 2F 73 65 63 75 72 69 74 79 2F 41 75 74 68 49 6E 66 6F 49 74 65 6D 01 00 36 63 6F 6D 2F 73 75 6E 2F 64 65 70 6C 6F 79 2F 73 65 63 75 72 69 74 79 2F 57 49 45 78 70 6C 6F 72 65 72 42 72 6F 77 73 65 72 41 75 74 68 65 6E 74 69 63 61 74 6F 72 01 00 38 63 6F 6D 2F 73 75 6E 2F 64 65 70 6C 6F 79 2F | success or wait | 692819605 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 65536 Value: 6C 6F 79 2F 75 74 69 6C 2F 54 72 61 63 65 4C 65 76 65 6C 01 00 06 65 71 75 61 6C 73 01 00 05 66 6C 75 73 68 01 00 0E 67 65 74 49 6E 70 75 74 53 74 72 65 61 6D 01 00 0F 67 65 74 4F 75 74 70 75 74 53 74 72 65 61 6D 01 00 11 67 6F 74 20 6D 61 67 69 63 20 77 6F 72 64 21 21 21 01 00 07 68 61 73 4E 65 78 | success or wait | 692856854 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 65536 Value: 9A 00 0A 2A B4 03 71 B6 04 1A A7 00 0B 2A B4 03 7F 03 B6 04 40 B1 00 00 00 00 00 00 01 5B 02 18 00 01 04 55 00 00 00 1C 00 02 00 02 00 00 00 10 2A B4 03 56 C6 00 0B 2A B4 03 56 2B B6 03 CE B1 00 00 00 00 00 01 00 94 00 22 00 01 04 55 00 00 00 14 00 01 00 01 00 00 00 08 2A B4 03 71 B6 04 19 B1 00 00 | success or wait | 692897317 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 65536 Value: 00 00 00 01 00 09 00 4B 00 01 00 94 00 00 00 16 00 02 00 02 00 00 00 0A 2A B7 00 75 2A 2B B6 00 80 B1 00 00 00 00 00 01 00 09 00 07 00 01 00 94 00 00 00 60 00 09 00 07 00 00 00 54 2A B7 00 75 2A 1C B5 00 70 BB 00 3B 59 B7 00 8D 3A 04 19 04 B6 00 8E 3A 05 1D 99 00 10 19 05 04 1B 86 B6 00 88 3A 06 A7 | success or wait | 692936004 | 
| File read | Path: C:\Program Files\Java\jre6\lib\deploy.jar Offset: unknown Length: 49152 Value: 65 72 76 65 72 2F 52 4D 49 43 6C 61 73 73 4C 6F 61 64 65 72 53 70 69 3B 0C 00 02 00 01 0C 00 04 00 0E 0A 00 0A 00 0F 0A 00 0B 00 10 01 00 04 43 6F 64 65 01 00 0C 49 6E 6E 65 72 43 6C 61 73 73 65 73 00 30 00 09 00 0A 00 01 00 0C 00 00 00 02 00 00 00 02 00 01 00 01 00 13 00 00 00 11 00 01 00 01 00 00 | success or wait | 692974070 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\ext\dnsns.jar Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 693237732 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\ext\dnsns.jarNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@3f348a | success or wait | 693251209 | 
| File read | Path: C:\Program Files\Java\jre6\lib\ext\dnsns.jar Offset: unknown Length: 4143 Value: 5D 56 3E 69 D8 7A B2 1B 19 D9 50 A7 8F DB 48 4F 97 35 84 DD C9 7F 9F 82 D5 B2 33 10 6F 8C C6 AC E5 61 AB CB 8A 24 E2 36 C0 08 58 67 C4 F6 45 1E A5 D5 D7 51 6A AA 11 CD DD 78 9E AA 67 FA 10 53 4D 61 22 3A 78 E4 E5 07 82 41 5B 73 6F 76 E3 B9 4C 21 2A 0D 0D 95 28 24 62 11 0B C5 97 77 75 27 76 08 E6 7C | success or wait | 693251901 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\ext\localedata.jar Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 693310861 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\ext\localedata.jarNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@19269cb | success or wait | 693315257 | 
| File read | Path: C:\Program Files\Java\jre6\lib\ext\localedata.jar Offset: unknown Length: 14061 Value: 34 53 53 59 11 01 78 05 BD 08 DE 59 03 13 06 FB 53 59 04 19 39 53 53 59 11 01 79 05 BD 08 DE 59 03 13 06 FD 53 59 04 19 39 53 53 59 11 01 7A 05 BD 08 DE 59 03 13 06 FC 53 59 04 19 13 53 53 59 11 01 7B 05 BD 08 DE 59 03 12 15 53 59 04 19 0E 53 53 59 11 01 7C 05 BD 08 DE 59 03 12 18 53 59 04 19 0F 53 | success or wait | 693315652 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\fontconfig.bfc Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 693375401 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\fontconfig.bfcNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@15fb94a | success or wait | 693395034 | 
| File read | Path: C:\Program Files\Java\jre6\lib\fontconfig.bfc Offset: unknown Length: 3478 Value: 00 14 00 24 00 AC 00 B7 00 EE 01 0A 01 2C 01 4E 01 5E 01 6E 01 76 01 76 01 7C 02 03 06 CB 00 84 00 00 00 85 00 00 00 00 00 30 00 37 00 34 00 28 00 33 00 35 00 36 00 2C 00 29 00 2A 00 2E 00 2D 00 32 00 2B 00 2F 00 31 00 01 00 02 00 03 00 02 00 04 FF F0 00 06 00 07 00 08 00 09 00 08 FF DC FF C8 FF B4 | success or wait | 693397061 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\fonts\lucidabrightdemibold.ttf Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 693425284 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaBrightDemiBold.ttfNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@17dc299 | success or wait | 693449882 | 
| File read | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaBrightDemiBold.ttf Offset: unknown Length: 4096 Value: 00 01 00 00 00 0F 00 80 00 03 00 70 4C 54 53 48 24 EC BE C1 00 01 23 FC 00 00 01 8C 4F 53 2F 32 70 C4 7B 91 00 00 00 FC 00 00 00 56 63 6D 61 70 12 55 EC 7A 00 00 01 54 00 00 04 6A 63 76 74 20 38 1E 45 AE 00 00 05 C0 00 00 01 EE 66 70 67 6D 07 DB 31 8A 00 00 07 B0 00 00 07 BA 67 6C 79 66 40 3E D1 37 | success or wait | 693450665 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 693459771 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 693462626 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 693463825 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaBrightDemiBold.ttfNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@172cc99 | success or wait | 693464255 | 
| File read | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaBrightDemiBold.ttf Offset: unknown Length: 4096 Value: FF FF 00 00 00 00 02 D8 07 CF 02 32 00 4F 00 00 01 17 00 E0 FE F4 01 8B 00 13 40 0B 01 19 19 16 15 07 25 01 18 02 26 00 2B 35 01 2B 35 00 FF FF 00 2C FE 50 06 02 05 C8 02 32 00 31 00 00 01 17 00 DD FE C5 00 00 00 0E B9 00 01 FE 26 B4 29 34 16 21 25 01 2B 35 FF FF 00 1F FE 50 05 3B 04 63 02 32 00 51 | success or wait | 693464365 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\fonts\lucidabrightdemiitalic.ttf Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 693478598 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaBrightDemiItalic.ttfNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1d66c39 | success or wait | 693481642 | 
| File read | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaBrightDemiItalic.ttf Offset: unknown Length: 4096 Value: 00 01 00 00 00 0F 00 80 00 03 00 70 4C 54 53 48 9E C2 B3 9F 00 01 23 E8 00 00 01 8C 4F 53 2F 32 6B 9A 7B 91 00 00 00 FC 00 00 00 56 63 6D 61 70 12 55 EC 7A 00 00 01 54 00 00 04 6A 63 76 74 20 3D 6A 43 95 00 00 05 C0 00 00 01 EA 66 70 67 6D 07 DB 31 8A 00 00 07 AC 00 00 07 BA 67 6C 79 66 A1 95 9A E8 | success or wait | 693482228 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaBrightDemiItalic.ttfNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5b1426 | success or wait | 693513384 | 
| File read | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaBrightDemiItalic.ttf Offset: unknown Length: 8192 Value: 00 16 00 19 00 00 01 37 33 32 36 3F 01 21 37 01 33 03 33 07 23 07 06 15 14 1F 01 33 07 01 21 13 02 20 0E 0B 31 21 10 0B FE 5A 17 02 1F B2 66 6E 1D 6D 0B 0B 2D 11 0A 0D FD FD 01 3A 4D 02 50 46 28 4E 38 77 02 18 FD FF 8E 38 37 1F 1C 03 01 46 01 82 01 83 00 01 00 7B FF DB 05 E9 05 EE 00 2A 00 00 25 07 | success or wait | 693513481 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\fonts\lucidabrightitalic.ttf Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 693529791 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaBrightItalic.ttfNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1880571 | success or wait | 693534964 | 
| File read | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaBrightItalic.ttf Offset: unknown Length: 4096 Value: 00 01 00 00 00 0F 00 80 00 03 00 70 4C 54 53 48 8C 91 FB 32 00 01 3A 4C 00 00 01 8C 4F 53 2F 32 70 9A 7C 79 00 00 00 FC 00 00 00 56 63 6D 61 70 12 55 EC 7A 00 00 01 54 00 00 04 6A 63 76 74 20 46 A1 3B C7 00 00 05 C0 00 00 01 C2 66 70 67 6D 07 DB 31 8A 00 00 07 84 00 00 07 BA 67 6C 79 66 D2 7D 13 B9 | success or wait | 693535526 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaBrightItalic.ttfNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11d5b39 | success or wait | 693543110 | 
| File read | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaBrightItalic.ttf Offset: unknown Length: 4096 Value: 1C 03 1C A3 1D 39 1E 18 1E B7 1F 95 20 8C 21 5C 21 D4 22 26 22 4F 22 94 22 DD 22 F3 23 14 23 AF 24 63 24 D8 25 79 25 EF 26 69 27 28 27 EC 28 55 28 D8 29 82 29 CF 2A C6 2B 88 2B D7 2C 78 2D 02 2D 77 2E 25 2E BB 2F 9C 30 1F 30 D6 31 96 32 3E 32 D2 33 45 33 71 33 F6 34 4E 34 6E 34 99 34 AF 34 C7 34 DE | success or wait | 693543646 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\fonts\lucidabrightregular.ttf Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 693565224 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaBrightRegular.ttfNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5003f6 | success or wait | 693596529 | 
| File read | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaBrightRegular.ttf Offset: unknown Length: 4096 Value: 00 01 00 00 00 0F 00 80 00 03 00 70 4C 54 53 48 4E A6 83 55 00 05 3D CC 00 00 05 7E 4F 53 2F 32 94 83 82 53 00 00 00 FC 00 00 00 56 63 6D 61 70 1E D6 74 4F 00 00 01 54 00 00 07 96 63 76 74 20 3D 7C 74 3E 00 00 08 EC 00 00 03 74 66 70 67 6D 07 DB 31 8A 00 00 0C 60 00 00 07 BA 67 6C 79 66 15 4A EB E0 | success or wait | 693624213 | 
| File other op | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaBrightRegular.ttfNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1341b06 | success or wait | 693640223 | 
| File read | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaBrightRegular.ttf Offset: unknown Length: 4096 Value: 00 02 F9 28 00 02 FA 08 00 02 FA 1E 00 02 FB D8 00 02 FC AE 00 02 FD 84 00 02 FD E6 00 02 FD FC 00 02 FE 60 00 02 FE 76 00 02 FE DA 00 02 FF 42 00 03 00 46 00 03 00 5C 00 03 01 24 00 03 01 FE 00 03 03 BA 00 03 03 D0 00 03 04 22 00 03 04 74 00 03 04 8A 00 03 04 D8 00 03 04 EE 00 03 05 04 00 03 05 1A | success or wait | 693640577 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\fonts\lucidasansdemibold.ttf Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 693662430 | 
| File read | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaSansDemiBold.ttf Offset: unknown Length: 4096 Value: 00 01 00 00 00 0F 00 80 00 03 00 70 4C 54 53 48 5F 52 D6 61 00 00 00 FC 00 00 06 86 4F 53 2F 32 0F B9 EA 15 00 00 07 84 00 00 00 56 63 6D 61 70 7A EB 24 4C 00 00 07 DC 00 00 05 5A 63 76 74 20 A9 04 DC 79 00 00 0D 38 00 00 05 68 66 70 67 6D 07 DB 31 8A 00 00 12 A0 00 00 07 BA 67 6C 79 66 F2 88 07 A2 | success or wait | 693666629 | 
| File read | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaSansDemiBold.ttf Offset: unknown Length: 8192 Value: 00 01 8F 82 00 01 8F B4 00 01 8F E6 00 01 90 18 00 01 90 48 00 01 91 34 00 01 92 24 00 01 92 56 00 01 92 86 00 01 92 B4 00 01 92 E0 00 01 93 12 00 01 93 42 00 01 93 74 00 01 93 A4 00 01 93 D6 00 01 94 06 00 01 94 38 00 01 94 6A 00 01 94 E6 00 01 95 4C 00 01 96 6A 00 01 96 B4 00 01 97 1C 00 01 97 64 | success or wait | 693691658 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\fonts\lucidasansregular.ttf Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 694118403 | 
| File read | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaSansRegular.ttf Offset: unknown Length: 4096 Value: 00 01 00 00 00 12 01 00 00 04 00 20 47 44 45 46 BC DF BD 7C 00 09 E8 84 00 00 07 C6 47 50 4F 53 16 94 B8 CB 00 09 F0 4C 00 00 0E 48 47 53 55 42 CE AB 66 F2 00 09 FE 94 00 00 9B 0C 4C 54 53 48 89 88 92 E1 00 08 BE B0 00 00 0B 75 4F 53 2F 32 98 23 47 51 00 00 01 2C 00 00 00 56 63 6D 61 70 84 AF 34 D2 | success or wait | 694681171 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 694684498 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 694699118 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 694703195 | 
| File read | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaSansRegular.ttf Offset: unknown Length: 4096 Value: 00 05 ED EA 00 05 EF 84 00 05 EF AA 00 05 EF D0 00 05 EF F8 00 05 F0 20 00 05 F1 22 00 05 F2 04 00 05 F3 8E 00 05 F5 14 00 05 F6 E4 00 05 F7 B6 00 05 F8 8E 00 05 F9 E8 00 05 FB 64 00 05 FC 9E 00 05 FD 86 00 05 FE BC 00 05 FE E4 00 06 00 54 00 06 00 7E 00 06 01 B4 00 06 03 24 00 06 04 18 00 06 05 76 | success or wait | 695761994 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 695804637 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 695807037 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 695808192 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 697186252 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 697203854 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 697212781 | 
| File read | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaTypewriterBold.ttf Offset: unknown Length: 4096 Value: 00 01 00 00 00 0D 00 80 00 03 00 50 4F 53 2F 32 11 F4 E9 A6 00 00 00 DC 00 00 00 56 63 6D 61 70 57 1B 08 89 00 00 01 34 00 00 05 92 63 76 74 20 C1 4D 2F A7 00 00 06 C8 00 00 06 BC 66 70 67 6D 07 DB 31 8A 00 00 0D 84 00 00 07 BA 67 6C 79 66 7C 1E 9A 11 00 00 15 40 00 02 F7 0C 68 65 61 64 CC 9B 63 95 | success or wait | 697854050 | 
| File read | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaTypewriterBold.ttf Offset: unknown Length: 4096 Value: 00 01 DC AE 00 01 DC C6 00 01 DD FE 00 01 DE 16 00 01 DF 7E 00 01 DF A2 00 01 E0 78 00 01 E0 9C 00 01 E0 C2 00 01 E1 FC 00 01 E3 1A 00 01 E3 32 00 01 E3 58 00 01 E3 7C 00 01 E4 A0 00 01 E4 C8 00 01 E4 F4 00 01 E5 04 00 01 E6 2A 00 01 E6 42 00 01 E6 80 00 01 E6 C0 00 01 E7 72 00 01 E7 96 00 01 E7 C8 | success or wait | 697867008 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\fonts\lucidatypewriterregular.ttf Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 697896608 | 
| File read | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaTypewriterRegular.ttf Offset: unknown Length: 4096 Value: 00 01 00 00 00 0D 00 80 00 03 00 50 4F 53 2F 32 EF 01 8B 73 00 00 00 DC 00 00 00 60 63 6D 61 70 EB 15 52 68 00 00 01 3C 00 00 08 04 63 76 74 20 6D AA A1 09 00 00 09 40 00 00 04 3C 66 70 67 6D 07 DB 31 8A 00 00 0D 7C 00 00 07 BA 67 6C 79 66 A1 BD 3B 7D 00 00 15 38 00 03 1D 12 68 65 61 64 CC 98 2C 6A | success or wait | 697918737 | 
| File read | Path: C:\Program Files\Java\jre6\lib\fonts\LucidaTypewriterRegular.ttf Offset: unknown Length: 8192 Value: 00 01 04 0E 00 01 04 72 00 01 06 82 00 01 07 9A 00 01 08 34 00 01 08 62 00 01 09 B4 00 01 0A 38 00 01 0A 48 00 01 0A 58 00 01 0A 68 00 01 0A 78 00 01 0A 88 00 01 0A 98 00 01 0A A8 00 01 0B A0 00 01 0C 9E 00 01 0C AE 00 01 0D 14 00 01 0D AC 00 01 0E 4C 00 01 0F 0A 00 01 0F D6 00 01 10 78 00 01 11 52 | success or wait | 697954429 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\javaws.jar Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 697991733 | 
| File read | Path: C:\Program Files\Java\jre6\lib\javaws.jar Offset: unknown Length: 16384 Value: 50 4B 03 04 0A 00 00 00 00 00 D3 98 42 3E 00 00 00 00 00 00 00 00 00 00 00 00 09 00 00 00 4D 45 54 41 2D 49 4E 46 2F 50 4B 03 04 0A 00 00 00 00 00 D3 98 42 3E 6F 39 92 05 47 00 00 00 47 00 00 00 14 00 00 00 4D 45 54 41 2D 49 4E 46 2F 4D 41 4E 49 46 45 53 54 2E 4D 46 4D 61 6E 69 66 65 73 74 2D 56 65 | success or wait | 698009862 | 
| File read | Path: C:\Program Files\Java\jre6\lib\javaws.jar Offset: unknown Length: 65536 Value: 72 69 6E 67 3B 0C 00 0F 00 0D 0C 00 0B 00 09 0C 00 15 00 21 0C 00 16 00 21 0C 00 1B 00 21 0C 00 0B 00 22 0C 00 17 00 24 0C 00 10 00 25 0C 00 17 00 26 09 00 1E 00 27 0A 00 1D 00 2D 0A 00 1D 00 2F 0A 00 1E 00 29 0A 00 1E 00 2A 0A 00 1F 00 2C 0A 00 20 00 28 0A 00 20 00 2B 0A 00 20 00 2C 0A 00 20 00 2E | success or wait | 698045058 | 
| File read | Path: C:\Program Files\Java\jre6\lib\javaws.jar Offset: unknown Length: 65536 Value: 61 72 61 6D 65 74 65 72 73 01 00 19 63 6F 6D 2F 73 75 6E 2F 64 65 70 6C 6F 79 2F 75 74 69 6C 2F 54 72 61 63 65 01 00 1E 63 6F 6D 2F 73 75 6E 2F 64 65 70 6C 6F 79 2F 75 74 69 6C 2F 54 72 61 63 65 4C 65 76 65 6C 01 00 26 63 6F 6D 2F 73 75 6E 2F 64 65 70 6C 6F 79 2F 78 6D 6C 2F 58 4D 4C 41 74 74 72 69 | success or wait | 698088460 | 
| File read | Path: C:\Program Files\Java\jre6\lib\javaws.jar Offset: unknown Length: 65536 Value: 53 79 6E 74 68 65 74 69 63 01 00 01 5A 01 00 0A 61 63 63 65 73 73 24 31 30 30 01 00 03 61 64 64 01 00 20 63 6F 6D 2F 73 75 6E 2F 6A 61 76 61 77 73 2F 6A 6E 6C 2F 45 78 74 65 6E 73 69 6F 6E 44 65 73 63 01 00 1A 63 6F 6D 2F 73 75 6E 2F 6A 61 76 61 77 73 2F 6A 6E 6C 2F 4A 41 52 44 65 73 63 01 00 1A 63 | success or wait | 698129972 | 
| File read | Path: C:\Program Files\Java\jre6\lib\javaws.jar Offset: unknown Length: 65536 Value: 01 00 04 65 78 65 63 01 00 0B 65 78 65 63 50 72 6F 67 72 61 6D 01 00 11 65 78 65 63 75 74 65 49 6E 73 74 61 6C 6C 65 72 73 01 00 13 65 78 65 63 75 74 65 55 6E 69 6E 73 74 61 6C 6C 65 72 73 01 00 05 66 61 6C 73 65 01 00 04 66 69 6C 65 01 00 11 66 69 6C 65 52 65 61 64 57 72 69 74 65 4C 69 73 74 01 00 | success or wait | 698163861 | 
| File read | Path: C:\Program Files\Java\jre6\lib\javaws.jar Offset: unknown Length: 65536 Value: 49 6E 66 6F 3B 01 00 22 28 29 4C 63 6F 6D 2F 73 75 6E 2F 64 65 70 6C 6F 79 2F 75 69 2F 43 6F 6D 70 6F 6E 65 6E 74 52 65 66 3B 01 00 25 28 29 4C 63 6F 6D 2F 73 75 6E 2F 64 65 70 6C 6F 79 2F 75 74 69 6C 2F 4A 56 4D 50 61 72 61 6D 65 74 65 72 73 3B 01 00 23 28 4C 63 6F 6D 2F 73 75 6E 2F 64 65 70 6C 6F | success or wait | 698205006 | 
| File read | Path: C:\Program Files\Java\jre6\lib\javaws.jar Offset: unknown Length: 32768 Value: 00 00 01 00 9C 00 00 00 1A 00 03 00 34 00 33 00 9F 00 02 00 35 00 34 00 9D 00 02 00 36 00 34 00 9E 00 02 50 4B 03 04 0A 00 00 00 00 00 CA 98 42 3E 74 B5 16 21 46 0F 00 00 46 0F 00 00 25 00 00 00 63 6F 6D 2F 73 75 6E 2F 6A 61 76 61 77 73 2F 4F 70 65 72 61 50 72 65 66 65 72 65 6E 63 65 73 2E 63 6C 61 | success or wait | 698818852 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 698819338 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 698822820 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 698824144 | 
| File read | Path: C:\Program Files\Java\jre6\lib\javaws.jar Offset: unknown Length: 28672 Value: 75 6D 6E 01 00 16 72 65 73 2E 76 69 65 77 65 72 2E 73 69 7A 65 2E 63 6F 6C 75 6D 6E 01 00 15 72 65 73 2E 76 69 65 77 65 72 2E 75 72 6C 2E 63 6F 6C 75 6D 6E 01 00 19 72 65 73 2E 76 69 65 77 65 72 2E 76 65 72 73 69 6F 6E 2E 63 6F 6C 75 6D 6E 01 00 07 73 65 74 49 63 6F 6E 01 00 07 73 65 74 54 65 78 74 | success or wait | 698943620 | 
| File read | Path: C:\Program Files\Java\jre6\lib\javaws.jar Offset: unknown Length: 65536 Value: 63 6F 6D 2F 73 75 6E 2F 6A 61 76 61 77 73 2F 75 69 2F 44 6F 77 6E 6C 6F 61 64 57 69 6E 64 6F 77 24 36 01 00 09 67 65 74 53 74 72 69 6E 67 01 00 10 6A 61 76 61 2F 6C 61 6E 67 2F 4F 62 6A 65 63 74 01 00 12 6A 61 76 61 2F 6C 61 6E 67 2F 52 75 6E 6E 61 62 6C 65 01 00 12 70 72 6F 67 72 65 73 73 2E 6C 61 | success or wait | 699012319 | 
| File read | Path: C:\Program Files\Java\jre6\lib\javaws.jar Offset: unknown Length: 65536 Value: 01 EE 0A 01 36 01 E2 0A 01 36 01 F3 0A 01 37 01 8B 0A 01 38 01 8B 0A 01 38 01 EB 0A 01 39 01 8D 0A 01 39 01 8E 0A 01 39 01 A4 0A 01 39 01 A5 0A 01 39 01 A8 0A 01 39 01 A9 0A 01 39 01 AA 0A 01 39 01 B0 0A 01 39 01 B2 0A 01 39 01 B4 0A 01 39 01 B8 0A 01 39 01 C6 0A 01 39 01 C8 0A 01 39 01 D5 0A 01 39 | success or wait | 699056940 | 
| File read | Path: C:\Program Files\Java\jre6\lib\javaws.jar Offset: unknown Length: 8192 Value: 69 6C 65 3B 0C 00 0F 00 16 0C 00 04 00 01 0C 00 07 00 02 0C 00 04 00 03 0C 00 06 00 19 09 00 11 00 1A 0A 00 10 00 1E 0A 00 12 00 1C 0A 00 13 00 1D 0A 00 14 00 1B 01 00 04 43 6F 64 65 01 00 0C 49 6E 6E 65 72 43 6C 61 73 73 65 73 00 20 00 11 00 14 00 01 00 15 00 01 00 12 00 0F 00 16 00 01 00 05 00 00 | success or wait | 699098330 | 
| File read | Path: C:\Program Files\Java\jre6\lib\javaws.jar Offset: unknown Length: 45056 Value: 65 74 41 73 73 6F 63 69 61 74 69 6F 6E 01 00 0B 73 65 74 4D 69 6D 65 54 79 70 65 01 00 07 73 65 74 4E 61 6D 65 01 00 0B 73 65 74 53 68 6F 72 74 63 75 74 01 00 09 73 75 62 73 74 72 69 6E 67 01 00 0B 74 6F 4C 6F 77 65 72 43 61 73 65 01 00 08 74 6F 53 74 72 69 6E 67 01 00 04 74 72 69 6D 01 00 1C 76 61 | success or wait | 699122368 | 
| File read | Path: C:\Program Files\Java\jre6\lib\javaws.jar Offset: unknown Length: 57344 Value: 65 74 2F 55 52 4C 3B 29 56 0C 00 0C 00 14 0C 00 0D 00 15 0C 00 02 00 01 0C 00 06 00 17 09 00 0F 00 19 09 00 0F 00 1A 0A 00 0E 00 1C 0A 00 11 00 1B 01 00 04 43 6F 64 65 01 00 0A 45 78 63 65 70 74 69 6F 6E 73 01 00 0C 49 6E 6E 65 72 43 6C 61 73 73 65 73 00 20 00 0F 00 11 00 01 00 13 00 02 00 12 00 0D | success or wait | 699204570 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\jsse.jar Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 699795016 | 
| File read | Path: C:\Program Files\Java\jre6\lib\jsse.jar Offset: unknown Length: 24576 Value: 67 3B 29 4C 6A 61 76 61 2F 73 65 63 75 72 69 74 79 2F 50 72 69 76 61 74 65 4B 65 79 3B 01 00 39 28 4C 6A 61 76 61 2F 6C 61 6E 67 2F 53 74 72 69 6E 67 3B 29 5B 4C 6A 61 76 61 2F 73 65 63 75 72 69 74 79 2F 63 65 72 74 2F 58 35 30 39 43 65 72 74 69 66 69 63 61 74 65 3B 01 00 40 28 4C 6A 61 76 61 2F 6C | success or wait | 699840950 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 699891191 | 
| Thread delayed | Time: 0 TID: 3696 | success or wait | 699896063 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\logging.properties Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 700106650 | 
| File read | Path: C:\Program Files\Java\jre6\lib\logging.properties Offset: unknown Length: 2245 Value: 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 0A 23 20 20 09 44 65 66 61 75 6C 74 20 4C 6F 67 67 69 6E 67 20 43 6F 6E 66 69 67 75 72 61 74 69 6F 6E 20 46 69 6C 65 0A | success or wait | 700108762 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\meta-index Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 700118872 | 
| File read | Path: C:\Program Files\Java\jre6\lib\meta-index Offset: unknown Length: 2338 Value: 25 20 56 45 52 53 49 4F 4E 20 32 0D 0A 25 20 57 41 52 4E 49 4E 47 3A 20 74 68 69 73 20 66 69 6C 65 20 69 73 20 61 75 74 6F 2D 67 65 6E 65 72 61 74 65 64 3B 20 64 6F 20 6E 6F 74 20 65 64 69 74 0D 0A 25 20 55 4E 53 55 50 50 4F 52 54 45 44 3A 20 74 68 69 73 20 66 69 6C 65 20 61 6E 64 20 69 74 73 20 66 | success or wait | 700121260 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\net.properties Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 700128775 | 
| File read | Path: C:\Program Files\Java\jre6\lib\net.properties Offset: unknown Length: 3070 Value: 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 23 0A 23 20 20 09 44 65 66 61 75 6C 74 20 4E 65 74 77 6F 72 6B 69 6E 67 20 43 6F 6E 66 69 67 75 72 61 74 69 6F 6E 20 46 69 | success or wait | 700130684 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\plugin.jar Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 700138910 | 
| File read | Path: C:\Program Files\Java\jre6\lib\plugin.jar Offset: unknown Length: 8192 Value: 50 4B 03 04 0A 00 00 00 00 00 41 99 42 3E 00 00 00 00 00 00 00 00 00 00 00 00 09 00 00 00 4D 45 54 41 2D 49 4E 46 2F 50 4B 03 04 0A 00 00 00 00 00 41 99 42 3E 6F 39 92 05 47 00 00 00 47 00 00 00 14 00 00 00 4D 45 54 41 2D 49 4E 46 2F 4D 41 4E 49 46 45 53 54 2E 4D 46 4D 61 6E 69 66 65 73 74 2D 56 65 | success or wait | 700140930 | 
| File read | Path: C:\Program Files\Java\jre6\lib\plugin.jar Offset: unknown Length: 8192 Value: 13 2B BB 00 6A 59 B7 00 B8 B6 00 A8 2B 04 B6 00 A7 2B B0 00 00 00 00 00 00 50 4B 03 04 0A 00 00 00 00 00 3A 99 42 3E 00 00 00 00 00 00 00 00 00 00 00 00 11 00 00 00 73 75 6E 2F 70 6C 75 67 69 6E 2F 63 61 63 68 65 2F 50 4B 03 04 0A 00 00 00 00 00 3A 99 42 3E E0 10 85 D4 13 08 00 00 13 08 00 00 28 00 | success or wait | 700154394 | 
| File read | Path: C:\Program Files\Java\jre6\lib\plugin.jar Offset: unknown Length: 36864 Value: 67 2F 53 74 72 69 6E 67 42 75 66 66 65 72 3B 01 00 57 28 4C 73 75 6E 2F 70 6C 75 67 69 6E 2F 65 78 74 65 6E 73 69 6F 6E 2F 45 78 74 65 6E 73 69 6F 6E 49 6E 73 74 61 6C 6C 61 74 69 6F 6E 49 6D 70 6C 3B 4C 6A 61 76 61 2F 6C 61 6E 67 2F 53 74 72 69 6E 67 3B 4C 6A 61 76 61 2F 6C 61 6E 67 2F 53 74 72 69 | success or wait | 700170748 | 
| File read | Path: C:\Program Files\Java\jre6\lib\plugin.jar Offset: unknown Length: 40960 Value: 6E 2F 6E 65 74 2F 63 6F 6F 6B 69 65 2F 4E 65 74 73 63 61 70 65 34 43 6F 6F 6B 69 65 48 61 6E 64 6C 65 72 2E 63 6C 61 73 73 CA FE BA BE 00 00 00 30 00 71 08 00 0B 08 00 0D 08 00 0E 08 00 12 08 00 13 01 00 03 28 29 56 01 00 03 28 29 5A 01 00 04 28 49 29 49 01 00 06 3C 69 6E 69 74 3E 01 00 04 43 6F 64 | success or wait | 700229996 | 
| File read | Path: C:\Program Files\Java\jre6\lib\plugin.jar Offset: unknown Length: 8192 Value: 6F 6B 69 65 48 61 6E 64 6C 65 72 3B 01 00 2D 28 29 4C 63 6F 6D 2F 73 75 6E 2F 64 65 70 6C 6F 79 2F 6E 65 74 2F 6F 66 66 6C 69 6E 65 2F 4F 66 66 6C 69 6E 65 48 61 6E 64 6C 65 72 3B 01 00 2F 28 29 4C 63 6F 6D 2F 73 75 6E 2F 64 65 70 6C 6F 79 2F 6E 65 74 2F 70 72 6F 78 79 2F 42 72 6F 77 73 65 72 50 72 | success or wait | 700286859 | 
| File read | Path: C:\Program Files\Java\jre6\lib\plugin.jar Offset: unknown Length: 28672 Value: C7 1F BE FE 9D EF 77 2D 0D 36 0D 55 8D 9C C6 E2 23 70 44 79 E4 E9 F7 09 DF F7 1E 0D 3A DA 76 8C 7B AC E1 07 D3 1F 76 1D 67 1D 2F 6A 42 9A F2 9A 46 9B 53 9A FB 5B 62 5B BA 4F CC 3E D1 D6 EA DE 7A FC 47 DB 1F 0F 9C 34 3C 59 79 4A F3 54 C9 69 DA E9 82 D3 93 67 F2 CF 8C 9D 95 9D 7D 7E 2E F9 DC 60 DB A2 | success or wait | 700304759 | 
| File read | Path: C:\Program Files\Java\jre6\lib\plugin.jar Offset: unknown Length: 36864 Value: 63 48 52 4D 00 00 7A 25 00 00 80 83 00 00 F9 FF 00 00 80 E9 00 00 75 30 00 00 EA 60 00 00 3A 98 00 00 17 6F 92 5F C5 46 00 00 14 25 49 44 41 54 78 DA EC 9D 79 94 1D 55 9D C7 3F BD 27 DD 9D 85 34 D9 20 84 6C 64 21 89 89 C0 30 48 06 07 64 58 0C 51 06 C2 22 8A 3A 84 45 E1 88 A3 38 10 D4 D1 91 19 07 38 | success or wait | 700342876 | 
| File read | Path: C:\Program Files\Java\jre6\lib\plugin.jar Offset: unknown Length: 65536 Value: 00 C2 01 07 09 00 C2 01 08 09 00 C2 01 09 09 00 C2 01 0A 09 00 C2 01 0B 09 00 C2 01 0C 0A 00 A7 01 2F 0A 00 A8 01 26 0A 00 A9 01 43 0A 00 A9 01 44 0A 00 AA 01 32 0A 00 AB 01 10 0A 00 AC 01 1A 0A 00 AC 01 41 0A 00 AE 01 1D 0A 00 AE 01 2D 0A 00 B0 01 10 0A 00 B0 01 46 0A 00 B2 01 10 0A 00 B2 01 15 0A | success or wait | 700399472 | 
| File read | Path: C:\Program Files\Java\jre6\lib\plugin.jar Offset: unknown Length: 16384 Value: 0C 00 D8 01 75 0C 00 7A 01 76 0C 00 38 01 77 0C 00 D3 01 78 0C 00 DD 01 79 0C 00 96 01 7A 0C 00 9C 01 7A 0C 00 9D 01 7A 0C 00 EF 01 7B 0C 00 EE 01 7C 0C 00 5B 01 7D 0C 00 38 01 7E 0C 00 D5 01 7F 0C 00 53 01 80 0C 00 53 01 81 0C 00 A5 01 82 0C 00 63 01 83 0C 00 DF 01 84 0C 00 DA 01 85 0C 00 ED 01 87 | success or wait | 701345642 | 
| File read | Path: C:\Program Files\Java\jre6\lib\plugin.jar Offset: unknown Length: 65536 Value: 54 69 74 6C 65 01 00 0E 73 65 74 55 6E 64 65 63 6F 72 61 74 65 64 01 00 0A 73 65 74 56 69 73 69 62 6C 65 01 00 12 73 65 74 75 70 43 6C 6F 73 65 4C 69 73 74 65 6E 65 72 01 00 0B 73 65 74 75 70 57 69 6E 64 6F 77 01 00 09 73 75 62 73 74 72 69 6E 67 01 00 1D 73 75 6E 2F 70 6C 75 67 69 6E 32 2F 61 70 70 | success or wait | 701383967 | 
| File read | Path: C:\Program Files\Java\jre6\lib\plugin.jar Offset: unknown Length: 65536 Value: 04 BA B6 04 B9 B2 04 07 B8 04 4E 19 0C 15 18 B9 05 06 02 00 36 0D 15 06 9A 00 0E 15 0D 99 00 09 B2 04 0E 99 01 03 1C 99 00 0E 2A 13 02 31 04 B8 04 B7 B6 04 EB 15 15 9A 00 20 2A 13 02 30 19 16 B6 04 EB BB 02 5E 59 19 16 09 09 19 10 B6 04 76 01 01 B7 04 78 3A 17 B2 04 0C 99 00 70 BB 02 78 59 B7 04 B8 | success or wait | 701490801 | 
| File read | Path: C:\Program Files\Java\jre6\lib\plugin.jar Offset: unknown Length: 49152 Value: 50 6C 75 67 69 6E 32 4D 61 6E 61 67 65 72 24 41 70 70 6C 65 74 45 78 65 63 75 74 69 6F 6E 52 75 6E 6E 61 62 6C 65 24 31 2E 63 6C 61 73 73 CA FE BA BE 00 00 00 30 00 61 08 00 09 08 00 0B 01 00 03 28 29 49 01 00 03 28 29 56 01 00 03 28 29 5A 01 00 05 28 49 49 29 56 01 00 04 28 5A 29 56 01 00 06 3C 69 | success or wait | 701575087 | 
| File read | Path: C:\Program Files\Java\jre6\lib\plugin.jar Offset: unknown Length: 65536 Value: 72 3B 01 00 64 28 4C 73 75 6E 2F 70 6C 75 67 69 6E 32 2F 61 70 70 6C 65 74 2F 76 69 65 77 65 72 2F 4A 4E 4C 50 32 56 69 65 77 65 72 3B 4C 6A 61 76 61 2F 6C 61 6E 67 2F 54 68 72 65 61 64 47 72 6F 75 70 3B 4C 73 75 6E 2F 70 6C 75 67 69 6E 32 2F 61 70 70 6C 65 74 2F 50 6C 75 67 69 6E 32 4D 61 6E 61 67 | success or wait | 701645367 | 
| File read | Path: C:\Program Files\Java\jre6\lib\plugin.jar Offset: unknown Length: 65536 Value: 6C 61 6E 67 2F 4F 62 6A 65 63 74 3B 5A 29 56 01 00 14 28 29 4C 6A 61 76 61 2F 6C 61 6E 67 2F 53 74 72 69 6E 67 3B 01 00 15 28 4C 6A 61 76 61 2F 6C 61 6E 67 2F 53 74 72 69 6E 67 3B 29 56 01 00 22 28 4C 6A 61 76 61 2F 6C 61 6E 67 2F 72 65 66 6C 65 63 74 2F 43 6F 6E 73 74 72 75 63 74 6F 72 3B 29 56 01 | success or wait | 701740560 | 
| File read | Path: C:\Program Files\Java\jre6\lib\plugin.jar Offset: unknown Length: 65536 Value: 69 6F 6E 44 65 6C 65 67 61 74 65 01 00 15 4A 61 76 61 4E 61 6D 65 53 70 61 63 65 44 65 6C 65 67 61 74 65 01 00 11 4C 69 76 65 43 6F 6E 6E 65 63 74 57 6F 72 6B 65 72 01 00 0D 50 65 72 41 70 70 6C 65 74 49 6E 66 6F 00 20 00 E1 00 CC 00 00 00 0F 00 02 00 43 00 29 00 00 00 02 00 93 00 F8 00 00 00 02 00 | success or wait | 701826119 | 
| File read | Path: C:\Program Files\Java\jre6\lib\plugin.jar Offset: unknown Length: 28672 Value: 69 6E 32 2F 6D 61 69 6E 2F 63 6C 69 65 6E 74 2F 50 6C 75 67 69 6E 4D 61 69 6E 3B 01 00 7A 28 4C 73 75 6E 2F 70 6C 75 67 69 6E 32 2F 6D 61 69 6E 2F 63 6C 69 65 6E 74 2F 50 6C 75 67 69 6E 4D 61 69 6E 24 50 6C 75 67 69 6E 4D 61 69 6E 44 72 61 67 4C 69 73 74 65 6E 65 72 24 31 3B 29 4C 73 75 6E 2F 70 6C | success or wait | 701918597 | 
| File read | Path: C:\Program Files\Java\jre6\lib\plugin.jar Offset: unknown Length: 65536 Value: 6E 74 72 6F 6C 57 69 6E 64 6F 77 01 00 07 68 61 6E 64 6C 65 72 01 00 06 68 65 69 67 68 74 01 00 17 69 43 72 65 61 74 65 64 4D 61 69 6E 54 68 72 65 61 64 45 76 65 6E 74 01 00 12 69 64 65 6E 74 69 66 69 65 72 54 6F 53 74 72 69 6E 67 01 00 07 69 6E 64 65 78 4F 66 01 00 09 69 6E 69 74 43 61 75 73 65 01 | success or wait | 701959262 | 
| File read | Path: C:\Program Files\Java\jre6\lib\plugin.jar Offset: unknown Length: 65536 Value: 01 00 05 73 74 61 72 74 01 00 20 73 75 6E 2F 70 6C 75 67 69 6E 32 2F 6D 65 73 73 61 67 65 2F 43 6F 6E 76 65 72 73 61 74 69 6F 6E 01 00 18 73 75 6E 2F 70 6C 75 67 69 6E 32 2F 6D 65 73 73 61 67 65 2F 50 69 70 65 01 00 25 73 75 6E 2F 70 6C 75 67 69 6E 32 2F 6D 65 73 73 61 67 65 2F 50 69 70 65 24 57 6F | success or wait | 702959671 | 
| File read | Path: C:\Program Files\Java\jre6\lib\plugin.jar Offset: unknown Length: 57344 Value: 0C 00 30 00 5D 0C 00 2E 00 5E 0C 00 2F 00 5E 0C 00 4E 00 5E 0C 00 4F 00 5E 0C 00 31 00 5F 0C 00 48 00 60 0C 00 1E 00 61 0C 00 3E 00 61 0C 00 44 00 61 0C 00 29 00 62 0C 00 47 00 62 0C 00 1E 00 64 0C 00 2D 00 65 0C 00 32 00 65 0C 00 33 00 65 0C 00 46 00 66 0C 00 27 00 67 0C 00 50 00 68 0C 00 2C 00 69 | success or wait | 703303709 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\resources.jar Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 703338991 | 
| File read | Path: C:\Program Files\Java\jre6\lib\resources.jar Offset: unknown Length: 16384 Value: 6D 65 64 20 6F 67 69 6C 74 69 67 20 73 74 61 74 75 73 20 28 6D E5 73 74 65 20 76 61 72 61 20 77 61 69 74 29 0A 72 6D 69 64 2E 65 78 65 63 2E 70 6F 6C 69 63 79 2E 65 78 63 65 70 74 69 6F 6E 3D 72 6D 69 64 5C 3A 20 66 F6 72 73 F6 6B 20 61 74 74 20 68 E4 6D 74 61 20 74 68 72 6F 77 73 20 66 F6 72 20 65 | success or wait | 703341695 | 
| File read | Path: C:\Program Files\Java\jre6\lib\resources.jar Offset: unknown Length: 65536 Value: 08 08 08 08 08 08 FF FF FF 0C 08 09 09 09 09 09 09 09 09 09 09 08 08 08 08 08 08 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 05 | success or wait | 703351442 | 
| File read | Path: C:\Program Files\Java\jre6\lib\resources.jar Offset: unknown Length: 36864 Value: 61 DD ED 00 01 90 94 00 01 90 F1 00 01 91 11 00 02 D8 61 DF 2E 00 01 91 1B 00 01 92 38 00 01 92 D7 00 01 92 D8 00 01 92 7C 00 01 93 F9 00 01 94 15 00 02 D8 62 DF FA 00 01 95 8B 00 01 49 95 00 01 95 B7 00 02 D8 63 DD 77 00 01 49 E6 00 01 96 C3 00 01 5D B2 00 01 97 23 00 02 D8 64 DD 45 00 02 D8 64 DE | success or wait | 703380837 | 
| File read | Path: C:\Program Files\Java\jre6\lib\resources.jar Offset: unknown Length: 28672 Value: 03 CC 03 CF 03 D5 03 D2 03 CC 03 CF 03 D5 03 D2 03 CC 03 CF 03 D5 03 D2 03 CC 03 CF 03 D5 03 D2 03 CC 03 CF 03 D5 03 D2 03 CC 03 CF 03 D5 03 D2 03 CC 03 CF 03 D5 03 D2 03 CC 03 CF 03 D5 03 D2 03 CC 03 D2 03 CC 03 D2 03 CC 03 D2 03 CC 03 D2 03 CC 03 D2 03 CC 03 D2 03 CC 03 CF 03 D5 03 D2 03 CC 03 CF | success or wait | 703398656 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\rt.jar Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 703412139 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 20480 Value: 69 2F 74 72 61 6E 73 70 6F 72 74 2F 54 72 61 6E 73 70 6F 72 74 44 65 66 61 75 6C 74 24 32 01 00 31 63 6F 6D 2F 73 75 6E 2F 63 6F 72 62 61 2F 73 65 2F 73 70 69 2F 74 72 61 6E 73 70 6F 72 74 2F 54 72 61 6E 73 70 6F 72 74 44 65 66 61 75 6C 74 24 33 01 00 10 6A 61 76 61 2F 6C 61 6E 67 2F 4F 62 6A 65 63 | success or wait | 703414606 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 32768 Value: 69 6F 6E 20 6D 65 74 68 6F 64 20 28 6E 6F 74 20 30 29 21 01 00 1E 55 6E 6B 6E 6F 77 6E 20 66 69 6C 74 65 72 20 6D 65 74 68 6F 64 20 28 6E 6F 74 20 30 29 21 01 00 26 55 6E 6B 6E 6F 77 6E 20 69 6E 74 65 72 6C 61 63 65 20 6D 65 74 68 6F 64 20 28 6E 6F 74 20 30 20 6F 72 20 31 29 21 01 00 1B 55 6E 6B 6E | success or wait | 703426864 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 24576 Value: 00 18 00 26 0A 00 18 00 2B 0A 00 19 00 25 0A 00 1A 00 27 0A 00 1A 00 29 0A 00 1B 00 25 0A 00 1B 00 28 0A 00 1B 00 2A 01 00 04 49 6D 70 6C 04 21 00 18 00 19 00 01 00 17 00 01 00 42 00 14 00 1D 00 01 00 09 00 00 00 02 00 1E 00 05 00 01 00 05 00 02 00 01 00 06 00 00 00 11 00 01 00 01 00 00 00 05 2A B7 | success or wait | 703444138 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 12288 Value: 3E 9D 27 58 76 3A 1A 00 00 3A 1A 00 00 36 00 00 00 63 6F 6D 2F 73 75 6E 2F 6A 61 76 61 2F 73 77 69 6E 67 2F 70 6C 61 66 2F 6D 6F 74 69 66 2F 4D 6F 74 69 66 47 72 61 70 68 69 63 73 55 74 69 6C 73 2E 63 6C 61 73 73 CA FE BA BE 00 00 00 31 01 44 08 00 06 08 00 0F 08 00 16 08 00 45 08 00 68 01 00 00 01 | success or wait | 703456990 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 8192 Value: 79 42 69 6E 64 69 6E 67 52 65 67 69 73 74 65 72 65 64 01 00 0A 69 73 53 65 6C 65 63 74 65 64 01 00 0E 6A 61 76 61 2F 61 77 74 2F 43 6F 6C 6F 72 01 00 10 6A 61 76 61 2F 61 77 74 2F 54 6F 6F 6C 6B 69 74 01 00 15 6A 61 76 61 78 2F 73 77 69 6E 67 2F 41 63 74 69 6F 6E 4D 61 70 01 00 1A 6A 61 76 61 78 2F | success or wait | 703463554 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 4096 Value: 02 08 02 03 08 02 04 08 02 05 08 02 07 08 02 08 08 02 09 08 02 0A 08 02 0B 08 02 0C 08 02 0D 08 02 0E 08 02 0F 08 02 10 08 02 11 08 02 12 08 02 13 08 02 14 08 02 16 08 02 17 08 02 18 08 02 19 08 02 1A 08 02 1B 08 02 1C 08 02 1D 08 02 1E 08 02 1F 08 02 21 08 02 22 08 02 23 08 02 24 08 02 25 08 02 26 | success or wait | 703465436 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 28672 Value: 04 12 21 53 53 59 10 07 05 BD 00 51 59 03 12 0A 53 59 04 12 16 53 53 59 10 08 05 BD 00 51 59 03 12 0B 53 59 04 12 02 53 53 59 10 09 05 BD 00 51 59 03 12 0C 53 59 04 12 23 53 53 59 10 0A 05 BD 00 51 59 03 12 0D 53 59 04 12 18 53 53 59 10 0B 05 BD 00 51 59 03 12 0E 53 59 04 12 1B 53 53 59 10 0C 05 BD | success or wait | 703467485 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 28672 Value: 64 45 64 69 74 61 62 6C 65 01 00 22 70 61 69 6E 74 42 61 63 6B 67 72 6F 75 6E 64 4D 6F 75 73 65 4F 76 65 72 41 6E 64 46 6F 63 75 73 65 64 01 00 16 70 61 69 6E 74 42 61 63 6B 67 72 6F 75 6E 64 50 72 65 73 73 65 64 01 00 21 70 61 69 6E 74 42 61 63 6B 67 72 6F 75 6E 64 50 72 65 73 73 65 64 41 6E 64 45 | success or wait | 703481578 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 65536 Value: 65 72 2F 49 6E 61 63 63 65 73 73 69 62 6C 65 57 53 44 4C 45 78 63 65 70 74 69 6F 6E 01 00 45 63 6F 6D 2F 73 75 6E 2F 78 6D 6C 2F 69 6E 74 65 72 6E 61 6C 2F 77 73 2F 77 73 64 6C 2F 70 61 72 73 65 72 2F 49 6E 61 63 63 65 73 73 69 62 6C 65 57 53 44 4C 45 78 63 65 70 74 69 6F 6E 24 42 75 69 6C 64 65 72 | success or wait | 703499538 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 65536 Value: 06 BE 36 07 03 36 08 15 08 15 07 A2 00 46 19 06 15 08 32 3A 09 19 09 B9 00 F8 01 00 B6 00 D6 2D B9 00 ED 01 00 B6 00 D6 B6 00 D8 99 00 20 19 09 B9 00 F9 01 00 12 01 B6 00 D8 99 00 04 B1 2A 2B 19 09 B9 00 F9 01 00 B7 00 D4 B1 84 08 01 A7 FF B9 B1 00 00 00 00 00 02 00 1F 00 8E 00 01 00 15 00 00 00 1A | success or wait | 703763885 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 65536 Value: 11 4C 6A 61 76 61 2F 61 77 74 2F 42 75 74 74 6F 6E 3B 01 00 24 4C 6A 61 76 61 78 2F 61 63 63 65 73 73 69 62 69 6C 69 74 79 2F 41 63 63 65 73 73 69 62 6C 65 52 6F 6C 65 3B 01 00 16 28 4C 6A 61 76 61 2F 61 77 74 2F 41 57 54 45 76 65 6E 74 3B 29 56 01 00 14 28 4C 6A 61 76 61 2F 61 77 74 2F 42 75 74 74 | success or wait | 703798361 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 65536 Value: 2A 2B 2C 2D 19 04 B7 00 55 2A 15 05 B5 00 4C B1 00 00 00 00 00 01 00 18 00 35 00 01 00 0A 00 00 00 22 00 04 00 01 00 00 00 16 BB 00 2F 59 2A B4 00 4F B4 00 51 2A B4 00 4F B4 00 52 B7 00 59 B0 00 00 00 00 00 01 00 16 00 34 00 01 00 0A 00 00 00 11 00 01 00 01 00 00 00 05 2A B4 00 4D B0 00 00 00 00 00 | success or wait | 703829727 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 28672 Value: 00 11 00 01 00 00 00 00 00 05 03 B3 01 3E B1 00 00 00 00 00 01 00 1F 00 00 00 0A 00 01 00 AF 00 AE 01 9A 00 04 50 4B 03 04 0A 00 00 00 00 00 81 90 42 3E DE 7E C5 C8 7C 02 00 00 7C 02 00 00 25 00 00 00 6A 61 76 61 2F 61 77 74 2F 4D 65 6E 75 24 41 63 63 65 73 73 69 62 6C 65 41 57 54 4D 65 6E 75 2E 63 | success or wait | 703861154 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 65536 Value: 61 76 61 2F 61 77 74 2F 50 6F 6C 79 67 6F 6E 24 50 6F 6C 79 67 6F 6E 50 61 74 68 49 74 65 72 61 74 6F 72 01 00 1D 6A 61 76 61 2F 61 77 74 2F 67 65 6F 6D 2F 41 66 66 69 6E 65 54 72 61 6E 73 66 6F 72 6D 01 00 1A 6A 61 76 61 2F 61 77 74 2F 67 65 6F 6D 2F 50 61 74 68 49 74 65 72 61 74 6F 72 01 00 10 6A | success or wait | 703876475 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 65536 Value: 0C 00 22 00 C0 0C 00 6A 00 C0 0C 00 3D 00 C1 0C 00 6D 00 C2 09 00 8A 00 C3 09 00 90 00 CD 09 00 91 00 C4 09 00 91 00 C5 09 00 91 00 C6 09 00 91 00 C7 09 00 91 00 C8 09 00 91 00 C9 09 00 91 00 CA 09 00 91 00 CB 09 00 91 00 CC 09 00 91 00 CE 09 00 91 00 CF 09 00 91 00 D0 09 00 91 00 D1 0A 00 8B 00 FE | success or wait | 703907279 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 65536 Value: 2F 61 77 74 2F 64 6E 64 2F 44 72 61 67 47 65 73 74 75 72 65 45 76 65 6E 74 2E 63 6C 61 73 73 CA FE BA BE 00 00 00 31 00 A8 03 40 00 00 00 08 00 1A 08 00 1B 08 00 1C 08 00 1E 08 00 1F 08 00 3A 08 00 3B 08 00 3C 08 00 3D 08 00 3E 01 00 03 28 29 49 01 00 03 28 29 56 01 00 03 28 29 5A 01 00 15 28 4C 6A | success or wait | 703938149 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 65536 Value: B4 00 60 B6 00 6B B8 00 6F 90 AE 00 00 00 00 00 01 00 19 00 02 00 01 00 0A 00 00 00 19 00 04 00 01 00 00 00 0D 0E 2A B4 00 60 B6 00 6A B8 00 6F 90 AE 00 00 00 00 00 01 00 13 00 41 00 01 00 0A 00 00 00 5C 00 03 00 05 00 00 00 40 2B 24 8B 25 8B B6 00 63 2A B4 00 5E 04 A0 00 0E 2B 2A B4 00 5F B6 00 64 | success or wait | 703973769 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 65536 Value: 00 01 00 33 00 08 00 01 00 0E 00 00 00 3B 00 03 00 0E 00 00 00 2F 2A 15 0D B6 00 68 2A 27 90 B5 00 64 2A 29 90 B5 00 65 2A 18 05 90 B5 00 63 2A 18 07 90 B5 00 61 2A 18 09 90 B5 00 62 2A 18 0B 90 B5 00 60 B1 00 00 00 00 00 01 00 32 00 07 00 01 00 0E 00 00 00 13 00 03 00 03 00 00 00 07 2A 27 90 B5 00 | success or wait | 704237371 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 20480 Value: 6F 72 20 6F 75 74 20 6F 66 20 62 6F 75 6E 64 73 01 00 09 74 72 61 6E 73 66 6F 72 6D 01 00 01 77 01 00 01 78 01 00 01 79 07 00 19 07 00 1A 07 00 1B 07 00 1C 07 00 1D 07 00 1E 01 00 1F 4C 6A 61 76 61 2F 61 77 74 2F 67 65 6F 6D 2F 41 66 66 69 6E 65 54 72 61 6E 73 66 6F 72 6D 3B 01 00 3D 28 4C 6A 61 76 | success or wait | 704267679 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 8192 Value: 2F 6C 61 6E 67 2F 4F 62 6A 65 63 74 3B 29 56 01 00 31 28 4C 6A 61 76 61 2F 69 6F 2F 49 6E 70 75 74 53 74 72 65 61 6D 3B 4C 6F 72 67 2F 78 6D 6C 2F 73 61 78 2F 48 61 6E 64 6C 65 72 42 61 73 65 3B 29 56 01 00 48 28 4C 6A 61 76 61 2F 69 6F 2F 49 6E 70 75 74 53 74 72 65 61 6D 3B 4C 6A 61 76 61 2F 6C 61 | success or wait | 704277845 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 8192 Value: 62 65 61 6E 73 2F 62 65 61 6E 63 6F 6E 74 65 78 74 2F 42 65 61 6E 43 6F 6E 74 65 78 74 53 65 72 76 69 63 65 73 01 00 31 6A 61 76 61 2F 62 65 61 6E 73 2F 62 65 61 6E 63 6F 6E 74 65 78 74 2F 42 65 61 6E 43 6F 6E 74 65 78 74 53 65 72 76 69 63 65 73 53 75 70 70 6F 72 74 01 00 3B 6A 61 76 61 2F 62 65 61 | success or wait | 704286885 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 8192 Value: 04 73 69 7A 65 01 00 0F 77 72 69 74 65 45 78 70 72 65 73 73 69 6F 6E 07 00 14 07 00 15 07 00 16 07 00 17 07 00 18 07 00 19 07 00 1A 07 00 1B 07 00 1C 07 00 1D 01 00 20 28 29 4C 6A 61 76 61 2F 62 65 61 6E 73 2F 45 78 63 65 70 74 69 6F 6E 4C 69 73 74 65 6E 65 72 3B 01 00 1A 28 4C 6A 61 76 61 2F 62 65 | success or wait | 704293229 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 32768 Value: 01 00 1B 6A 61 76 61 2F 69 6F 2F 53 79 6E 63 46 61 69 6C 65 64 45 78 63 65 70 74 69 6F 6E 07 00 04 07 00 05 0C 00 02 00 01 0A 00 06 00 08 00 21 00 07 00 06 00 00 00 00 00 01 00 01 00 02 00 01 00 01 00 03 00 00 00 12 00 02 00 02 00 00 00 06 2A 2B B7 00 09 B1 00 00 00 00 00 00 50 4B 03 04 0A 00 00 00 | success or wait | 704297281 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 16384 Value: 4E 49 4E 47 5F 43 4C 41 53 53 5F 41 42 4F 56 45 01 00 04 43 6F 64 65 01 00 0D 43 6F 6E 73 74 61 6E 74 56 61 6C 75 65 01 00 05 45 6E 74 72 79 01 00 0B 46 49 4E 41 4C 5F 43 41 53 45 44 01 00 01 49 01 00 0C 49 6E 6E 65 72 43 6C 61 73 73 65 73 01 00 0A 4D 4F 52 45 5F 41 42 4F 56 45 01 00 0E 4E 4F 54 5F | success or wait | 704314032 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 32768 Value: 0C 00 1B 00 01 0C 00 1D 00 01 0C 00 07 00 02 0C 00 07 00 04 0C 00 07 00 05 0C 00 07 00 06 0C 00 18 00 23 0C 00 0F 00 24 09 00 21 00 29 09 00 21 00 2A 09 00 21 00 2B 0A 00 1F 00 35 0A 00 20 00 32 0A 00 20 00 33 0A 00 20 00 34 0A 00 21 00 2C 0A 00 21 00 2D 0A 00 21 00 2E 0A 00 21 00 2F 0A 00 21 00 30 | success or wait | 704322931 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 65536 Value: BD 00 2A B5 00 3F 2C 03 2A B4 00 3F 03 2C BE B8 00 45 B1 00 00 00 00 00 01 00 13 00 02 00 01 00 06 00 00 00 11 00 01 00 01 00 00 00 05 2A B4 00 3E B0 00 00 00 00 00 01 00 12 00 31 00 01 00 06 00 00 00 1A 00 01 00 01 00 00 00 0E 2A B4 00 3F B6 00 40 C0 00 24 C0 00 24 B0 00 00 00 00 00 01 00 11 00 04 | success or wait | 704341447 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 12288 Value: 00 02 00 01 00 00 00 19 2A B4 00 2A C6 00 10 2A B4 00 2A 2A B4 00 29 B9 00 2D 02 00 2A B4 00 29 B0 00 00 00 00 00 05 00 00 00 04 00 01 00 1C 00 02 00 15 00 20 00 02 00 03 00 00 00 25 00 02 00 02 00 00 00 19 2A B4 00 2A C6 00 10 2A B4 00 2A 2A B4 00 29 B9 00 2D 02 00 2B B6 00 2B B1 00 00 00 00 00 05 | success or wait | 704369124 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 28672 Value: 75 72 69 74 79 2F 4B 65 79 53 74 6F 72 65 24 50 72 6F 74 65 63 74 69 6F 6E 50 61 72 61 6D 65 74 65 72 3B 01 00 2E 28 29 4C 6A 61 76 61 2F 73 65 63 75 72 69 74 79 2F 4B 65 79 53 74 6F 72 65 24 50 72 6F 74 65 63 74 69 6F 6E 50 61 72 61 6D 65 74 65 72 3B 01 00 2F 28 4C 6A 61 76 61 2F 73 65 63 75 72 69 | success or wait | 704377596 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 65536 Value: 01 00 00 00 05 2A B4 01 06 B0 00 00 00 00 00 01 00 8C 00 1F 00 01 00 2D 00 00 01 07 00 03 00 03 00 00 00 FB BB 00 98 59 B7 01 14 4C 2B 12 11 B6 01 16 57 2A B4 01 08 C6 00 40 2B 12 04 B6 01 16 57 2A B4 01 08 B6 01 2E 4D 2C B9 01 3D 01 00 99 00 28 2B BB 00 99 59 B7 01 17 12 02 B6 01 1A 2C B9 01 3E 01 | success or wait | 704395601 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 24576 Value: 40 00 01 00 44 00 05 00 19 00 0F 00 0D 00 01 00 0B 00 00 00 02 00 3B 00 19 00 11 00 0D 00 01 00 0B 00 00 00 02 00 3C 00 19 00 10 00 0D 00 01 00 0B 00 00 00 02 00 3D 00 19 00 12 00 0D 00 01 00 0B 00 00 00 02 00 3E 00 19 00 13 00 0D 00 01 00 0B 00 00 00 02 00 3F 00 2F 04 01 00 1C 00 4D 00 01 00 0C 00 | success or wait | 704429067 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 8192 Value: 2F 53 74 72 69 6E 67 01 00 25 6A 61 76 61 2F 74 65 78 74 2F 41 74 74 72 69 62 75 74 65 64 43 68 61 72 61 63 74 65 72 49 74 65 72 61 74 6F 72 01 00 2F 6A 61 76 61 2F 74 65 78 74 2F 41 74 74 72 69 62 75 74 65 64 43 68 61 72 61 63 74 65 72 49 74 65 72 61 74 6F 72 24 41 74 74 72 69 62 75 74 65 01 00 1A | success or wait | 704440776 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 40960 Value: 66 6F 72 6D 61 74 20 61 72 72 61 79 73 20 6F 66 20 64 69 66 66 65 72 65 6E 74 20 6C 65 6E 67 74 68 2E 01 00 10 6C 6F 6E 67 42 69 74 73 54 6F 44 6F 75 62 6C 65 01 00 0A 6E 65 78 74 44 6F 75 62 6C 65 01 00 05 70 61 72 73 65 01 00 0E 70 72 65 76 69 6F 75 73 44 6F 75 62 6C 65 01 00 0A 72 65 61 64 4F 62 | success or wait | 704445955 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 20480 Value: 54 79 70 65 01 00 07 68 61 73 4E 65 78 74 01 00 08 68 61 73 68 43 6F 64 65 01 00 07 69 73 45 6D 70 74 79 01 00 0A 69 73 49 6E 73 74 61 6E 63 65 01 00 08 69 74 65 72 61 74 6F 72 01 00 0F 6A 61 76 61 2F 6C 61 6E 67 2F 43 6C 61 73 73 01 00 10 6A 61 76 61 2F 6C 61 6E 67 2F 4F 62 6A 65 63 74 01 00 10 6A | success or wait | 704465484 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 12288 Value: 7A 61 62 6C 65 3B 4C 6A 61 76 61 2F 6C 61 6E 67 2F 43 6C 6F 6E 65 61 62 6C 65 3B 01 00 1E 28 4C 6A 61 76 61 2F 69 6F 2F 4F 62 6A 65 63 74 49 6E 70 75 74 53 74 72 65 61 6D 3B 29 56 01 00 1F 28 4C 6A 61 76 61 2F 69 6F 2F 4F 62 6A 65 63 74 4F 75 74 70 75 74 53 74 72 65 61 6D 3B 29 56 01 00 13 28 29 4C | success or wait | 704714907 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 40960 Value: 0C 00 A3 01 50 0C 00 64 01 51 0C 00 65 01 51 0C 00 66 01 51 0C 00 E4 01 51 0C 00 E9 01 51 0C 00 EC 01 51 0C 00 E3 01 52 0C 00 80 01 53 0C 00 98 01 53 0C 00 AD 01 53 0C 00 82 01 54 0C 00 8C 01 54 0C 00 A5 01 54 0C 00 AE 01 54 0C 00 D9 01 55 0C 00 7D 01 56 0C 00 87 01 57 0C 00 89 01 58 0C 00 90 01 59 | success or wait | 704722311 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 65536 Value: 3B 01 00 1A 4C 6A 61 76 61 2F 75 74 69 6C 2F 54 72 65 65 4D 61 70 24 4B 65 79 53 65 74 3B 01 00 1F 4C 6A 61 76 61 2F 75 74 69 6C 2F 54 72 65 65 4D 61 70 24 4B 65 79 53 65 74 3C 54 4B 3B 3E 3B 01 00 38 4C 6A 61 76 61 2F 75 74 69 6C 2F 54 72 65 65 4D 61 70 24 4E 61 76 69 67 61 62 6C 65 53 75 62 4D 61 | success or wait | 704742235 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 12288 Value: 28 28 5B 4C 6A 61 76 61 2F 6C 61 6E 67 2F 4F 62 6A 65 63 74 3B 29 5B 4C 6A 61 76 61 2F 6C 61 6E 67 2F 4F 62 6A 65 63 74 3B 01 00 2C 28 4C 6A 61 76 61 2F 6C 61 6E 67 2F 54 68 72 6F 77 61 62 6C 65 3B 29 4C 6A 61 76 61 2F 6C 61 6E 67 2F 54 68 72 6F 77 61 62 6C 65 3B 01 00 2D 28 4C 6A 61 76 61 2F 6C 61 | success or wait | 704775252 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 65536 Value: 03 00 06 00 00 00 99 2A B4 01 27 99 00 16 1C 05 7E 9A 00 0A 1C 05 80 3D A7 00 09 1C 05 02 82 7E 3D 2A 2B B7 01 4D 99 00 1D 1C 05 7E 9A 00 15 2A B7 01 55 4E 2A 2D B7 01 56 99 00 08 2D B4 01 24 B0 01 B0 2A 2B B7 01 4C 99 00 26 1C 05 7E 99 00 1E 2A B7 01 54 4E 2D C6 00 15 2D B4 01 24 3A 04 2A 19 04 B7 | success or wait | 704782617 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 4096 Value: 00 9D 2A 10 20 BD 00 51 B5 00 96 2A BB 00 54 59 B7 00 B6 B5 00 97 B1 00 00 00 00 00 01 00 26 00 62 00 03 00 11 00 00 00 42 00 05 00 03 00 00 00 36 B8 00 A2 9A 00 2B 2A 2B C7 00 09 B2 00 95 A7 00 04 2B 03 09 B7 00 A7 4D 2C B2 00 95 A6 00 05 01 B0 2C B2 00 94 A5 00 05 2C B0 B8 00 A2 57 BB 00 48 59 B7 | success or wait | 704827944 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 40960 Value: 6C 2F 63 6F 6E 63 75 72 72 65 6E 74 2F 45 78 65 63 75 74 6F 72 73 24 52 75 6E 6E 61 62 6C 65 41 64 61 70 74 65 72 01 00 28 6A 61 76 61 2F 75 74 69 6C 2F 63 6F 6E 63 75 72 72 65 6E 74 2F 4C 69 6E 6B 65 64 42 6C 6F 63 6B 69 6E 67 51 75 65 75 65 01 00 30 6A 61 76 61 2F 75 74 69 6C 2F 63 6F 6E 63 75 72 | success or wait | 704833728 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 65536 Value: 01 00 06 28 54 54 3B 29 56 01 00 07 28 54 54 3B 49 29 56 01 00 08 28 54 54 3B 49 49 29 5A 01 00 08 3C 63 6C 69 6E 69 74 3E 01 00 06 3C 69 6E 69 74 3E 01 00 06 43 6C 61 73 73 20 01 00 04 43 6F 64 65 01 00 0C 49 6E 6E 65 72 43 6C 61 73 73 65 73 01 00 01 4A 01 00 11 4C 6A 61 76 61 2F 6C 61 6E 67 2F 43 | success or wait | 704855959 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 4096 Value: 66 6C 75 73 68 01 00 13 6A 61 76 61 2F 69 6F 2F 49 4F 45 78 63 65 70 74 69 6F 6E 01 00 14 6A 61 76 61 2F 69 6F 2F 4F 75 74 70 75 74 53 74 72 65 61 6D 01 00 1D 6A 61 76 61 2F 75 74 69 6C 2F 6C 6F 67 67 69 6E 67 2F 46 69 6C 65 48 61 6E 64 6C 65 72 01 00 2B 6A 61 76 61 2F 75 74 69 6C 2F 6C 6F 67 67 69 | success or wait | 704889027 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 4096 Value: 61 76 61 2F 75 74 69 6C 2F 44 61 74 65 01 00 18 6A 61 76 61 2F 75 74 69 6C 2F 52 65 73 6F 75 72 63 65 42 75 6E 64 6C 65 01 00 1B 6A 61 76 61 2F 75 74 69 6C 2F 6C 6F 67 67 69 6E 67 2F 46 6F 72 6D 61 74 74 65 72 01 00 19 6A 61 76 61 2F 75 74 69 6C 2F 6C 6F 67 67 69 6E 67 2F 48 61 6E 64 6C 65 72 01 00 | success or wait | 704891173 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 20480 Value: 00 D6 00 01 00 33 00 00 00 A4 00 03 00 05 00 00 00 98 BB 00 B3 59 B7 01 2D 4D 2B C6 00 0B 2B B2 01 11 B6 01 26 4C 03 3E 1D 2A B4 01 13 BE A2 00 2D 2A B4 01 13 1D 32 C7 00 06 A7 00 1B 2A B4 01 13 1D 32 2B B6 01 1E 3A 04 19 04 C6 00 0A 2A 19 04 2C B7 01 37 84 03 01 A7 FF D0 03 3E 1D 2A B4 01 13 BE A2 | success or wait | 704893348 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 4096 Value: 00 62 00 01 00 1A 00 00 00 20 00 01 00 01 00 00 00 14 2A B4 00 89 C7 00 05 01 B0 2A B4 00 89 B6 00 90 C0 00 56 B0 00 00 00 00 00 01 00 40 00 15 00 01 00 1A 00 00 00 8E 00 03 00 05 00 00 00 82 1B 9D 00 0D BB 00 57 59 12 0C B7 00 91 BF 1C 9D 00 0D BB 00 57 59 12 0D B7 00 91 BF 1D 9B 00 08 1D 1B A1 00 | success or wait | 704904170 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 65536 Value: 6E 67 2F 53 74 72 69 6E 67 3B 5B 4C 6A 61 76 61 2F 6C 61 6E 67 2F 53 74 72 69 6E 67 3B 4C 6A 61 76 61 2F 6C 61 6E 67 2F 53 74 72 69 6E 67 3B 5A 4C 6A 61 76 61 2F 6C 61 6E 67 2F 53 74 72 69 6E 67 3B 4C 6A 61 76 61 2F 6C 61 6E 67 2F 53 74 72 69 6E 67 3B 5B 4C 6A 61 76 61 2F 6C 61 6E 67 2F 53 74 72 69 | success or wait | 704907718 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 65536 Value: 07 69 73 43 6C 61 73 73 01 00 07 69 73 46 69 65 6C 64 01 00 0B 69 73 49 6E 74 65 72 66 61 63 65 01 00 0E 6A 61 76 61 2F 6C 61 6E 67 2F 45 6E 75 6D 01 00 24 6A 61 76 61 78 2F 6C 61 6E 67 2F 6D 6F 64 65 6C 2F 65 6C 65 6D 65 6E 74 2F 45 6C 65 6D 65 6E 74 4B 69 6E 64 01 00 07 76 61 6C 75 65 4F 66 01 00 | success or wait | 704946148 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 49152 Value: 08 18 0C 98 9D 00 07 04 A7 00 04 03 AC 2C C0 00 3A B6 00 5B 3A 05 2D C0 00 3A B6 00 5B 3A 06 19 04 C0 00 3A B6 00 5B 3A 07 19 06 19 05 B6 00 52 9D 00 11 19 05 19 07 B6 00 52 9D 00 07 04 A7 00 04 03 AC 00 00 00 00 00 12 00 00 00 0A 00 04 00 34 00 33 00 32 00 36 00 01 00 2D 00 08 00 01 00 10 00 00 00 | success or wait | 704995657 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 24576 Value: 78 2F 6D 61 6E 61 67 65 6D 65 6E 74 2F 4D 42 65 61 6E 53 65 72 76 65 72 3B 4C 6A 61 76 61 78 2F 6D 61 6E 61 67 65 6D 65 6E 74 2F 4D 42 65 61 6E 53 65 72 76 65 72 44 65 6C 65 67 61 74 65 3B 5A 29 4C 6A 61 76 61 78 2F 6D 61 6E 61 67 65 6D 65 6E 74 2F 4D 42 65 61 6E 53 65 72 76 65 72 3B 0C 00 02 00 01 | success or wait | 705608048 | 
| File read | Path: C:\Program Files\Java\jre6\lib\rt.jar Offset: unknown Length: 49152 Value: 72 69 62 75 74 65 4C 69 73 74 3B 01 00 3C 28 4C 6A 61 76 61 78 2F 6D 61 6E 61 67 65 6D 65 6E 74 2F 4D 42 65 61 6E 49 6E 66 6F 3B 5A 29 4C 6A 61 76 61 78 2F 6D 61 6E 61 67 65 6D 65 6E 74 2F 44 65 73 63 72 69 70 74 6F 72 3B 01 00 4E 28 4C 6A 61 76 61 78 2F 6D 61 6E 61 67 65 6D 65 6E 74 2F 49 6D 6D 75 | success or wait | 705641245 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\security\blacklist Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 712437633 | 
| File read | Path: C:\Program Files\Java\jre6\lib\security\blacklist Offset: unknown Length: 92 Value: 23 20 4A 4E 4C 50 41 70 70 6C 65 74 4C 61 75 6E 63 68 65 72 20 61 70 70 6C 65 74 2D 6C 61 75 6E 63 68 65 72 2E 6A 61 72 0A 53 48 41 31 2D 44 69 67 65 73 74 2D 4D 61 6E 69 66 65 73 74 3A 20 35 42 6F 35 2F 65 67 38 39 32 68 51 39 6D 67 62 55 57 35 36 69 44 6D 73 70 31 6B 3D 0A | success or wait | 712438701 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\security\java.policy Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 712440009 | 
| File read | Path: C:\Program Files\Java\jre6\lib\security\java.policy Offset: unknown Length: 2253 Value: 0A 2F 2F 20 53 74 61 6E 64 61 72 64 20 65 78 74 65 6E 73 69 6F 6E 73 20 67 65 74 20 61 6C 6C 20 70 65 72 6D 69 73 73 69 6F 6E 73 20 62 79 20 64 65 66 61 75 6C 74 0A 0A 67 72 61 6E 74 20 63 6F 64 65 42 61 73 65 20 22 66 69 6C 65 3A 24 7B 7B 6A 61 76 61 2E 65 78 74 2E 64 69 72 73 7D 7D 2F 2A 22 20 7B | success or wait | 712441817 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\security\java.security Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 712445036 | 
| File read | Path: C:\Program Files\Java\jre6\lib\security\java.security Offset: unknown Length: 9979 Value: 23 0A 23 20 54 68 69 73 20 69 73 20 74 68 65 20 22 6D 61 73 74 65 72 20 73 65 63 75 72 69 74 79 20 70 72 6F 70 65 72 74 69 65 73 20 66 69 6C 65 22 2E 0A 23 0A 23 20 49 6E 20 74 68 69 73 20 66 69 6C 65 2C 20 76 61 72 69 6F 75 73 20 73 65 63 75 72 69 74 79 20 70 72 6F 70 65 72 74 69 65 73 20 61 72 65 | success or wait | 712445725 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\security\javaws.policy Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 712452385 | 
| File read | Path: C:\Program Files\Java\jre6\lib\security\javaws.policy Offset: unknown Length: 109 Value: 2F 2F 20 25 57 25 20 25 45 25 0A 0A 67 72 61 6E 74 20 63 6F 64 65 42 61 73 65 20 22 66 69 6C 65 3A 24 7B 6A 6E 6C 70 78 2E 68 6F 6D 65 7D 2F 6A 61 76 61 77 73 2E 6A 61 72 22 20 7B 0A 20 20 20 20 70 65 72 6D 69 73 73 69 6F 6E 20 6A 61 76 61 2E 73 65 63 75 72 69 74 79 2E 41 6C 6C 50 65 72 6D 69 73 73 | success or wait | 712454305 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\tzmappings Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 712455353 | 
| File read | Path: C:\Program Files\Java\jre6\lib\tzmappings Offset: unknown Length: 7961 Value: 23 0A 23 20 25 57 25 20 25 45 25 0A 23 20 0A 23 20 54 68 69 73 20 66 69 6C 65 20 64 65 73 63 72 69 62 65 73 20 6D 61 70 70 69 6E 67 20 69 6E 66 6F 72 6D 61 74 69 6F 6E 20 62 65 74 77 65 65 6E 20 57 69 6E 64 6F 77 73 20 61 6E 64 20 4A 61 76 61 0A 23 20 74 69 6D 65 20 7A 6F 6E 65 73 2E 0A 23 20 46 6F | success or wait | 712457253 | 
| File opened | Path: C:\Program Files\Java\jre6\lib\zi\gmt Access: read attributes and synchronize and generic read Options: sequential only and synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 712463584 | 
| File read | Path: C:\Program Files\Java\jre6\lib\zi\GMT Offset: unknown Length: 27 Value: 6A 61 76 61 7A 69 00 01 01 00 04 00 00 00 00 02 00 02 00 00 03 00 04 00 00 00 00 | success or wait | 712464402 | 
| File opened | Path: C:\Program Files\Java\jre6\bin\awt.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 712467144 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\awt.dll Access: write and read and execute Type: commit Baseaddress: 10F0000 Size: 1208320 Protection: execute Mapped to pid: own pid | success or wait | 712468905 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\awt.dll Access: query and write and read and execute Type: image Baseaddress: 6D000000 Size: 1351680 Protection: read write Mapped to pid: own pid | success or wait | 712473487 | 
| Process information queried | PID: 400 Info Class: BasicInformation | success or wait | 712477173 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 712484510 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 712485118 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 712489187 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 712499387 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 712499559 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 712508767 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 712508938 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 712552163 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 712552775 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 712555483 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 712564502 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 712564672 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 712882761 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 712883703 | 
| File opened | Path: C:\Program Files\Java\jre6\bin\client\jvm.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 712923486 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\client\jvm.dll Access: write and read and execute Type: commit Baseaddress: 18B0000 Size: 2695168 Protection: execute Mapped to pid: own pid | success or wait | 712924989 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\client\jvm.dll Access: query and write and read and execute Type: image Baseaddress: 6D7F0000 Size: 2777088 Protection: read write Mapped to pid: own pid | success or wait | 712926696 | 
| Process information queried | PID: 400 Info Class: BasicInformation | success or wait | 712927302 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 712932667 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 712933261 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 712936286 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 712947404 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 712947573 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 712956218 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 712956387 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 713017096 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 713017804 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 713020885 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713029531 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713029703 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713039068 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713039237 | 
| File opened | Path: C:\Program Files\Java\jre6\bin\dcpr.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 713049747 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\dcpr.dll Access: write and read and execute Type: commit Baseaddress: 10F0000 Size: 143360 Protection: execute Mapped to pid: own pid | success or wait | 713051067 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\dcpr.dll Access: query and write and read and execute Type: image Baseaddress: 6D1A0000 Size: 143360 Protection: read write Mapped to pid: own pid | success or wait | 713052700 | 
| Process information queried | PID: 400 Info Class: BasicInformation | success or wait | 713053262 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 713058668 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 713059260 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 713061819 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713071150 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713071319 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713080585 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713080756 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 713103514 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 713104109 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 713106630 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713115493 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713115656 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713124135 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713124299 | 
| File opened | Path: C:\Program Files\Java\jre6\bin\deploy.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 713133945 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\deploy.dll Access: write and read and execute Type: commit Baseaddress: 10F0000 Size: 77824 Protection: execute Mapped to pid: own pid | success or wait | 713134769 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\deploy.dll Access: query and write and read and execute Type: image Baseaddress: 6D1D0000 Size: 77824 Protection: read write Mapped to pid: own pid | success or wait | 713136427 | 
| Process information queried | PID: 400 Info Class: BasicInformation | success or wait | 713137014 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 713142658 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 713143251 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 713145813 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713155542 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713155712 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713164610 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713164779 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 713179572 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 713180172 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 713182702 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713191496 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713191658 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713209856 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713210033 | 
| File opened | Path: C:\Program Files\Java\jre6\bin\fontmanager.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 713219645 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\fontmanager.dll Access: write and read and execute Type: commit Baseaddress: 10F0000 Size: 323584 Protection: execute Mapped to pid: own pid | success or wait | 713221603 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\fontmanager.dll Access: query and write and read and execute Type: image Baseaddress: 6D230000 Size: 323584 Protection: read write Mapped to pid: own pid | success or wait | 713223406 | 
| Process information queried | PID: 400 Info Class: BasicInformation | success or wait | 713223990 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 713229406 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 713229998 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 713232592 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713241946 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713242116 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713251111 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713251280 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 713271292 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 713271878 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 713274461 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713282938 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713283101 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713292261 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713292423 | 
| File opened | Path: C:\Program Files\Java\jre6\bin\hpi.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 713302099 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\hpi.dll Access: write and read and execute Type: commit Baseaddress: 10F0000 Size: 16384 Protection: execute Mapped to pid: own pid | success or wait | 713303552 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\hpi.dll Access: query and write and read and execute Type: image Baseaddress: 6D280000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 713305154 | 
| Process information queried | PID: 400 Info Class: BasicInformation | success or wait | 713305731 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 713311258 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 713311853 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 713314479 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713323909 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713324080 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713333382 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713333552 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 713346147 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 713346747 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 713349349 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713357763 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713357926 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713367243 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713367405 | 
| File opened | Path: C:\Program Files\Java\jre6\bin\java.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 713377163 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\java.dll Access: write and read and execute Type: commit Baseaddress: 10F0000 Size: 126976 Protection: execute Mapped to pid: own pid | success or wait | 713378634 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\java.dll Access: query and write and read and execute Type: image Baseaddress: 6D320000 Size: 126976 Protection: read write Mapped to pid: own pid | success or wait | 713380347 | 
| Process information queried | PID: 400 Info Class: BasicInformation | success or wait | 713380928 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 713386315 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 713386905 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 713389580 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713399272 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713399449 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713408436 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713408606 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 713423971 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 713424556 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 713427187 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713436209 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713436373 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713445258 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713445421 | 
| File opened | Path: C:\Program Files\Java\jre6\bin\javaw.exe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 713455061 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\javaw.exe Access: write and read and execute Type: commit Baseaddress: 10F0000 Size: 147456 Protection: execute Mapped to pid: own pid | success or wait | 713455854 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\javaw.exe Access: query and write and read and execute Type: image Baseaddress: 10F0000 Size: 147456 Protection: read write Mapped to pid: own pid | conflicting addresses | 713457549 | 
| Process information queried | PID: 400 Info Class: BasicInformation | success or wait | 713458912 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 713464385 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 713464980 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 713467576 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713476628 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713476684 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713485742 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713485911 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 713501690 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 713502284 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 713504871 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713513683 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713513847 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713522728 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713522891 | 
| File opened | Path: C:\Program Files\Java\jre6\bin\jp2native.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 713532602 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\jp2native.dll Access: write and read and execute Type: commit Baseaddress: 10F0000 Size: 8192 Protection: execute Mapped to pid: own pid | success or wait | 713534493 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\jp2native.dll Access: query and write and read and execute Type: image Baseaddress: 6D420000 Size: 24576 Protection: read write Mapped to pid: own pid | success or wait | 713536134 | 
| Process information queried | PID: 400 Info Class: BasicInformation | success or wait | 713536712 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 713542435 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 713543044 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 713545680 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713555067 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713555238 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713564143 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713564312 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 713576757 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 713577374 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 713580228 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713588799 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713588964 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713597854 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713598017 | 
| File opened | Path: C:\Program Files\Java\jre6\bin\jpeg.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 713607724 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\jpeg.dll Access: write and read and execute Type: commit Baseaddress: 10F0000 Size: 151552 Protection: execute Mapped to pid: own pid | success or wait | 713608514 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\jpeg.dll Access: query and write and read and execute Type: image Baseaddress: 6D440000 Size: 151552 Protection: read write Mapped to pid: own pid | success or wait | 713610248 | 
| Process information queried | PID: 400 Info Class: BasicInformation | success or wait | 713610829 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 713616560 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 713617189 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 713619789 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713629221 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713629391 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713638296 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713638466 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 713653498 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 713654081 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 713656587 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713664964 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713665127 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713673731 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 713673894 | 
| File opened | Path: C:\Program Files\Java\jre6\bin\msvcr71.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 713957156 | 
| Process information queried | PID: 400 Info Class: BasicInformation | success or wait | 713957559 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 713959686 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 713960289 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 713963031 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 713972145 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 714400413 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 714448015 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 714448455 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 714497700 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 714499299 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 714505807 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 714528661 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 714529085 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 714552984 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 714553408 | 
| File opened | Path: C:\Program Files\Java\jre6\bin\net.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 714578333 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\net.dll Access: write and read and execute Type: commit Baseaddress: 10F0000 Size: 77824 Protection: execute Mapped to pid: own pid | success or wait | 714582144 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\net.dll Access: query and write and read and execute Type: image Baseaddress: 6D600000 Size: 77824 Protection: read write Mapped to pid: own pid | success or wait | 714586046 | 
| Process information queried | PID: 400 Info Class: BasicInformation | success or wait | 714587665 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 714602069 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 714603571 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 714610392 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 714634647 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 714635088 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1908558 | success or wait | 714658389 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1226fe1 | success or wait | 714658829 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 714693899 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 714695422 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 714702342 | 
| File opened | Path: C:\Program Files\Java\jre6\bin\nio.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 714777408 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\nio.dll Access: write and read and execute Type: commit Baseaddress: 10F0000 Size: 20480 Protection: execute Mapped to pid: own pid | success or wait | 714779399 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\nio.dll Access: query and write and read and execute Type: image Baseaddress: 6D620000 Size: 36864 Protection: read write Mapped to pid: own pid | success or wait | 714783253 | 
| Process information queried | PID: 400 Info Class: BasicInformation | success or wait | 714784712 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 714801741 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 714803293 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 714809972 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 714907351 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 714908829 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 714916067 | 
| File opened | Path: C:\Program Files\Java\jre6\bin\regutils.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 714987876 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\regutils.dll Access: write and read and execute Type: commit Baseaddress: 10F0000 Size: 278528 Protection: execute Mapped to pid: own pid | success or wait | 714991350 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\regutils.dll Access: query and write and read and execute Type: image Baseaddress: 6D6A0000 Size: 286720 Protection: read write Mapped to pid: own pid | success or wait | 714995327 | 
| Process information queried | PID: 400 Info Class: BasicInformation | success or wait | 714996832 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 715011181 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 715012778 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 715019464 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 715111199 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 715112678 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 715119557 | 
| File opened | Path: C:\Program Files\Java\jre6\bin\verify.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 715191888 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\verify.dll Access: write and read and execute Type: commit Baseaddress: 10F0000 Size: 32768 Protection: execute Mapped to pid: own pid | success or wait | 715195436 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\verify.dll Access: query and write and read and execute Type: image Baseaddress: 6D7A0000 Size: 49152 Protection: read write Mapped to pid: own pid | success or wait | 715199416 | 
| Process information queried | PID: 400 Info Class: BasicInformation | success or wait | 715200878 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 715215173 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 715216672 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 715223337 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 715303820 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 715305293 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 715311840 | 
| File opened | Path: C:\Program Files\Java\jre6\bin\zip.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 715386983 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\zip.dll Access: write and read and execute Type: commit Baseaddress: 10F0000 Size: 49152 Protection: execute Mapped to pid: own pid | success or wait | 715389004 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\zip.dll Access: query and write and read and execute Type: image Baseaddress: 6D7E0000 Size: 61440 Protection: read write Mapped to pid: own pid | success or wait | 715392912 | 
| Process information queried | PID: 400 Info Class: BasicInformation | success or wait | 715394507 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 715411311 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 715412819 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 715419475 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 715520098 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 715521572 | 
| Process information queried | PID: 400 Info Class: Wow64Information | success or wait | 715528161 | 
| Thread created | PID: 400 TID: 3904 EIP: 7C8106F9 Imagepath: C:\Program Files\Java\jre6\bin\jqs.exe | success or wait | 788202396 | 
| Thread resumed | TID: 3904 PID: 400 Path: C:\Program Files\Java\jre6\bin\jqs.exe | success or wait | 788206100 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | success or wait | 788224649 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 788270228 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 788270900 | 
| Sections | ||||||||||||||||||||||||||||||||
| 
 | ||||||||||||||||||||||||||||||||
| Memory Activities: 
 | ||||||||||||||||||||||||||||||||
| System Activities: 
 | ||||||||||||||||||||||||||||||||
| User Activities: 
 | ||||||||||||||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| System info queried | Type: ProcessInformation | success or wait | 627558222 | 
| System info queried | Type: ProcessInformation | success or wait | 634391872 | 
| System info queried | Type: ProcessInformation | success or wait | 641610125 | 
| System info queried | Type: ProcessInformation | success or wait | 648769363 | 
| System info queried | Type: ProcessInformation | success or wait | 655924997 | 
| Message posted | TID: 1B4 Message: 401 WParam: 2116 LParam: 0 | success | 655931067 | 
| System info queried | Type: ProcessInformation | success or wait | 663476620 | 
| System info queried | Type: ProcessInformation | info length mismatch | 670242784 | 
| Memory allocated | PID: 420 Path: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\MDM.EXE Base: 165000 Length: B6FBDC Allocation Type: unknown Protection: page read and write | success or wait | 670245075 | 
| System info queried | Type: ProcessInformation | success or wait | 670245231 | 
| Message posted | TID: 1B4 Message: 401 WParam: 2724 LParam: 0 | success | 670247666 | 
| System info queried | Type: ProcessInformation | success or wait | 677488252 | 
| System info queried | Type: ProcessInformation | success or wait | 684563256 | 
| System info queried | Type: ProcessInformation | success or wait | 692327443 | 
| System info queried | Type: ProcessInformation | success or wait | 698879800 | 
| System info queried | Type: ProcessInformation | success or wait | 706051038 | 
| System info queried | Type: ProcessInformation | success or wait | 713199313 | 
| System info queried | Type: ProcessInformation | success or wait | 720356637 | 
| System info queried | Type: ProcessInformation | success or wait | 727516040 | 
| System info queried | Type: ProcessInformation | success or wait | 734738591 | 
| System info queried | Type: ProcessInformation | success or wait | 741839149 | 
| System info queried | Type: ProcessInformation | success or wait | 748993376 | 
| System info queried | Type: ProcessInformation | success or wait | 756168388 | 
| System info queried | Type: ProcessInformation | success or wait | 763311507 | 
| System info queried | Type: ProcessInformation | success or wait | 770473485 | 
| System info queried | Type: ProcessInformation | success or wait | 777629665 | 
| System info queried | Type: ProcessInformation | success or wait | 784788804 | 
| System info queried | Type: ProcessInformation | success or wait | 791947842 | 
| System info queried | Type: ProcessInformation | success or wait | 799107008 | 
| Sections | ||||||||||||||||||||
| 
 | ||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Sections | ||||||||||||||||||||
| 
 | ||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Sections | ||||||||||||||||||||
| 
 | ||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Sections | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| File Activities: 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Section Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Mutant Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Process Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Thread Activities: 
 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Memory Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Mutant created | Name: \BaseNamedObjects\zXeRY3a_PtW|00000000 | success or wait | 796110066 | 
| Thread created | PID: 172 TID: 3972 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\wbem\wmiprvse.exe | success or wait | 796114863 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796120032 | 
| Section loaded | Path: \KnownDlls\CRYPT32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 796144187 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and write and read and execute Type: image Baseaddress: 77A80000 Size: 610304 Protection: read write Mapped to pid: own pid | success or wait | 796148341 | 
| Section loaded | Path: \KnownDlls\MSASN1.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 796168435 | 
| Section loaded | Path: C:\WINDOWS\system32\msasn1.dll Access: query and write and read and execute Type: image Baseaddress: 77B20000 Size: 73728 Protection: read write Mapped to pid: own pid | success or wait | 796170187 | 
| Section loaded | Path: \KnownDlls\WININET.dll Access: write and read and execute Type: unknown Baseaddress: 3D930000 Size: 942080 Protection: read write Mapped to pid: own pid | success or wait | 796204693 | 
| Section loaded | Path: \KnownDlls\Normaliz.dll Access: write and read and execute Type: unknown Baseaddress: C10000 Size: 36864 Protection: read write Mapped to pid: own pid | conflicting addresses | 796227257 | 
| Section loaded | Path: \KnownDlls\urlmon.dll Access: write and read and execute Type: unknown Baseaddress: 78130000 Size: 1257472 Protection: read write Mapped to pid: own pid | success or wait | 796250746 | 
| Section loaded | Path: \KnownDlls\iertutil.dll Access: write and read and execute Type: unknown Baseaddress: 3DFD0000 Size: 2002944 Protection: read write Mapped to pid: own pid | success or wait | 796261838 | 
| Section loaded | Path: \KnownDlls\MSIMG32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 796417663 | 
| Section loaded | Path: C:\WINDOWS\system32\msimg32.dll Access: query and write and read and execute Type: image Baseaddress: 76380000 Size: 20480 Protection: read write Mapped to pid: own pid | success or wait | 796419314 | 
| Thread created | PID: 172 TID: 3988 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\wbem\wmiprvse.exe | success or wait | 796427894 | 
| Thread delayed | Time: 0 TID: 3988 | success or wait | 796429722 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and write copy | success or wait | 796430535 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 796431558 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@197c457 | success or wait | 796432391 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 796432665 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@db38e1 | success or wait | 796434570 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 796434834 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 796435146 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7359f7 | success or wait | 796435745 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 796436003 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1176e8a | success or wait | 796436913 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: EC0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 796437257 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796442540 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BAFEA50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796442847 | 
| Thread created | PID: 172 TID: 3992 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\wbem\wmiprvse.exe | success or wait | 796444440 | 
| Thread created | PID: 172 TID: 3996 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\wbem\wmiprvse.exe | success or wait | 796447130 | 
| Process information queried | PID: 172 Info Class: Wow64Information | success or wait | 796449122 | 
| Process information queried | PID: 172 Info Class: Wow64Information | success or wait | 796449667 | 
| Thread delayed | Time: 0 TID: 3988 | success or wait | 796450174 | 
| Thread delayed | Time: 0 TID: 3988 | success or wait | 796450574 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796450766 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 796451773 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@197c457 | success or wait | 796452651 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 796452924 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@db38e1 | success or wait | 796453312 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 796453571 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 796453880 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7359f7 | success or wait | 796454477 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 796454736 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1176e8a | success or wait | 796455257 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: F40000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 796455596 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796458386 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BB186C0 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796458689 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796458997 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 796459984 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@197c457 | success or wait | 796460807 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 796461070 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@db38e1 | success or wait | 796461456 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 796461714 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 796462025 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7359f7 | success or wait | 796462620 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 796462878 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1176e8a | success or wait | 796463398 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: F40000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 796463738 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796466488 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BB06F28 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796466791 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796467100 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 796468163 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@197c457 | success or wait | 796468994 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 796469261 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@db38e1 | success or wait | 796469653 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 796469913 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 796470222 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7359f7 | success or wait | 796470829 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 796471088 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1176e8a | success or wait | 796471616 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: F40000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 796472116 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796474878 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BB04B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796475182 | 
| Process information queried | PID: 172 Info Class: Wow64Information | success or wait | 796475685 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796475947 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 796476937 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@197c457 | success or wait | 796477906 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 796478175 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@db38e1 | success or wait | 796478572 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 796478832 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 796479142 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7359f7 | success or wait | 796479749 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 796480009 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1176e8a | success or wait | 796480541 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: F40000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 796480794 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796483597 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BB17D98 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796483899 | 
| Section loaded | Path: \KnownDlls\nspr4.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 796484474 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 796486963 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 796487998 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 796508643 | 
| File opened | Path: C:\WINDOWS\system32\USER32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 796509698 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@15a4247 | success or wait | 796510569 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 4 Value: D8 00 00 00 | success or wait | 796510846 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b57646 | success or wait | 796512511 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 1B A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 796512784 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 F4 05 00 00 E2 02 00 00 00 00 00 17 B2 00 00 00 10 00 00 00 B0 05 00 00 00 41 7E 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 10 09 00 00 04 00 00 76 FC 08 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 39 00 00 | success or wait | 796513107 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1680bc6 | success or wait | 796513724 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 83 F2 05 00 00 10 00 00 00 F4 05 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 80 11 00 00 00 10 06 00 00 0C 00 00 00 F8 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 88 A0 02 00 00 30 06 00 00 A2 02 00 | success or wait | 796513993 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1dd2519 | success or wait | 796514532 | 
| Section loaded | Path: C:\WINDOWS\system32\user32.dll Access: query and read Type: commit Baseaddress: F40000 Size: 57344 Protection: readonly Mapped to pid: own pid | success or wait | 796514883 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796520573 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BB03E40 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796520886 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 796521287 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 796522314 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1aea0c1 | success or wait | 796523176 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 796523448 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1bbf341 | success or wait | 796525111 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 796525379 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 796525695 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f4e03 | success or wait | 796526310 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 796526575 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@fad969 | success or wait | 796527111 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: F40000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 796527457 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796533196 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BB189C8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796533976 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 796534377 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 796535406 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1aea0c1 | success or wait | 796536266 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 796536537 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1bbf341 | success or wait | 796536938 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 796537204 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 796537519 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f4e03 | success or wait | 796538133 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 796538398 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@fad969 | success or wait | 796538933 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: F40000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 796539277 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796543919 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BB18118 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796544217 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 796544669 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 796545705 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1aea0c1 | success or wait | 796546551 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 796546821 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1bbf341 | success or wait | 796547221 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 796547487 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 796547802 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f4e03 | success or wait | 796548412 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 796548679 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@fad969 | success or wait | 796549216 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: F40000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 796549562 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796552724 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BAFE1F8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796553052 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 796554829 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 796555939 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1aea0c1 | success or wait | 796556787 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 796557057 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1bbf341 | success or wait | 796557456 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 796557722 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 796558037 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f4e03 | success or wait | 796558647 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 796558915 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@fad969 | success or wait | 796559450 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: F40000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 796559796 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796564288 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BB07290 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796564586 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 796565492 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 796566491 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 796589244 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 796592607 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1aea0c1 | success or wait | 796593875 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 796594147 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1bbf341 | success or wait | 796595220 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 796595910 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 796596229 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f4e03 | success or wait | 796597475 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 796598162 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@fad969 | success or wait | 796598708 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: F40000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 796600196 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796603473 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BB07A10 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796603770 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 796604132 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 796605171 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1aea0c1 | success or wait | 796606018 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 796606287 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1bbf341 | success or wait | 796606690 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 796606956 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 796607270 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f4e03 | success or wait | 796607882 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 796608147 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@fad969 | success or wait | 796608684 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: F40000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 796609030 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796612277 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BB18B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796612584 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 796612944 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 796614121 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1aea0c1 | success or wait | 796614967 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 796615237 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1bbf341 | success or wait | 796615635 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 796615901 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 796616212 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f4e03 | success or wait | 796616823 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 796617087 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@fad969 | success or wait | 796617627 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: F40000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 796617970 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796622765 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BB05310 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796623072 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 796623356 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 796625219 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1aea0c1 | success or wait | 796626063 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 796626420 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1bbf341 | success or wait | 796626826 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 796627092 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 796627408 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f4e03 | success or wait | 796628019 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 796628284 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@fad969 | success or wait | 796628823 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: F40000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 796629169 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796634014 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BB18ED8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796634311 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 796634673 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 796635692 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1aea0c1 | success or wait | 796636538 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 796636807 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1bbf341 | success or wait | 796637207 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 796637473 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 796637786 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f4e03 | success or wait | 796638398 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 796638663 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@fad969 | success or wait | 796639201 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: F40000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 796639546 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796642783 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BB04D50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796643088 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 796643450 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 796644465 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1aea0c1 | success or wait | 796645174 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 796645646 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1bbf341 | success or wait | 796646419 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 796646685 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 796647000 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f4e03 | success or wait | 796647610 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 796647875 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@fad969 | success or wait | 796648411 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: F40000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 796648755 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796651994 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BB05538 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796652290 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 796652652 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 796653660 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1aea0c1 | success or wait | 796654500 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 796654770 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1bbf341 | success or wait | 796655169 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 796655434 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 796655747 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f4e03 | success or wait | 796656359 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 796656623 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@fad969 | success or wait | 796657159 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: F40000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 796657506 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796660689 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: BAFE698 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796661052 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 796661536 | 
| File opened | Path: C:\WINDOWS\system32\WS2_32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 796662634 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d7ad36 | success or wait | 796663480 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 796663749 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1acc826 | success or wait | 796665845 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 63 A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 796666116 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 22 01 00 00 1C 00 00 00 00 00 00 73 12 00 00 00 10 00 00 00 20 01 00 00 00 AB 71 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 70 01 00 00 04 00 00 20 F0 01 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 04 14 00 00 | success or wait | 796666432 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@8843f5 | success or wait | 796667045 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 53 21 01 00 00 10 00 00 00 22 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 14 09 00 00 00 40 01 00 00 0A 00 00 00 26 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 F8 03 00 00 00 50 01 00 00 04 00 00 | success or wait | 796667310 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@25997c | success or wait | 796667847 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and read Type: commit Baseaddress: F40000 Size: 20480 Protection: readonly Mapped to pid: own pid | success or wait | 796668190 | 
| Memory attributes changed | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 796674013 | 
| File opened | Path: C:\WINDOWS\system32\ADVAPI32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 796675725 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7f9e04 | success or wait | 796676586 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 796676855 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5f39b0 | success or wait | 796678971 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 48 1D 90 49 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 796679241 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 46 07 00 00 3E 02 00 00 00 00 00 0B 71 00 00 00 10 00 00 00 20 07 00 00 00 DD 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 B0 09 00 00 04 00 00 B8 5B 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 A4 16 00 00 | success or wait | 796679555 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1c49094 | success or wait | 796680165 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C9 45 07 00 00 10 00 00 00 46 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 28 46 00 00 00 60 07 00 00 2C 00 00 00 4A 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 80 A9 01 00 00 B0 07 00 00 AA 01 00 | success or wait | 796680430 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1efe574 | success or wait | 796680966 | 
| Section loaded | Path: C:\WINDOWS\system32\advapi32.dll Access: query and read Type: commit Baseaddress: F40000 Size: 28672 Protection: readonly Mapped to pid: own pid | success or wait | 796681079 | 
| File opened | Path: C:\WINDOWS\system32\CRYPT32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 796690991 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c12ad8 | success or wait | 796691849 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 796692119 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1e3f34c | success or wait | 796694008 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D7 A0 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 796694263 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 44 08 00 00 DC 00 00 00 00 00 00 32 16 00 00 00 10 00 00 00 20 08 00 00 00 A8 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 50 09 00 00 04 00 00 30 C5 09 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 9C 1A 00 00 | success or wait | 796694578 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7a39ea | success or wait | 796695191 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C4 43 08 00 00 10 00 00 00 44 08 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 E8 23 00 00 00 60 08 00 00 24 00 00 00 48 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 50 67 00 00 00 90 08 00 00 68 00 00 | success or wait | 796695492 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@7053be | success or wait | 796696031 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and read Type: commit Baseaddress: F40000 Size: 77824 Protection: readonly Mapped to pid: own pid | success or wait | 796696376 | 
| Mutant created | Name: \BaseNamedObjects\Global\ch971pGLCYGJFFTTU5XPPGQTZJ8OdYB | object name exists | 796703870 | 
| Thread created | PID: 172 TID: 4000 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\wbem\wmiprvse.exe | success or wait | 796705614 | 
| Thread resumed | TID: 4000 PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe | success or wait | 796706348 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | success or wait | 796707379 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 796707915 | 
| Thread terminated | TID: 3972 PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe | unknown | 796710498 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 796741684 | 
| Memory allocated | PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe Base: DC0000 Length: F7FF30 Allocation Type: unknown Protection: page execute and read and write | success or wait | 796775592 | 
| Thread created | PID: 172 TID: 4008 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\wbem\wmiprvse.exe | success or wait | 796777508 | 
| Thread resumed | TID: 4008 PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe | success or wait | 796778209 | 
| Process information queried | PID: 172 Info Class: Cookie | success or wait | 796779301 | 
| Process information queried | PID: 172 Info Class: Cookie | success or wait | 796779546 | 
| Thread created | PID: 172 TID: 4012 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\wbem\wmiprvse.exe | success or wait | 796782587 | 
| Thread resumed | TID: 4012 PID: 172 Path: C:\WINDOWS\system32\wbem\wmiprvse.exe | success or wait | 796783283 | 
| Thread delayed | Time: 0 TID: 3988 | success or wait | 797540974 | 
| Thread delayed | Time: 0 TID: 3988 | success or wait | 797541499 | 
| Thread delayed | Time: 0 TID: 3988 | success or wait | 797541999 | 
| Thread delayed | Time: 0 TID: 3988 | success or wait | 798659541 | 
| Thread delayed | Time: 0 TID: 3988 | success or wait | 798660084 | 
| Thread delayed | Time: 0 TID: 3988 | success or wait | 798660585 | 
| Thread delayed | Time: 0 TID: 3988 | success or wait | 799778140 | 
| Thread delayed | Time: 0 TID: 3988 | success or wait | 799778670 | 
| Thread delayed | Time: 0 TID: 3988 | success or wait | 799779170 | 
| Thread delayed | Time: 0 TID: 3988 | success or wait | 800896791 | 
| Thread delayed | Time: 0 TID: 3988 | success or wait | 800897310 | 
| Thread delayed | Time: 0 TID: 3988 | success or wait | 800897805 | 
| Thread delayed | Time: 0 TID: 3988 | success or wait | 802015399 | 
| Thread delayed | Time: 0 TID: 3988 | success or wait | 802015927 | 
| Thread delayed | Time: 0 TID: 3988 | success or wait | 802016429 | 
| Sections | ||||||||||||||||||||
| 
 | ||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Sections | ||||||||||||||||||||
| 
 | ||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Sections | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| File Activities: 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Section Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Mutant Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Process Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Thread Activities: 
 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Memory Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Mutant created | Name: \BaseNamedObjects\zXeRY3a_PtW|00000000 | success or wait | 709177808 | 
| Thread created | PID: 1452 TID: 2420 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\msiexec.exe | success or wait | 709180379 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 7C90CFEE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709182748 | 
| Section loaded | Path: \KnownDlls\WS2_32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 709184912 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and write and read and execute Type: image Baseaddress: 71AB0000 Size: 94208 Protection: read write Mapped to pid: own pid | success or wait | 709185513 | 
| Section loaded | Path: \KnownDlls\WS2HELP.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 709189836 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2help.dll Access: query and write and read and execute Type: image Baseaddress: 71AA0000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 709190451 | 
| Section loaded | Path: \KnownDlls\WININET.dll Access: write and read and execute Type: unknown Baseaddress: 3D930000 Size: 942080 Protection: read write Mapped to pid: own pid | success or wait | 709215714 | 
| Section loaded | Path: \KnownDlls\Normaliz.dll Access: write and read and execute Type: unknown Baseaddress: 990000 Size: 36864 Protection: read write Mapped to pid: own pid | conflicting addresses | 709218825 | 
| Section loaded | Path: \KnownDlls\urlmon.dll Access: write and read and execute Type: unknown Baseaddress: 78130000 Size: 1257472 Protection: read write Mapped to pid: own pid | success or wait | 709224306 | 
| Section loaded | Path: \KnownDlls\iertutil.dll Access: write and read and execute Type: unknown Baseaddress: 3DFD0000 Size: 2002944 Protection: read write Mapped to pid: own pid | success or wait | 709228594 | 
| Section loaded | Path: \KnownDlls\MSIMG32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 709297627 | 
| Section loaded | Path: C:\WINDOWS\system32\msimg32.dll Access: query and write and read and execute Type: image Baseaddress: 76380000 Size: 20480 Protection: read write Mapped to pid: own pid | success or wait | 709298146 | 
| Thread created | PID: 1452 TID: 2432 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\msiexec.exe | success or wait | 709303509 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 709304212 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and write copy | success or wait | 709304506 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 709304864 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ac6fb1 | success or wait | 709305178 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 709305272 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d8ced6 | success or wait | 709306390 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 709306500 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 709307256 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f3471d | success or wait | 709307912 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 709308006 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c1c2f1 | success or wait | 709309573 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 709309700 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709312531 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BAFEA50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709312639 | 
| Thread created | PID: 1452 TID: 2436 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\msiexec.exe | success or wait | 709313208 | 
| Thread created | PID: 1452 TID: 2440 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\msiexec.exe | success or wait | 709314234 | 
| Process information queried | PID: 1452 Info Class: Wow64Information | success or wait | 709314966 | 
| Process information queried | PID: 1452 Info Class: Wow64Information | success or wait | 709315167 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 709315368 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 709315514 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709315594 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 709315954 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ac6fb1 | success or wait | 709316336 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 709316434 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d8ced6 | success or wait | 709316849 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 709316941 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 709317052 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f3471d | success or wait | 709317265 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 709317357 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c1c2f1 | success or wait | 709317577 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 709317714 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709318741 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BB186C0 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709318847 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709318957 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 709319310 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ac6fb1 | success or wait | 709319613 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 709319707 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d8ced6 | success or wait | 709319846 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 709319938 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 709320048 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f3471d | success or wait | 709320301 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 709320393 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c1c2f1 | success or wait | 709320581 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 709320723 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709321716 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BB06F28 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709321822 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709321932 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 709322284 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ac6fb1 | success or wait | 709322591 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 709322686 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d8ced6 | success or wait | 709322827 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 709322920 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 709323030 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f3471d | success or wait | 709323247 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 709323339 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c1c2f1 | success or wait | 709323528 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 709323648 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709324638 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BB04B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709324744 | 
| Process information queried | PID: 1452 Info Class: Wow64Information | success or wait | 709324926 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709325019 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 709325371 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ac6fb1 | success or wait | 709325677 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 709325772 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d8ced6 | success or wait | 709325913 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 709326006 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 709326117 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f3471d | success or wait | 709326333 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 709326426 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c1c2f1 | success or wait | 709326615 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 709326736 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709327725 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BB17D98 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709327832 | 
| Section loaded | Path: \KnownDlls\nspr4.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 709328553 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 709329466 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 709329841 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 709339337 | 
| File opened | Path: C:\WINDOWS\system32\USER32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 709339709 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e589bd | success or wait | 709340030 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 4 Value: D8 00 00 00 | success or wait | 709340128 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b5e410 | success or wait | 709341018 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 1B A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 709341115 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 F4 05 00 00 E2 02 00 00 00 00 00 17 B2 00 00 00 10 00 00 00 B0 05 00 00 00 41 7E 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 10 09 00 00 04 00 00 76 FC 08 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 39 00 00 | success or wait | 709341230 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@8fd95d | success or wait | 709341452 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 83 F2 05 00 00 10 00 00 00 F4 05 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 80 11 00 00 00 10 06 00 00 0C 00 00 00 F8 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 88 A0 02 00 00 30 06 00 00 A2 02 00 | success or wait | 709341548 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@79e4c | success or wait | 709341741 | 
| Section loaded | Path: C:\WINDOWS\system32\user32.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 57344 Protection: readonly Mapped to pid: own pid | success or wait | 709341866 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709345954 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BB03E40 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709346063 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 709346206 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 709346571 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@29ae5e | success or wait | 709346889 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 709346985 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@76a9b6 | success or wait | 709349690 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 709349786 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 709349899 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@801919 | success or wait | 709350118 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 709350212 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1efe4ac | success or wait | 709350404 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 709350526 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709353757 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BB189C8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709353863 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 709354003 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 709354368 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@29ae5e | success or wait | 709354684 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 709354780 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@76a9b6 | success or wait | 709354924 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 709355019 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 709355131 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@801919 | success or wait | 709355350 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 709355444 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1efe4ac | success or wait | 709355636 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 709355759 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709358357 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BB18118 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709358463 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 709358603 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 709358966 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@29ae5e | success or wait | 709359280 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 709359377 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@76a9b6 | success or wait | 709359521 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 709359644 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 709359757 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@801919 | success or wait | 709359976 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 709360070 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1efe4ac | success or wait | 709360261 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 709360384 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709361559 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BAFE1F8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709361665 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 709362938 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 709363305 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@29ae5e | success or wait | 709363619 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 709363715 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@76a9b6 | success or wait | 709363859 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 709363954 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 709364066 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@801919 | success or wait | 709364285 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 709364379 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1efe4ac | success or wait | 709364571 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 709364694 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709366504 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BB07290 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709366611 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 709366943 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 709367315 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 709375947 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 709376319 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@29ae5e | success or wait | 709376637 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 709376734 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@76a9b6 | success or wait | 709376877 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 709376972 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 709377085 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@801919 | success or wait | 709377304 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 709377398 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1efe4ac | success or wait | 709377590 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 709377713 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709378944 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BB07A10 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709379071 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 709379199 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 709379565 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@29ae5e | success or wait | 709379876 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 709379973 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@76a9b6 | success or wait | 709380117 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 709380211 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 709380323 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@801919 | success or wait | 709380542 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 709380636 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1efe4ac | success or wait | 709380827 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 709380950 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709382118 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BB18B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709382228 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 709382356 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 709382720 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@29ae5e | success or wait | 709383030 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 709383126 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@76a9b6 | success or wait | 709383269 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 709383364 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 709383477 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@801919 | success or wait | 709383695 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 709383790 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1efe4ac | success or wait | 709383982 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 709384104 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709396039 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BB05310 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709396148 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 709396277 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 709396641 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@29ae5e | success or wait | 709396956 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 709397052 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@76a9b6 | success or wait | 709397195 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 709397289 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 709397402 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@801919 | success or wait | 709397620 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 709397714 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1efe4ac | success or wait | 709397905 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 709398027 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709399929 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BB18ED8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709400035 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 709400164 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 709400557 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@29ae5e | success or wait | 709400872 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 709400968 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@76a9b6 | success or wait | 709401112 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 709401206 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 709401318 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@801919 | success or wait | 709401538 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 709401633 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1efe4ac | success or wait | 709401825 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 709401948 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709403117 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BB04D50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709403227 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 709403357 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 709403718 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@29ae5e | success or wait | 709404027 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 709404124 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@76a9b6 | success or wait | 709404267 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 709404361 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 709404474 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@801919 | success or wait | 709404693 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 709404788 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1efe4ac | success or wait | 709404979 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 709405103 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709406268 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BB05538 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709406374 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 709406504 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 709406864 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@29ae5e | success or wait | 709407174 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 709407271 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@76a9b6 | success or wait | 709407414 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 709407509 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 709407622 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@801919 | success or wait | 709407841 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 709407936 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1efe4ac | success or wait | 709408128 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 709408252 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709409418 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: BAFE698 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709409524 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 709409735 | 
| File opened | Path: C:\WINDOWS\system32\WS2_32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 709410109 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@8e13ab | success or wait | 709410421 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 709410518 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ad44f6 | success or wait | 709411613 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 63 A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 709412374 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 22 01 00 00 1C 00 00 00 00 00 00 73 12 00 00 00 10 00 00 00 20 01 00 00 00 AB 71 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 70 01 00 00 04 00 00 20 F0 01 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 04 14 00 00 | success or wait | 709412509 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@8aaed5 | success or wait | 709413189 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 53 21 01 00 00 10 00 00 00 22 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 14 09 00 00 00 40 01 00 00 0A 00 00 00 26 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 F8 03 00 00 00 50 01 00 00 04 00 00 | success or wait | 709413285 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@dc4414 | success or wait | 709413478 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 20480 Protection: readonly Mapped to pid: own pid | success or wait | 709413601 | 
| Memory attributes changed | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 709416414 | 
| File opened | Path: C:\WINDOWS\system32\ADVAPI32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 709417099 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@f98ce0 | success or wait | 709417417 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 709417513 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@18fcdce | success or wait | 709418586 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 48 1D 90 49 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 709418902 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 46 07 00 00 3E 02 00 00 00 00 00 0B 71 00 00 00 10 00 00 00 20 07 00 00 00 DD 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 B0 09 00 00 04 00 00 B8 5B 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 A4 16 00 00 | success or wait | 709419018 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10a098 | success or wait | 709419238 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C9 45 07 00 00 10 00 00 00 46 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 28 46 00 00 00 60 07 00 00 2C 00 00 00 4A 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 80 A9 01 00 00 B0 07 00 00 AA 01 00 | success or wait | 709419334 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@19f9088 | success or wait | 709419526 | 
| Section loaded | Path: C:\WINDOWS\system32\advapi32.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 28672 Protection: readonly Mapped to pid: own pid | success or wait | 709419649 | 
| File opened | Path: C:\WINDOWS\system32\CRYPT32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 709456475 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c9dee3 | success or wait | 709456798 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 709456895 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1480d96 | success or wait | 709458166 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D7 A0 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 709458282 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 44 08 00 00 DC 00 00 00 00 00 00 32 16 00 00 00 10 00 00 00 20 08 00 00 00 A8 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 50 09 00 00 04 00 00 30 C5 09 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 9C 1A 00 00 | success or wait | 709458396 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@174331c | success or wait | 709458617 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C4 43 08 00 00 10 00 00 00 44 08 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 E8 23 00 00 00 60 08 00 00 24 00 00 00 48 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 50 67 00 00 00 90 08 00 00 68 00 00 | success or wait | 709458712 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1c77610 | success or wait | 709458903 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and read Type: commit Baseaddress: 11E0000 Size: 77824 Protection: readonly Mapped to pid: own pid | success or wait | 709459026 | 
| Mutant created | Name: \BaseNamedObjects\Global\ch971pGLCYGJFFTTU5XPPGQTZJ8OdYB | object name exists | 709524667 | 
| Thread created | PID: 1452 TID: 2460 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\msiexec.exe | success or wait | 709525617 | 
| Thread resumed | TID: 2460 PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe | success or wait | 709526035 | 
| Thread terminated | TID: 2420 PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe | unknown | 709526442 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | success or wait | 709526535 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 709526733 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 709539289 | 
| Memory allocated | PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe Base: 9C0000 Length: 121FF30 Allocation Type: unknown Protection: page execute and read and write | success or wait | 709549895 | 
| Thread created | PID: 1452 TID: 2468 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\msiexec.exe | success or wait | 709551024 | 
| Thread resumed | TID: 2468 PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe | success or wait | 709551294 | 
| Process information queried | PID: 1452 Info Class: Cookie | success or wait | 709551641 | 
| Process information queried | PID: 1452 Info Class: Cookie | success or wait | 709551731 | 
| Thread created | PID: 1452 TID: 2472 EIP: 7C8106F9 Imagepath: C:\WINDOWS\system32\msiexec.exe | success or wait | 709552901 | 
| Thread resumed | TID: 2472 PID: 1452 Path: C:\WINDOWS\system32\msiexec.exe | success or wait | 709553162 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 710410223 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 710412426 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 710413768 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 712097402 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 712105740 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 712109288 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 713199986 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 713202787 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 713204054 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 714414079 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 714420785 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 714423990 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 715497632 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 715504390 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 715507604 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 716615236 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 716622090 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 716625441 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 718181501 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 718189022 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 718192582 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 719453983 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 719462185 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 719465967 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 720529531 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 720588942 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 720591387 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 721647419 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 721704675 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 721706881 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 723237482 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 723241429 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 723244024 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 724332051 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 724334456 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 724336626 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 725448612 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 725450988 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 725453190 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 726566429 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 726568836 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 726571298 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 727687533 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 727693774 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 727699833 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 728810346 | 
| Thread delayed | Time: 0 TID: 2432 | success or wait | 728816743 | 
| Sections | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| File Activities: 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Section Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Mutant Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Process Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Thread Activities: 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Memory Activities: 
 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Section loaded | Path: \KnownDlls\kernel32.dll Access: write and read and execute Type: unknown Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid | success or wait | 654643548 | 
| Process information queried | PID: 2116 Info Class: Cookie | success or wait | 654656883 | 
| Section loaded | Path: unknown Access: query and write and read and execute and extend size Type: reserve Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid | success or wait | 654659243 | 
| Section loaded | Path: \NLS\NlsSectionUnicode Access: read Type: unknown Baseaddress: 270000 Size: 90112 Protection: readonly Mapped to pid: own pid | success or wait | 654666794 | 
| Section loaded | Path: \NLS\NlsSectionLocale Access: read Type: unknown Baseaddress: 290000 Size: 266240 Protection: readonly Mapped to pid: own pid | success or wait | 654672722 | 
| Section loaded | Path: \NLS\NlsSectionSortkey Access: query and read Type: unknown Baseaddress: 2E0000 Size: 266240 Protection: readonly Mapped to pid: own pid | success or wait | 654676286 | 
| Section loaded | Path: \NLS\NlsSectionSortTbls Access: read Type: unknown Baseaddress: 330000 Size: 24576 Protection: readonly Mapped to pid: own pid | success or wait | 654682633 | 
| Section loaded | Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 654690680 | 
| Section loaded | Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 654691053 | 
| Section loaded | Path: \KnownDlls\ADVAPI32.dll Access: write and read and execute Type: unknown Baseaddress: 77DD0000 Size: 634880 Protection: read write Mapped to pid: own pid | success or wait | 654694792 | 
| Section loaded | Path: \KnownDlls\RPCRT4.dll Access: write and read and execute Type: unknown Baseaddress: 77E70000 Size: 602112 Protection: read write Mapped to pid: own pid | success or wait | 654759940 | 
| Section loaded | Path: \KnownDlls\Secur32.dll Access: write and read and execute Type: unknown Baseaddress: 77FE0000 Size: 69632 Protection: read write Mapped to pid: own pid | success or wait | 654776760 | 
| Section loaded | Path: \KnownDlls\USER32.dll Access: write and read and execute Type: unknown Baseaddress: 7E410000 Size: 593920 Protection: read write Mapped to pid: own pid | success or wait | 654798751 | 
| Section loaded | Path: \KnownDlls\GDI32.dll Access: write and read and execute Type: unknown Baseaddress: 77F10000 Size: 299008 Protection: read write Mapped to pid: own pid | success or wait | 654803066 | 
| Section loaded | Path: \KnownDlls\msvcrt.dll Access: write and read and execute Type: unknown Baseaddress: 77C10000 Size: 360448 Protection: read write Mapped to pid: own pid | success or wait | 654819486 | 
| Section loaded | Path: \KnownDlls\SHLWAPI.dll Access: write and read and execute Type: unknown Baseaddress: 77F60000 Size: 483328 Protection: read write Mapped to pid: own pid | success or wait | 654890803 | 
| Section loaded | Path: \KnownDlls\SHELL32.dll Access: write and read and execute Type: unknown Baseaddress: 7C9C0000 Size: 8482816 Protection: read write Mapped to pid: own pid | success or wait | 654914996 | 
| Section loaded | Path: \KnownDlls\ole32.dll Access: write and read and execute Type: unknown Baseaddress: 774E0000 Size: 1302528 Protection: read write Mapped to pid: own pid | success or wait | 654924630 | 
| Section loaded | Path: \KnownDlls\iertutil.dll Access: write and read and execute Type: unknown Baseaddress: 3DFD0000 Size: 2002944 Protection: read write Mapped to pid: own pid | success or wait | 654931861 | 
| Section loaded | Path: \KnownDlls\urlmon.dll Access: write and read and execute Type: unknown Baseaddress: 78130000 Size: 1257472 Protection: read write Mapped to pid: own pid | success or wait | 654938350 | 
| Section loaded | Path: \KnownDlls\OLEAUT32.dll Access: write and read and execute Type: unknown Baseaddress: 77120000 Size: 569344 Protection: read write Mapped to pid: own pid | success or wait | 654942063 | 
| Section loaded | Path: \KnownDlls\ShimEng.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 654954755 | 
| Section loaded | Path: C:\WINDOWS\system32\shimeng.dll Access: query and write and read and execute Type: image Baseaddress: 5CB70000 Size: 155648 Protection: read write Mapped to pid: own pid | success or wait | 654956372 | 
| Section loaded | Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 4A0000 Size: 1208320 Protection: readonly Mapped to pid: own pid | success or wait | 654968980 | 
| Process information queried | PID: 2116 Info Class: Wow64Information | success or wait | 654971084 | 
| Process information queried | PID: 2116 Info Class: Wow64Information | success or wait | 654973053 | 
| Section loaded | Path: C:\WINDOWS\AppPatch\aclayers.dll Access: write and read and execute Type: commit Baseaddress: 350000 Size: 475136 Protection: execute Mapped to pid: own pid | success or wait | 654985051 | 
| Section loaded | Path: C:\WINDOWS\AppPatch\aclayers.dll Access: write and read and execute Type: commit Baseaddress: 350000 Size: 475136 Protection: execute Mapped to pid: own pid | success or wait | 654989910 | 
| Section loaded | Path: C:\WINDOWS\AppPatch\aclayers.dll Access: query and write and read and execute Type: image Baseaddress: 71590000 Size: 495616 Protection: read write Mapped to pid: own pid | success or wait | 654992393 | 
| Section loaded | Path: \KnownDlls\USERENV.dll Access: write and read and execute Type: unknown Baseaddress: 769C0000 Size: 737280 Protection: read write Mapped to pid: own pid | success or wait | 655005593 | 
| Section loaded | Path: \KnownDlls\WINSPOOL.DRV Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 655011961 | 
| Section loaded | Path: C:\WINDOWS\system32\winspool.drv Access: query and write and read and execute Type: image Baseaddress: 73000000 Size: 155648 Protection: read write Mapped to pid: own pid | success or wait | 655013619 | 
| Section loaded | Path: \NLS\NlsSectionCType Access: read Type: unknown Baseaddress: 360000 Size: 12288 Protection: readonly Mapped to pid: own pid | success or wait | 655037509 | 
| Process information queried | PID: 2116 Info Class: Cookie | success or wait | 655043426 | 
| Process information queried | PID: 2116 Info Class: Cookie | success or wait | 655043739 | 
| Process information queried | PID: 2116 Info Class: ImageInformation | success or wait | 655091648 | 
| Section loaded | Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit Baseaddress: 3B0000 Size: 110592 Protection: execute Mapped to pid: own pid | success or wait | 655100409 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655104128 | 
| Section loaded | Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit Baseaddress: 3B0000 Size: 110592 Protection: execute Mapped to pid: own pid | success or wait | 655105644 | 
| Section loaded | Path: C:\WINDOWS\system32\imm32.dll Access: query and write and read and execute Type: image Baseaddress: 76390000 Size: 118784 Protection: read write Mapped to pid: own pid | success or wait | 655108243 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655115415 | 
| Process information queried | PID: 2116 Info Class: Cookie | success or wait | 655125518 | 
| Process information queried | PID: 2116 Info Class: Cookie | success or wait | 655125834 | 
| Section loaded | Path: C:\WINDOWS\system32\shell32.dll Access: read Type: commit Baseaddress: 980000 Size: 8462336 Protection: readonly Mapped to pid: own pid | success or wait | 655130436 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655168561 | 
| Section loaded | Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll Access: write and read and execute Type: commit Baseaddress: 980000 Size: 1056768 Protection: execute Mapped to pid: own pid | success or wait | 655171537 | 
| Section loaded | Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll Access: query and write and read and execute Type: image Baseaddress: 773D0000 Size: 1060864 Protection: read write Mapped to pid: own pid | success or wait | 655174665 | 
| Section loaded | Path: C:\WINDOWS\WindowsShell.Manifest Access: write and read and execute Type: commit Baseaddress: 3E0000 Size: 4096 Protection: execute Mapped to pid: own pid | success or wait | 655187610 | 
| Section loaded | Path: C:\WINDOWS\WindowsShell.Manifest Access: query and read Type: commit Baseaddress: 3E0000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 655191276 | 
| Section loaded | Path: C:\WINDOWS\WindowsShell.Manifest Access: read Type: commit Baseaddress: 3E0000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 655194586 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655233812 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655234221 | 
| Section loaded | Path: \KnownDlls\comctl32.dll Access: write and read and execute Type: unknown Baseaddress: 5D090000 Size: 630784 Protection: read write Mapped to pid: own pid | success or wait | 655234700 | 
| Section loaded | Path: C:\WINDOWS\system32\comctl32.dll Access: read Type: commit Baseaddress: 980000 Size: 618496 Protection: readonly Mapped to pid: own pid | success or wait | 655248203 | 
| Process information queried | PID: 2116 Info Class: SessionInformation | success or wait | 655254641 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655257811 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655258396 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655259810 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655321608 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655323251 | 
| Section loaded | Path: \KnownDlls\CRYPT32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 655343934 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and write and read and execute Type: image Baseaddress: 77A80000 Size: 610304 Protection: read write Mapped to pid: own pid | success or wait | 655345536 | 
| Section loaded | Path: \KnownDlls\MSASN1.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 655349256 | 
| Section loaded | Path: C:\WINDOWS\system32\msasn1.dll Access: query and write and read and execute Type: image Baseaddress: 77B20000 Size: 73728 Protection: read write Mapped to pid: own pid | success or wait | 655350880 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655362618 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655362985 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655364241 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655364595 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655366090 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655366469 | 
| Section loaded | Path: \KnownDlls\WS2_32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 655368741 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and write and read and execute Type: image Baseaddress: 71AB0000 Size: 94208 Protection: read write Mapped to pid: own pid | success or wait | 655370324 | 
| Section loaded | Path: \KnownDlls\WS2HELP.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 655375530 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2help.dll Access: query and write and read and execute Type: image Baseaddress: 71AA0000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 655377220 | 
| Section loaded | Path: \KnownDlls\WININET.dll Access: write and read and execute Type: unknown Baseaddress: 3D930000 Size: 942080 Protection: read write Mapped to pid: own pid | success or wait | 655385609 | 
| Section loaded | Path: \KnownDlls\Normaliz.dll Access: write and read and execute Type: unknown Baseaddress: 9A0000 Size: 36864 Protection: read write Mapped to pid: own pid | conflicting addresses | 655391992 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655465399 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655467501 | 
| Section loaded | Path: \KnownDlls\MSIMG32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 655480232 | 
| Section loaded | Path: C:\WINDOWS\system32\msimg32.dll Access: query and write and read and execute Type: image Baseaddress: 76380000 Size: 20480 Protection: read write Mapped to pid: own pid | success or wait | 655482834 | 
| Thread created | PID: 2116 TID: 2248 EIP: 7C8106F9 Imagepath: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 655488589 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 655490400 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 655491313 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 655492160 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@f91c8f | success or wait | 655492988 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 655493252 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c21095 | success or wait | 655493847 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 655494114 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 655494417 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ced1ac | success or wait | 655495001 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 655495250 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@277bd2 | success or wait | 655495987 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 655496316 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655498975 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BAFEA50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655499265 | 
| Thread created | PID: 2116 TID: 2252 EIP: 7C8106F9 Imagepath: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 655500833 | 
| Thread created | PID: 2116 TID: 2256 EIP: 7C8106F9 Imagepath: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 655503550 | 
| Process information queried | PID: 2116 Info Class: Wow64Information | success or wait | 655505314 | 
| Process information queried | PID: 2116 Info Class: Wow64Information | success or wait | 655505873 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 655506426 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 655506822 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655507004 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 655507973 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@f91c8f | success or wait | 655508806 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 655509071 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c21095 | success or wait | 655509444 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 655509776 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 655510078 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ced1ac | success or wait | 655510662 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 655510911 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@277bd2 | success or wait | 655511422 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 655511749 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655514458 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB186C0 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655514747 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655515042 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 655515995 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@f91c8f | success or wait | 655516809 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 655517065 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c21095 | success or wait | 655517439 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 655517687 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 655517986 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ced1ac | success or wait | 655518569 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 655518728 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@277bd2 | success or wait | 655519288 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 655519614 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655522385 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB06F28 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655522676 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655522971 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 655523921 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@f91c8f | success or wait | 655524746 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 655525002 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c21095 | success or wait | 655525383 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 655525633 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 655525932 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ced1ac | success or wait | 655526522 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 655526771 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@277bd2 | success or wait | 655527288 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 655527615 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655530299 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB04B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655530589 | 
| Process information queried | PID: 2116 Info Class: Wow64Information | success or wait | 655531076 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655531332 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 655532284 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@f91c8f | success or wait | 655533181 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 655533529 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c21095 | success or wait | 655533917 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 655534167 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 655534467 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ced1ac | success or wait | 655535059 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 655535309 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@277bd2 | success or wait | 655535828 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 655536155 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655538847 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB17D98 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655539135 | 
| Section loaded | Path: \KnownDlls\nspr4.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 655540081 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 655542503 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 655543971 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 655563141 | 
| File opened | Path: C:\WINDOWS\system32\USER32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 655564142 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@3256a5 | success or wait | 655564988 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 4 Value: D8 00 00 00 | success or wait | 655565255 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d6866f | success or wait | 655565875 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 1B A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 655566139 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 F4 05 00 00 E2 02 00 00 00 00 00 17 B2 00 00 00 10 00 00 00 B0 05 00 00 00 41 7E 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 10 09 00 00 04 00 00 76 FC 08 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 39 00 00 | success or wait | 655566450 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@13f347 | success or wait | 655567051 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 83 F2 05 00 00 10 00 00 00 F4 05 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 80 11 00 00 00 10 06 00 00 0C 00 00 00 F8 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 88 A0 02 00 00 30 06 00 00 A2 02 00 | success or wait | 655567312 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1c8d400 | success or wait | 655567841 | 
| Section loaded | Path: C:\WINDOWS\system32\user32.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 57344 Protection: readonly Mapped to pid: own pid | success or wait | 655568179 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655570960 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB03E40 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655571274 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 655571663 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 655572629 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1d66aa9 | success or wait | 655573462 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 655573721 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4bdca | success or wait | 655574327 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 655574583 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 655574890 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d81cda | success or wait | 655575488 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 655575744 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@4e57ba | success or wait | 655576267 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 655576599 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655579680 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB189C8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655579964 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 655580345 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 655581313 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1d66aa9 | success or wait | 655582142 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 655582402 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4bdca | success or wait | 655582789 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 655583045 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 655583350 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d81cda | success or wait | 655583945 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 655584201 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@4e57ba | success or wait | 655584723 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 655585055 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655588220 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB18118 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655588506 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 655588729 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 655591312 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1d66aa9 | success or wait | 655592154 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 655592414 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4bdca | success or wait | 655592802 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 655593145 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 655593452 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d81cda | success or wait | 655594051 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 655594309 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@4e57ba | success or wait | 655594833 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 655595166 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655598345 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BAFE1F8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655598631 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 655599302 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 655600257 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1d66aa9 | success or wait | 655601088 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 655601347 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4bdca | success or wait | 655601733 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 655601991 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 655602295 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d81cda | success or wait | 655602891 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 655603146 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@4e57ba | success or wait | 655603668 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 655603999 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655607141 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB07290 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655607426 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 655608340 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 655609323 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 655632918 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 655633905 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1d66aa9 | success or wait | 655634751 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 655635011 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4bdca | success or wait | 655635401 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 655635657 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 655635961 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d81cda | success or wait | 655636556 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 655636812 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@4e57ba | success or wait | 655637338 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 655637670 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655640846 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB07A10 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655641132 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 655641483 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 655642461 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1d66aa9 | success or wait | 655643295 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 655643557 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4bdca | success or wait | 655643943 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 655644199 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 655644502 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d81cda | success or wait | 655645749 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 655646016 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@4e57ba | success or wait | 655646546 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 655647420 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655653331 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB18B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655653629 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 655654397 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 655656052 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1d66aa9 | success or wait | 655656908 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 655657168 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4bdca | success or wait | 655658949 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 655660013 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 655660324 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d81cda | success or wait | 655661457 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 655661715 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@4e57ba | success or wait | 655662241 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 655665015 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655670727 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB05310 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655671023 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 655672326 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 655673657 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1d66aa9 | success or wait | 655674508 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 655674768 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4bdca | success or wait | 655676554 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 655677463 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 655677769 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d81cda | success or wait | 655678539 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 655678796 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@4e57ba | success or wait | 655679320 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 655680187 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655683386 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB18ED8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655683672 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 655684026 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 655685009 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1d66aa9 | success or wait | 655685847 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 655686105 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4bdca | success or wait | 655686491 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 655686747 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 655687050 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d81cda | success or wait | 655687720 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 655687977 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@4e57ba | success or wait | 655688499 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 655688829 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655691991 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB04D50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655692286 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 655692638 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 655693601 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1d66aa9 | success or wait | 655694434 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 655694694 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4bdca | success or wait | 655695082 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 655695338 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 655695641 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d81cda | success or wait | 655696235 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 655696490 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@4e57ba | success or wait | 655697289 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 655697619 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655701007 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB05538 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655701379 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 655701734 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 655702708 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1d66aa9 | success or wait | 655703542 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 655703800 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4bdca | success or wait | 655704186 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 655704440 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 655704743 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d81cda | success or wait | 655705335 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 655705590 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@4e57ba | success or wait | 655706111 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 655706441 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655709588 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BAFE698 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655709873 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 655710410 | 
| File opened | Path: C:\WINDOWS\system32\WS2_32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 655711379 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1619137 | success or wait | 655712209 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 655712468 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@84c1f9 | success or wait | 655713078 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 63 A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 655713332 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 22 01 00 00 1C 00 00 00 00 00 00 73 12 00 00 00 10 00 00 00 20 01 00 00 00 AB 71 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 70 01 00 00 04 00 00 20 F0 01 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 04 14 00 00 | success or wait | 655713636 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1dae27f | success or wait | 655714229 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 53 21 01 00 00 10 00 00 00 22 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 14 09 00 00 00 40 01 00 00 0A 00 00 00 26 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 F8 03 00 00 00 50 01 00 00 04 00 00 | success or wait | 655714485 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@14c4066 | success or wait | 655715003 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 20480 Protection: readonly Mapped to pid: own pid | success or wait | 655715332 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655717709 | 
| Memory attributes changed | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB18D30 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 655717996 | 
| File opened | Path: C:\WINDOWS\system32\ADVAPI32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 655719411 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@117ffc5 | success or wait | 655720251 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 655720512 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@99146a | success or wait | 655721121 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 48 1D 90 49 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 655721377 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 46 07 00 00 3E 02 00 00 00 00 00 0B 71 00 00 00 10 00 00 00 20 07 00 00 00 DD 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 B0 09 00 00 04 00 00 B8 5B 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 A4 16 00 00 | success or wait | 655721683 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b4ef2 | success or wait | 655722280 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C9 45 07 00 00 10 00 00 00 46 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 28 46 00 00 00 60 07 00 00 2C 00 00 00 4A 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 80 A9 01 00 00 B0 07 00 00 AA 01 00 | success or wait | 655722536 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@6bf80b | success or wait | 655723055 | 
| Section loaded | Path: C:\WINDOWS\system32\advapi32.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 28672 Protection: readonly Mapped to pid: own pid | success or wait | 655723387 | 
| File opened | Path: C:\WINDOWS\system32\CRYPT32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 655728224 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@69b824 | success or wait | 655729055 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 655729315 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b846c6 | success or wait | 655729920 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D7 A0 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 655730176 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 44 08 00 00 DC 00 00 00 00 00 00 32 16 00 00 00 10 00 00 00 20 08 00 00 00 A8 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 50 09 00 00 04 00 00 30 C5 09 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 9C 1A 00 00 | success or wait | 655730478 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@2e749c | success or wait | 655731072 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C4 43 08 00 00 10 00 00 00 44 08 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 E8 23 00 00 00 60 08 00 00 24 00 00 00 48 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 50 67 00 00 00 90 08 00 00 68 00 00 | success or wait | 655731327 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1e9c46d | success or wait | 655731846 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 77824 Protection: readonly Mapped to pid: own pid | success or wait | 655732495 | 
| Mutant created | Name: \BaseNamedObjects\Global\ch971pGLCYGJFFTTU5XPPGQTZJ8OdYB | object name exists | 655736141 | 
| Thread created | PID: 2116 TID: 2264 EIP: 7C8106F9 Imagepath: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 655737933 | 
| Thread resumed | TID: 2264 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 655738636 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | success or wait | 655739645 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 655740764 | 
| Process information queried | PID: 2116 Info Class: Cookie | success or wait | 655742219 | 
| Process information queried | PID: 2116 Info Class: Cookie | success or wait | 655743131 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 655781521 | 
| Memory allocated | PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 9C0000 Length: 102FF30 Allocation Type: unknown Protection: page execute and read and write | success or wait | 655819754 | 
| Thread created | PID: 2116 TID: 2272 EIP: 7C8106F9 Imagepath: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 655825463 | 
| Thread resumed | TID: 2272 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 655826168 | 
| Process information queried | PID: 2116 Info Class: Cookie | success or wait | 655832788 | 
| Process information queried | PID: 2116 Info Class: Cookie | success or wait | 655833029 | 
| Thread created | PID: 2116 TID: 2276 EIP: 7C8106F9 Imagepath: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 655837126 | 
| Thread resumed | TID: 2276 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 655844149 | 
| Process information queried | PID: 2116 Info Class: Wow64Information | success or wait | 655850247 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655853715 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655854672 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655855608 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655865664 | 
| Section loaded | Path: \KnownDlls\IEFRAME.dll Access: write and read and execute Type: unknown Baseaddress: 3E1C0000 Size: 11096064 Protection: read write Mapped to pid: own pid | success or wait | 655866701 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655908056 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655909049 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655910013 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655910964 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655911938 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655912933 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655913893 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655914922 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655915876 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655916826 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655917775 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 655918722 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 656023985 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 656027234 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 656028702 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 656030245 | 
| Section loaded | Path: C:\WINDOWS\system32\en-us\ieframe.dll.mui Access: query and read Type: commit Baseaddress: 1130000 Size: 1241088 Protection: write copy Mapped to pid: own pid | success or wait | 656036172 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 656064467 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 656071004 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 656072249 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 656109761 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 656110735 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 656128406 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 656129380 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet FilesNew path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@5edf72 | success or wait | 656146044 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5New path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9fe5c5 | success or wait | 656151949 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\HistoryNew path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a5fc52 | success or wait | 656195685 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\History\History.IE5New path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@58924a | success or wait | 656200408 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5New path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9fe5c5 | success or wait | 656216774 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.datNew path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ec7913 | success or wait | 656221117 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Local Settings_Temporary Internet Files_Content.IE5_index.dat_32768 Access: write Type: unknown Baseaddress: 9E0000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 656222730 | 
| File other op | Path: C:\Documents and Settings\Administrator\CookiesNew path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1010435 | success or wait | 656229301 | 
| File other op | Path: C:\Documents and Settings\Administrator\Cookies\index.datNew path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1bb73b0 | success or wait | 656234074 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Cookies_index.dat_16384 Access: write Type: unknown Baseaddress: 9F0000 Size: 16384 Protection: read write Mapped to pid: own pid | success or wait | 656235586 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\History\History.IE5New path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@58924a | success or wait | 656240576 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.datNew path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a84fae | success or wait | 656244652 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Local Settings_History_History.IE5_index.dat_32768 Access: write Type: unknown Baseaddress: A00000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 656246067 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5New path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9fe5c5 | success or wait | 656250465 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\History\History.IE5New path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@58924a | success or wait | 656254678 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 656475606 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 656476697 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 656596438 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 656596850 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 656597265 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 656663225 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 656664584 | 
| Process information queried | PID: 2116 Info Class: DefaultHardErrorMode | success or wait | 656727456 | 
| Section loaded | Path: \KnownDlls\VERSION.dll Access: write and read and execute Type: unknown Baseaddress: 77C00000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 656742627 | 
| Thread resumed | TID: 2292 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 656786057 | 
| Section loaded | Path: C:\WINDOWS\system32\mswsock.dll Access: write and read and execute Type: commit Baseaddress: 1360000 Size: 245760 Protection: execute Mapped to pid: own pid | success or wait | 656794910 | 
| Section loaded | Path: C:\WINDOWS\system32\mswsock.dll Access: query and write and read and execute Type: image Baseaddress: 71A50000 Size: 258048 Protection: read write Mapped to pid: own pid | success or wait | 656803456 | 
| Process information queried | PID: 2116 Info Class: QuotaLimits | success or wait | 656839632 | 
| Process information queried | PID: 2116 Info Class: VmCounters | success or wait | 656844171 | 
| Section loaded | Path: \KnownDlls\DNSAPI.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 656848985 | 
| Section loaded | Path: C:\WINDOWS\system32\dnsapi.dll Access: query and write and read and execute Type: image Baseaddress: 76F20000 Size: 159744 Protection: read write Mapped to pid: own pid | success or wait | 656854693 | 
| Section loaded | Path: \BaseNamedObjects\Internet Explorer Immutable Application State (00000844-0000-0000-0000-000000000000) Access: query and write and read Type: commit Baseaddress: A10000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 656856954 | 
| Section loaded | Path: \KnownDlls\comdlg32.dll Access: write and read and execute Type: unknown Baseaddress: 763B0000 Size: 299008 Protection: read write Mapped to pid: own pid | success or wait | 656959863 | 
| Section loaded | Path: C:\WINDOWS\system32\rpcss.dll Access: write and read and execute Type: commit Baseaddress: 1360000 Size: 401408 Protection: execute Mapped to pid: own pid | success or wait | 657088316 | 
| Section loaded | Path: C:\WINDOWS\system32\msctf.dll Access: write and read and execute Type: commit Baseaddress: 1360000 Size: 299008 Protection: execute Mapped to pid: own pid | success or wait | 657163191 | 
| Section loaded | Path: C:\WINDOWS\system32\msctf.dll Access: query and write and read and execute Type: image Baseaddress: 74720000 Size: 311296 Protection: read write Mapped to pid: own pid | success or wait | 657169796 | 
| Process information queried | PID: 2116 Info Class: Wow64Information | success or wait | 657195912 | 
| Section loaded | Path: \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-507921405-1960408961-839522115-500 Access: query and write and read Type: commit Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name exists | 657198660 | 
| Section loaded | Path: \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-507921405-1960408961-839522115-500SFM.DefaultS-1-5-21-507921405-1960408961-839522115-500 Access: query and write and read and execute and extend size Type: unknown Baseaddress: 1370000 Size: 262144 Protection: read write Mapped to pid: own pid | success or wait | 657221199 | 
| Section loaded | Path: C:\WINDOWS\system32\winlogon.exe Access: write and read and execute Type: commit Baseaddress: 13B0000 Size: 507904 Protection: execute Mapped to pid: own pid | success or wait | 657234172 | 
| Section loaded | Path: \KnownDlls\xpsp2res.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 657243907 | 
| Section loaded | Path: C:\WINDOWS\system32\xpsp2res.dll Access: query and write and read and execute Type: image Baseaddress: 13B0000 Size: 2904064 Protection: read write Mapped to pid: own pid | conflicting addresses | 657246795 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1075056 | success or wait | 658011313 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 658017266 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 658021220 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 658023554 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12b71eb | success or wait | 658024838 | 
| Process information queried | PID: 2116 Info Class: Cookie | success or wait | 658062265 | 
| Process information queried | PID: 2116 Info Class: Cookie | success or wait | 658063309 | 
| Process information queried | PID: 2116 Info Class: Cookie | success or wait | 658064217 | 
| Process information queried | PID: 2116 Info Class: Cookie | success or wait | 658068044 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\sqmapi.dll Access: write and read and execute Type: commit Baseaddress: 1680000 Size: 135168 Protection: execute Mapped to pid: own pid | success or wait | 658113301 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\sqmapi.dll Access: query and write and read and execute Type: image Baseaddress: 6CD00000 Size: 147456 Protection: read write Mapped to pid: own pid | success or wait | 658128936 | 
| Process information queried | PID: 2116 Info Class: Wow64Information | success or wait | 658524253 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1075056 | success or wait | 658533531 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12b71eb | success or wait | 658533883 | 
| Section loaded | Path: \BaseNamedObjects\windows_ie_global_counters Access: write and read Type: unknown Baseaddress: 1680000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 658545387 | 
| Section loaded | Path: \BaseNamedObjects\ie_lcie_main_844_S-1-5-21-507921405-1960408961-839522115-500 Access: query and write and read Type: commit Baseaddress: 1690000 Size: 450560 Protection: read write Mapped to pid: own pid | success or wait | 658551985 | 
| Section loaded | Path: \BaseNamedObjects\Isolation Process Registry (0DD04C9B-4667-11E1-97AA-08002763FBB4) Access: query and write and read Type: commit Baseaddress: 1700000 Size: 8192 Protection: read write Mapped to pid: own pid | success or wait | 658554469 | 
| Section loaded | Path: \BaseNamedObjects\Isolation Signal Registry (0DD04C9B-4667-11E1-97AA-08002763FBB4, 0) Access: query and write and read Type: commit Baseaddress: 1710000 Size: 8192 Protection: read write Mapped to pid: own pid | success or wait | 658555303 | 
| Process information queried | PID: 2116 Info Class: BasicInformation | success or wait | 658556063 | 
| Thread resumed | TID: 2384 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 658562496 | 
| Thread resumed | TID: 2388 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 658565426 | 
| Section loaded | Path: \BaseNamedObjects\ie_lcie_LogonMedium_S-1-5-21-507921405-1960408961-839522115-500 Access: query and write and read Type: commit Baseaddress: 1B20000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 658569676 | 
| Section loaded | Path: \BaseNamedObjects\Local\IEFrame!GetAsyncKeyStateSharedMem!2116 Access: query and write and read Type: commit Baseaddress: 1B30000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 658576970 | 
| Thread resumed | TID: 2396 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 658579670 | 
| Section loaded | Path: \KnownDlls\RASAPI32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 658733900 | 
| Section loaded | Path: C:\WINDOWS\system32\rasapi32.dll Access: query and write and read and execute Type: image Baseaddress: 76EE0000 Size: 245760 Protection: read write Mapped to pid: own pid | success or wait | 658735043 | 
| Section loaded | Path: \KnownDlls\rasman.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 658740774 | 
| Section loaded | Path: C:\WINDOWS\system32\rasman.dll Access: query and write and read and execute Type: image Baseaddress: 76E90000 Size: 73728 Protection: read write Mapped to pid: own pid | success or wait | 658741854 | 
| Section loaded | Path: \KnownDlls\NETAPI32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 658746418 | 
| Section loaded | Path: C:\WINDOWS\system32\netapi32.dll Access: query and write and read and execute Type: image Baseaddress: 5B860000 Size: 348160 Protection: read write Mapped to pid: own pid | success or wait | 658747483 | 
| Section loaded | Path: \KnownDlls\TAPI32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 658756267 | 
| Section loaded | Path: C:\WINDOWS\system32\tapi32.dll Access: query and write and read and execute Type: image Baseaddress: 76EB0000 Size: 192512 Protection: read write Mapped to pid: own pid | success or wait | 658757328 | 
| Section loaded | Path: \KnownDlls\rtutils.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 658763230 | 
| Section loaded | Path: C:\WINDOWS\system32\rtutils.dll Access: query and write and read and execute Type: image Baseaddress: 76E80000 Size: 57344 Protection: read write Mapped to pid: own pid | success or wait | 658764360 | 
| Section loaded | Path: \KnownDlls\WINMM.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 658770451 | 
| Section loaded | Path: C:\WINDOWS\system32\winmm.dll Access: query and write and read and execute Type: image Baseaddress: 76B40000 Size: 184320 Protection: read write Mapped to pid: own pid | success or wait | 658771519 | 
| Section loaded | Path: C:\WINDOWS\system32\tapi32.dll Access: read Type: commit Baseaddress: 1CC0000 Size: 184320 Protection: readonly Mapped to pid: own pid | success or wait | 658828847 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1075056 | success or wait | 658872398 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12b71eb | success or wait | 658872758 | 
| Section loaded | Path: \KnownDlls\sensapi.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 658962757 | 
| Section loaded | Path: C:\WINDOWS\system32\sensapi.dll Access: query and write and read and execute Type: image Baseaddress: 722B0000 Size: 20480 Protection: read write Mapped to pid: own pid | success or wait | 658963820 | 
| Section loaded | Path: \BaseNamedObjects\SENS Information Cache Access: read Type: unknown Baseaddress: 1CC0000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 658970674 | 
| Section loaded | Path: \BaseNamedObjects\ie_lcie_ConnHashTable<2116>_S-1-5-21-507921405-1960408961-839522115-500 Access: query and write and read Type: commit Baseaddress: 1D00000 Size: 380928 Protection: read write Mapped to pid: own pid | success or wait | 658991157 | 
| Section loaded | Path: C:\WINDOWS\system32\msctfime.ime Access: write and read and execute Type: commit Baseaddress: 1D60000 Size: 180224 Protection: execute Mapped to pid: own pid | success or wait | 659034643 | 
| Section loaded | Path: C:\WINDOWS\system32\msctfime.ime Access: query and read Type: commit Baseaddress: 1D60000 Size: 180224 Protection: readonly Mapped to pid: own pid | success or wait | 659037567 | 
| Section loaded | Path: C:\WINDOWS\system32\msctfime.ime Access: write and read and execute Type: commit Baseaddress: 1D60000 Size: 180224 Protection: execute Mapped to pid: own pid | success or wait | 659041981 | 
| Section loaded | Path: C:\WINDOWS\system32\msctfime.ime Access: query and read Type: commit Baseaddress: 1D60000 Size: 180224 Protection: readonly Mapped to pid: own pid | success or wait | 659044032 | 
| Section loaded | Path: \KnownDlls\apphelp.dll Access: write and read and execute Type: unknown Baseaddress: 77B40000 Size: 139264 Protection: read write Mapped to pid: own pid | success or wait | 659046723 | 
| Section loaded | Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 1D60000 Size: 1208320 Protection: readonly Mapped to pid: own pid | success or wait | 659054845 | 
| Process information queried | PID: 2116 Info Class: Wow64Information | success or wait | 659056379 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 659062951 | 
| Section loaded | Path: \BaseNamedObjects\ShimSharedMemory Access: write Type: unknown Baseaddress: 1CD0000 Size: 57344 Protection: read write Mapped to pid: own pid | success or wait | 659064803 | 
| Section loaded | Path: C:\WINDOWS\system32\msctfime.ime Access: write and read and execute Type: commit Baseaddress: 1D60000 Size: 180224 Protection: execute Mapped to pid: own pid | success or wait | 659066575 | 
| Section loaded | Path: C:\WINDOWS\system32\msctfime.ime Access: query and write and read and execute Type: image Baseaddress: 755C0000 Size: 188416 Protection: read write Mapped to pid: own pid | success or wait | 659068608 | 
| Section loaded | Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 1D60000 Size: 1208320 Protection: readonly Mapped to pid: own pid | success or wait | 659083362 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 659090510 | 
| Section loaded | Path: \KnownDlls\IEUI.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 659107562 | 
| Section loaded | Path: C:\WINDOWS\system32\ieui.dll Access: query and write and read and execute Type: image Baseaddress: 1DC0000 Size: 172032 Protection: read write Mapped to pid: own pid | conflicting addresses | 659109439 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 659113812 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 659115375 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 659116808 | 
| Thread resumed | TID: 2444 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 659174123 | 
| Thread resumed | TID: 2448 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 659194347 | 
| Thread resumed | TID: 2452 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 659197284 | 
| Thread resumed | TID: 2456 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 659201717 | 
| File other op | Path: \ROUTERNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1441dc0 | success or wait | 659203366 | 
| File other op | Path: \ROUTERNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@fd5609 | success or wait | 659203524 | 
| Section loaded | Path: \BaseNamedObjects\DfRoot000152DF7 Access: query and write and read Type: commit Baseaddress: 22F0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 659227360 | 
| Thread resumed | TID: 2484 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 659227846 | 
| Thread resumed | TID: 2512 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 659248544 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b6c74 | success or wait | 659257409 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: EndOfFileInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@6d65fd | success or wait | 659264821 | 
| Section loaded | Path: \KnownDlls\msapsspc.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 659267025 | 
| Section loaded | Path: C:\WINDOWS\system32\msapsspc.dll Access: query and write and read and execute Type: image Baseaddress: 71E50000 Size: 86016 Protection: read write Mapped to pid: own pid | success or wait | 659267739 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: AllocationInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@4301c9 | success or wait | 659270258 | 
| Section loaded | Path: \KnownDlls\MSVCRT40.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 659270849 | 
| Section loaded | Path: C:\WINDOWS\system32\msvcrt40.dll Access: query and write and read and execute Type: image Baseaddress: 78080000 Size: 69632 Protection: read write Mapped to pid: own pid | success or wait | 659271580 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b6c74 | success or wait | 659272353 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: EndOfFileInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@6d65fd | success or wait | 659273904 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: AllocationInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@4301c9 | success or wait | 659275607 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12a375b | success or wait | 659277027 | 
| Section loaded | Path: \KnownDlls\CLBCATQ.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 659282404 | 
| Section loaded | Path: C:\WINDOWS\system32\clbcatq.dll Access: query and write and read and execute Type: image Baseaddress: 76FD0000 Size: 520192 Protection: read write Mapped to pid: own pid | success or wait | 659283433 | 
| Section loaded | Path: \KnownDlls\COMRes.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 659285216 | 
| Section loaded | Path: C:\WINDOWS\system32\comres.dll Access: query and write and read and execute Type: image Baseaddress: 77050000 Size: 806912 Protection: read write Mapped to pid: own pid | success or wait | 659286026 | 
| Section loaded | Path: \KnownDlls\schannel.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 659292932 | 
| Section loaded | Path: C:\WINDOWS\system32\schannel.dll Access: query and write and read and execute Type: image Baseaddress: 767F0000 Size: 163840 Protection: read write Mapped to pid: own pid | success or wait | 659293622 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@986c47 | success or wait | 659295474 | 
| Process information queried | PID: 2116 Info Class: Wow64Information | success or wait | 659301686 | 
| Section loaded | Path: \KnownDlls\digest.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 659303222 | 
| Section loaded | Path: C:\WINDOWS\system32\digest.dll Access: query and write and read and execute Type: image Baseaddress: 75B00000 Size: 86016 Protection: read write Mapped to pid: own pid | success or wait | 659303923 | 
| Section loaded | Path: \KnownDlls\msnsspc.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 659315752 | 
| Section loaded | Path: C:\WINDOWS\system32\msnsspc.dll Access: query and write and read and execute Type: image Baseaddress: 747B0000 Size: 290816 Protection: read write Mapped to pid: own pid | success or wait | 659316546 | 
| File other op | Path: C:\WINDOWS\Registration\R000000000010.clbNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@ecabac | success or wait | 659317649 | 
| File other op | Path: C:\WINDOWS\Registration\R000000000010.clbNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1fac352 | success or wait | 659318991 | 
| Section loaded | Path: \KnownDlls\MSVCRT40.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 659331009 | 
| Section loaded | Path: C:\WINDOWS\system32\msvcrt40.dll Access: query and write and read and execute Type: image Baseaddress: 78080000 Size: 69632 Protection: read write Mapped to pid: own pid | success or wait | 659331738 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\ieproxy.dll Access: write and read and execute Type: commit Baseaddress: 2400000 Size: 249856 Protection: execute Mapped to pid: own pid | success or wait | 659353373 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\ieproxy.dll Access: query and write and read and execute Type: image Baseaddress: 439B0000 Size: 262144 Protection: read write Mapped to pid: own pid | success or wait | 659356151 | 
| Section loaded | Path: C:\WINDOWS\system32\msv1_0.dll Access: write and read and execute Type: commit Baseaddress: 2400000 Size: 139264 Protection: execute Mapped to pid: own pid | success or wait | 659367207 | 
| Section loaded | Path: C:\WINDOWS\system32\msv1_0.dll Access: query and write and read and execute Type: image Baseaddress: 77C70000 Size: 151552 Protection: read write Mapped to pid: own pid | success or wait | 659369364 | 
| Section loaded | Path: \KnownDlls\cryptdll.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 659372170 | 
| Section loaded | Path: C:\WINDOWS\system32\cryptdll.dll Access: query and write and read and execute Type: image Baseaddress: 76790000 Size: 49152 Protection: read write Mapped to pid: own pid | success or wait | 659372919 | 
| Section loaded | Path: \KnownDlls\iphlpapi.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 659377452 | 
| Section loaded | Path: C:\WINDOWS\system32\iphlpapi.dll Access: query and write and read and execute Type: image Baseaddress: 76D60000 Size: 102400 Protection: read write Mapped to pid: own pid | success or wait | 659378192 | 
| File other op | Path: \ROUTERNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1441dc0 | success or wait | 659419032 | 
| File other op | Path: \ROUTERNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@fd5609 | success or wait | 659419474 | 
| Thread resumed | TID: 2560 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 659441842 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@2d6583 | success or wait | 659461114 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: EndOfFileInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@63a8af | success or wait | 659476020 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: AllocationInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d77f83 | success or wait | 659488123 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@2d6583 | success or wait | 659489943 | 
| Thread resumed | TID: 2624 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 659495035 | 
| Process information queried | PID: 2116 Info Class: SessionInformation | success or wait | 659534592 | 
| Section loaded | Path: C:\WINDOWS\system32\msimtf.dll Access: write and read and execute Type: commit Baseaddress: 2620000 Size: 159744 Protection: execute Mapped to pid: own pid | success or wait | 659541495 | 
| Section loaded | Path: C:\WINDOWS\system32\msimtf.dll Access: query and write and read and execute Type: image Baseaddress: 746F0000 Size: 172032 Protection: read write Mapped to pid: own pid | success or wait | 659545405 | 
| Process information queried | PID: 2116 Info Class: SessionInformation | success or wait | 659606879 | 
| Process information queried | PID: 2116 Info Class: SessionInformation | success or wait | 659628071 | 
| Section loaded | Path: \BaseNamedObjects\CTF.AsmListCache.FMPDefaultS-1-5-21-507921405-1960408961-839522115-500 Access: query and write and read and execute and extend size Type: unknown Baseaddress: 2620000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 659665735 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: EndOfFileInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@63a8af | success or wait | 659852383 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: AllocationInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d77f83 | success or wait | 659877629 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4a427 | success or wait | 659884097 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 659972736 | 
| Section loaded | Path: \BaseNamedObjects\Local\UrlZonesSM_Administrator Access: query and write and read Type: commit Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name exists | 659997913 | 
| Section loaded | Path: \KnownDlls\UxTheme.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 660173556 | 
| Section loaded | Path: C:\WINDOWS\system32\uxtheme.dll Access: query and write and read and execute Type: image Baseaddress: 5AD70000 Size: 229376 Protection: read write Mapped to pid: own pid | success or wait | 660178664 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 660235794 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 660240387 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 660243105 | 
| Section loaded | Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 2780000 Size: 1208320 Protection: readonly Mapped to pid: own pid | success or wait | 660490256 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 660510604 | 
| Process information queried | PID: 2116 Info Class: SessionInformation | success or wait | 660573232 | 
| Section loaded | Path: C:\WINDOWS\system32\cscui.dll Access: write and read and execute Type: commit Baseaddress: 2780000 Size: 327680 Protection: execute Mapped to pid: own pid | success or wait | 660585351 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: EndOfFileInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@451610 | success or wait | 660589366 | 
| Section loaded | Path: C:\WINDOWS\system32\cscui.dll Access: query and write and read and execute Type: image Baseaddress: 77A20000 Size: 344064 Protection: read write Mapped to pid: own pid | success or wait | 660593024 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: AllocationInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ab8f3f | success or wait | 660600159 | 
| Section loaded | Path: \KnownDlls\CSCDLL.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 660602936 | 
| Section loaded | Path: C:\WINDOWS\system32\cscdll.dll Access: query and write and read and execute Type: image Baseaddress: 76600000 Size: 118784 Protection: read write Mapped to pid: own pid | success or wait | 660605816 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4a427 | success or wait | 660612967 | 
| Section loaded | Path: C:\WINDOWS\system32\cscui.dll Access: read Type: commit Baseaddress: 2780000 Size: 327680 Protection: readonly Mapped to pid: own pid | success or wait | 660678395 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 660742825 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 660746312 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 660749246 | 
| Process information queried | PID: 2116 Info Class: Wow64Information | success or wait | 660795575 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 661043823 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 661044818 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 661045809 | 
| File other op | Path: C:\WINDOWS\system32\url.dllNew path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@498364 | success or wait | 661052044 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: EndOfFileInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@451610 | success or wait | 661052939 | 
| Section loaded | Path: C:\WINDOWS\system32\url.dll Access: query and read Type: commit Baseaddress: 2780000 Size: 106496 Protection: readonly Mapped to pid: own pid | success or wait | 661057996 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: AllocationInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ab8f3f | success or wait | 661060109 | 
| Process information queried | PID: 2116 Info Class: SessionInformation | success or wait | 661130089 | 
| Section loaded | Path: C:\WINDOWS\system32\oleacc.dll Access: write and read and execute Type: commit Baseaddress: 2780000 Size: 163840 Protection: execute Mapped to pid: own pid | success or wait | 661144456 | 
| Section loaded | Path: C:\WINDOWS\system32\oleacc.dll Access: query and write and read and execute Type: image Baseaddress: 74C80000 Size: 180224 Protection: read write Mapped to pid: own pid | success or wait | 661157199 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@2d6583 | success or wait | 661162787 | 
| Section loaded | Path: \KnownDlls\MSVCP60.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 661168465 | 
| Section loaded | Path: C:\WINDOWS\system32\msvcp60.dll Access: query and write and read and execute Type: image Baseaddress: 76080000 Size: 413696 Protection: read write Mapped to pid: own pid | success or wait | 661171209 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 661933451 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 661939005 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 661941578 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b6c74 | success or wait | 661957397 | 
| Section loaded | Path: C:\WINDOWS\system32\oleaccrc.dll Access: query and read Type: commit Baseaddress: 2780000 Size: 20480 Protection: readonly Mapped to pid: own pid | success or wait | 661979483 | 
| Section loaded | Path: C:\WINDOWS\system32\oleacc.dll Access: query and read Type: commit Baseaddress: 2790000 Size: 12288 Protection: readonly Mapped to pid: own pid | success or wait | 662050067 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@986c47 | success or wait | 662053823 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 662055281 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4a427 | success or wait | 662096240 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: EndOfFileInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@451610 | success or wait | 662107867 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: AllocationInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ab8f3f | success or wait | 662203945 | 
| Section loaded | Path: \BaseNamedObjects\windows_ie_global_counters Access: write and read Type: unknown Baseaddress: 2790000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 662284639 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@2d6583 | success or wait | 662335230 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@2d6583 | success or wait | 662546265 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4a427 | success or wait | 662648681 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12a375b | success or wait | 662662445 | 
| Section loaded | Path: C:\WINDOWS\system32\xmllite.dll Access: write and read and execute Type: commit Baseaddress: 2870000 Size: 122880 Protection: execute Mapped to pid: own pid | success or wait | 662679081 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@986c47 | success or wait | 662684461 | 
| Section loaded | Path: C:\WINDOWS\system32\xmllite.dll Access: query and write and read and execute Type: image Baseaddress: 47060000 Size: 135168 Protection: read write Mapped to pid: own pid | success or wait | 662686644 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 663478816 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 663493826 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 663497481 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4a427 | success or wait | 663501248 | 
| Section loaded | Path: C:\WINDOWS\system32\xpsp3res.dll Access: query and read Type: commit Baseaddress: 2AC0000 Size: 692224 Protection: readonly Mapped to pid: own pid | success or wait | 663868643 | 
| Section loaded | Path: C:\WINDOWS\system32\xpsp3res.dll Access: query and read Type: commit Baseaddress: 2AC0000 Size: 692224 Protection: write copy Mapped to pid: own pid | success or wait | 663882023 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Internet Explorer\icon.ico Access: query and read Type: commit Baseaddress: 2AC0000 Size: 8192 Protection: readonly Mapped to pid: own pid | success or wait | 663938277 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Internet Explorer\icon.ico Access: query and read Type: commit Baseaddress: 2AC0000 Size: 8192 Protection: readonly Mapped to pid: own pid | success or wait | 663947799 | 
| Section loaded | Path: \KnownDlls\rasadhlp.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 663967976 | 
| Section loaded | Path: C:\WINDOWS\system32\rasadhlp.dll Access: query and write and read and execute Type: image Baseaddress: 76FC0000 Size: 24576 Protection: read write Mapped to pid: own pid | success or wait | 663969866 | 
| Section loaded | Path: C:\PROGRA~1\MICROS~2\OFFICE11\REFBAR.ICO Access: query and read Type: commit Baseaddress: 2AC0000 Size: 8192 Protection: readonly Mapped to pid: own pid | success or wait | 664005041 | 
| Section loaded | Path: C:\PROGRA~1\MICROS~2\OFFICE11\REFBAR.ICO Access: query and read Type: commit Baseaddress: 2AC0000 Size: 8192 Protection: readonly Mapped to pid: own pid | success or wait | 664019522 | 
| Section loaded | Path: C:\Program Files\Messenger\msmsgs.exe Access: write and read and execute Type: commit Baseaddress: 2B10000 Size: 1695744 Protection: execute Mapped to pid: own pid | success or wait | 664034032 | 
| Section loaded | Path: C:\Program Files\Messenger\msmsgs.exe Access: query and read Type: commit Baseaddress: 2B10000 Size: 1695744 Protection: readonly Mapped to pid: own pid | success or wait | 664042785 | 
| Section loaded | Path: C:\Program Files\Messenger\msmsgs.exe Access: write and read and execute Type: commit Baseaddress: 2B10000 Size: 1695744 Protection: execute Mapped to pid: own pid | success or wait | 664064006 | 
| Section loaded | Path: C:\Program Files\Messenger\msmsgs.exe Access: query and read Type: commit Baseaddress: 2B10000 Size: 1695744 Protection: readonly Mapped to pid: own pid | success or wait | 664070022 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4a427 | success or wait | 664219759 | 
| Thread resumed | TID: 2392 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 664380975 | 
| Thread resumed | TID: 2720 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 664399983 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\iexplore.exe Access: query and write and read and execute and extend size Type: image Baseaddress: 2B10000 Size: 1695744 Protection: readonly Mapped to pid: own pid | success or wait | 664496629 | 
| Section loaded | Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 2C40000 Size: 1208320 Protection: readonly Mapped to pid: own pid | success or wait | 664501781 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 664517300 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 664601192 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 664606321 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 664609473 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\iexplore.exe Access: query and read Type: commit Baseaddress: 2C40000 Size: 638976 Protection: readonly Mapped to pid: own pid | success or wait | 664640210 | 
| Process created | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Cmdline: C:\Program Files\Internet Explorer\IEXPLORE.EXE SCODEF:2116 CREDAT:79873 Createflags: none | success or wait | 664657404 | 
| Process information queried | PID: 2724 Info Class: BasicInformation | success or wait | 664659405 | 
| Process information queried | PID: 2724 Info Class: BasicInformation | success or wait | 664670138 | 
| Process information queried | PID: 2724 Info Class: BasicInformation | success or wait | 665491062 | 
| Process information queried | PID: 2724 Info Class: ImageFileName | success or wait | 665492951 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b6c74 | success or wait | 665496173 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 665496828 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 665498137 | 
| Memory read | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7FFDE000 Length: 2860 Value: FF FF FF FF 00 00 14 00 00 20 13 00 00 00 00 00 00 1E 00 00 00 00 00 00 00 E0 FD 7F 00 00 00 00 A4 0A 00 00 A8 0A 00 00 00 00 00 00 00 00 00 00 00 F0 FD 7F 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 09 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | success or wait | 665502218 | 
| Memory read | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7FFDF000 Length: 488 Value: 00 00 00 00 FF FF FF FF 00 00 40 00 00 00 00 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 FB 7F 00 10 FC 7F 00 20 FD 7F 01 00 00 00 00 00 00 00 00 00 00 00 00 80 9B 07 6D E8 FF FF 00 00 10 00 00 20 00 00 00 00 01 00 00 10 00 00 00 00 00 00 7C 03 00 00 10 F2 FD 7F 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 05 00 00 00 01 00 00 00 28 0A 00 03 02 00 00 00 02 00 00 00 05 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | success or wait | 665508086 | 
| Memory read | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 40003C Length: 4 Value: E0 00 00 00 | success or wait | 665509859 | 
| Memory read | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 4000F8 Length: 24 Value: 0B 01 08 00 00 A0 00 00 00 04 09 00 00 00 00 00 25 1A 00 00 00 10 00 00 | success or wait | 665511129 | 
| Memory allocated | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BAD0000 Length: 13D294 Allocation Type: unknown Protection: page execute and read and write | success or wait | 665513244 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@2d6583 | success or wait | 665516228 | 
| Memory written | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BAD0000 Length: 319488 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 02 00 E6 82 86 4E 00 00 00 00 00 00 00 00 E0 00 02 01 0B 01 0A 00 00 A2 04 | success or wait | 665538178 | 
| Memory read | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 401A25 Length: 5 Value: E8 87 FD FF FF | success or wait | 665543847 | 
| Memory written | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BAFE048 Length: 421 Value: 25 1A 40 00 9B 61 AF 0B E8 87 FD FF FF 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 05 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 E9 71 47 6F 0B 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73 5C 49 6E 74 65 72 6E 65 74 20 45 78 70 6C 6F 72 65 72 5C 69 65 78 70 6C 6F 72 65 2E 65 78 65 00 78 70 6C 6F 72 65 72 5C 69 65 78 70 6C 6F 72 65 2E 65 78 65 00 00 00 00 A0 61 17 00 00 00 00 80 CC 03 1F 00 00 01 00 00 40 05 1F 00 64 D3 13 00 48 04 1F 00 5C 01 | success or wait | 665559888 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 665565394 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 665565820 | 
| Memory written | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 401A25 Length: 5 Value: E9 71 47 6F 0B | success or wait | 665580020 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@986c47 | success or wait | 665580589 | 
| Thread resumed | TID: 2728 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 665583471 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 665704911 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 665717419 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 665722039 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 665724401 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 665736223 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 665746412 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 665763166 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 665778596 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 665785224 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12a375b | success or wait | 666300745 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@986c47 | success or wait | 666327298 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4a427 | success or wait | 666345091 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: EndOfFileInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@451610 | success or wait | 666354942 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: AllocationInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ab8f3f | success or wait | 666442170 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 666836031 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 666839778 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 666843583 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4a427 | success or wait | 666973899 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: EndOfFileInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@451610 | success or wait | 666974749 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: AllocationInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ab8f3f | success or wait | 667106807 | 
| Thread resumed | TID: 3032 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 667538973 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b6c74 | success or wait | 667857546 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4a427 | success or wait | 667860113 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@986c47 | success or wait | 667868472 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 667951519 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 667953498 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 667954556 | 
| Section loaded | Path: \BaseNamedObjects\DfRoot000153E25 Access: query and write and read Type: commit Baseaddress: 2AF0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 668009504 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@2d6583 | success or wait | 668456467 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12a375b | success or wait | 668457035 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@986c47 | success or wait | 668458320 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4a427 | success or wait | 668458819 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: EndOfFileInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@451610 | success or wait | 668458936 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: AllocationInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ab8f3f | success or wait | 668459409 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1f4a427 | success or wait | 668459998 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: EndOfFileInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@451610 | success or wait | 668460118 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{0DD04C9C-4667-11E1-97AA-08002763FBB4}.datNew path: Disposition: AllocationInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1ab8f3f | success or wait | 668460425 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 669225759 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 669228399 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 669229524 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 670300551 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 670302808 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 670303858 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 672104299 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 672110061 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 672113023 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 673268443 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 673304307 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 673308185 | 
| Thread resumed | TID: 3152 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 674021420 | 
| Section loaded | Path: \KnownDlls\SXS.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 674138784 | 
| Section loaded | Path: C:\WINDOWS\system32\sxs.dll Access: query and write and read and execute Type: image Baseaddress: 7E720000 Size: 720896 Protection: read write Mapped to pid: own pid | success or wait | 674141416 | 
| Section loaded | Path: C:\WINDOWS\system32\ieframe.dll Access: query and read Type: commit Baseaddress: 2E40000 Size: 69632 Protection: readonly Mapped to pid: own pid | success or wait | 674361817 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 674386543 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 674391592 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 674394487 | 
| Section loaded | Path: C:\WINDOWS\system32\stdole2.tlb Access: query and read Type: commit Baseaddress: 2E60000 Size: 16384 Protection: readonly Mapped to pid: own pid | success or wait | 674465081 | 
| Section loaded | Path: \BaseNamedObjects\CTF.AsmListCache.FMPDefaultS-1-5-21-507921405-1960408961-839522115-500 Access: query and write and read and execute and extend size Type: unknown Baseaddress: 2E40000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 674561642 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 674632728 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 675488551 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 675505430 | 
| Thread delayed | Time: 0 TID: 2248 | success or wait | 675510915 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 675522311 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 675555879 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 675693627 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 675694620 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 675709129 | 
| Section loaded | Path: \KnownDlls\msfeeds.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 675778681 | 
| Section loaded | Path: C:\WINDOWS\system32\msfeeds.dll Access: query and write and read and execute Type: image Baseaddress: 435A0000 Size: 614400 Protection: read write Mapped to pid: own pid | success or wait | 675789267 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 675880707 | 
| Section loaded | Path: \BaseNamedObjects\Local\Feed Eventing Shared Memory S-1-5-21-507921405-1960408961-839522115-500 Access: query and write and read Type: commit Baseaddress: 2E50000 Size: 548864 Protection: read write Mapped to pid: own pid | success or wait | 675938917 | 
| Section loaded | Path: unknown Access: query and write and read Type: commit Baseaddress: 2860000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 676073706 | 
| Process information queried | PID: 2116 Info Class: SessionInformation | success or wait | 676146331 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 676146995 | 
| Section loaded | Path: C:\WINDOWS\system32\actxprxy.dll Access: write and read and execute Type: commit Baseaddress: 2EE0000 Size: 98304 Protection: execute Mapped to pid: own pid | success or wait | 676309599 | 
| Section loaded | Path: C:\WINDOWS\system32\actxprxy.dll Access: query and write and read and execute Type: image Baseaddress: 71D40000 Size: 110592 Protection: read write Mapped to pid: own pid | success or wait | 676311788 | 
| Section loaded | Path: unknown Access: query and write and read Type: commit Baseaddress: 2860000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 676461413 | 
| Section loaded | Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico Access: query and read Type: commit Baseaddress: 2EE0000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 676747954 | 
| Thread resumed | TID: 3304 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 676851856 | 
| Section loaded | Path: \KnownDlls\msi.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 676873454 | 
| Section loaded | Path: C:\WINDOWS\system32\msi.dll Access: query and write and read and execute Type: image Baseaddress: 7D1E0000 Size: 2867200 Protection: read write Mapped to pid: own pid | success or wait | 676874549 | 
| Process information queried | PID: 2116 Info Class: Wow64Information | success or wait | 676889867 | 
| Process information queried | PID: 2116 Info Class: Wow64Information | success or wait | 676892615 | 
| Process information queried | PID: 2116 Info Class: SessionInformation | success or wait | 677082269 | 
| Section loaded | Path: C:\Program Files\Common Files\Microsoft Shared\INK\SKCHUI.DLL Access: write and read and execute Type: commit Baseaddress: 2FF0000 Size: 368640 Protection: execute Mapped to pid: own pid | success or wait | 677087879 | 
| Section loaded | Path: C:\Program Files\Common Files\Microsoft Shared\INK\SKCHUI.DLL Access: query and write and read and execute Type: image Baseaddress: 10000000 Size: 372736 Protection: read write Mapped to pid: own pid | success or wait | 677090852 | 
| Process information queried | PID: 2116 Info Class: Cookie | success or wait | 677111682 | 
| Process information queried | PID: 2116 Info Class: Cookie | success or wait | 677112011 | 
| Process information queried | PID: 2116 Info Class: SessionInformation | success or wait | 677125577 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI..IEKBFB Access: query and write and read Type: commit Baseaddress: 3130000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677218417 | 
| Process information queried | PID: 2116 Info Class: SessionInformation | success or wait | 677502737 | 
| Process information queried | PID: 2116 Info Class: SessionInformation | success or wait | 677520116 | 
| Process information queried | PID: 2116 Info Class: SessionInformation | success or wait | 677541165 | 
| Process information queried | PID: 2116 Info Class: SessionInformation | success or wait | 677555480 | 
| Section loaded | Path: \KnownDlls\MLANG.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 677566590 | 
| Section loaded | Path: C:\WINDOWS\system32\mlang.dll Access: query and write and read and execute Type: image Baseaddress: 75CF0000 Size: 593920 Protection: read write Mapped to pid: own pid | success or wait | 677567693 | 
| Section loaded | Path: C:\WINDOWS\system32\mlang.dll Access: read Type: commit Baseaddress: 3140000 Size: 589824 Protection: readonly Mapped to pid: own pid | success or wait | 677578155 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 677611802 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 677612152 | 
| File other op | Path: C:\WINDOWS\system32\url.dllNew path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@498364 | success or wait | 677615312 | 
| Section loaded | Path: C:\WINDOWS\system32\url.dll Access: query and read Type: commit Baseaddress: 3140000 Size: 106496 Protection: readonly Mapped to pid: own pid | success or wait | 677617096 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 677669631 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 677669980 | 
| File other op | Path: C:\WINDOWS\system32\url.dllNew path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@498364 | success or wait | 677672185 | 
| Section loaded | Path: C:\WINDOWS\system32\url.dll Access: query and read Type: commit Baseaddress: 3140000 Size: 106496 Protection: readonly Mapped to pid: own pid | success or wait | 677673131 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.Shared.SFM.EMG Access: query and write and read and execute and extend size Type: unknown Baseaddress: 3140000 Size: 524288 Protection: read write Mapped to pid: own pid | success or wait | 677677281 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.B.FMKBFB Access: query and write and read Type: commit Baseaddress: 3130000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677679791 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.C.FMKBFB Access: query and write and read Type: commit Baseaddress: 31C0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677680588 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.D.FMKBFB Access: query and write and read Type: commit Baseaddress: 31E0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677681234 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.E.FNKBFB Access: query and write and read Type: commit Baseaddress: 31F0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677682628 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.F.FNKBFB Access: query and write and read Type: commit Baseaddress: 3200000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677683403 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.G.FNKBFB Access: query and write and read Type: commit Baseaddress: 3210000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677684188 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.H.FNKBFB Access: query and write and read Type: commit Baseaddress: 3220000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677684963 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.I.FNKBFB Access: query and write and read Type: commit Baseaddress: 3230000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677685849 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.J.FNKBFB Access: query and write and read Type: commit Baseaddress: 3240000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677686637 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.K.FNKBFB Access: query and write and read Type: commit Baseaddress: 3130000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677708625 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.L.FNKBFB Access: query and write and read Type: commit Baseaddress: 3130000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677736290 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.M.EOKBFB Access: query and write and read Type: commit Baseaddress: 3130000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677748844 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.N.EOKBFB Access: query and write and read Type: commit Baseaddress: 3130000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677762986 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.O.EOKBFB Access: query and write and read Type: commit Baseaddress: 3130000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677773234 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.P.EOKBFB Access: query and write and read Type: commit Baseaddress: 3130000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677781090 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.AB.EOKBFB Access: query and write and read Type: commit Baseaddress: 3130000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677789941 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.BB.EPKBFB Access: query and write and read Type: commit Baseaddress: 3130000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677800181 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EFI.CB.EPKBFB Access: query and write and read Type: commit Baseaddress: 3130000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677804790 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.HC.EPKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 3130000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677813351 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.IC.EPKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 3130000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677814478 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.JC.EPKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 3130000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677815566 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.KC.EPKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 3130000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677816639 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.LC.EPKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 3130000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677818049 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.MC.EPKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 3130000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677819351 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.NC.EPKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 3130000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677820401 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.OC.EPKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 3130000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677821587 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.PC.EPKBFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 3130000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 677822645 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_IETldCache_index.dat_262144 Access: write Type: unknown Baseaddress: 31E0000 Size: 262144 Protection: read write Mapped to pid: own pid | success or wait | 685273671 | 
| Section loaded | Path: \KnownDlls\USP10.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 694105260 | 
| Section loaded | Path: C:\WINDOWS\system32\usp10.dll Access: query and write and read and execute Type: image Baseaddress: 74D90000 Size: 438272 Protection: read write Mapped to pid: own pid | success or wait | 694108948 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 698871578 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 698893315 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 698911365 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 698919753 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 698919880 | 
| Process information queried | PID: 2116 Info Class: DeviceMap | success or wait | 698934052 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Local Settings_Application Data_Microsoft_Feeds Cache_index.dat_32768 Access: write Type: unknown Baseaddress: 31C0000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 720761324 | 
| Section loaded | Path: \BaseNamedObjects\Local\Feed Arbitration Shared Memory [ User : S-1-5-21-507921405-1960408961-839522115-500 ] Access: query and write and read Type: commit Baseaddress: 3220000 Size: 8192 Protection: read write Mapped to pid: own pid | success or wait | 720846190 | 
| Section loaded | Path: \BaseNamedObjects\DfSharedHeap1594E7 Access: query and write and read Type: reserve Baseaddress: 3230000 Size: 4194304 Protection: read write Mapped to pid: own pid | success or wait | 720891227 | 
| Section loaded | Path: \BaseNamedObjects\DfRoot0001594F0 Access: query and write and read Type: commit Baseaddress: 3630000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 720975644 | 
| Process information queried | PID: 2116 Info Class: QuotaLimits | success or wait | 721034173 | 
| Process information queried | PID: 2116 Info Class: VmCounters | success or wait | 721053822 | 
| Section loaded | Path: \BaseNamedObjects\DFMap0-1414409 Access: query and write and read Type: commit Baseaddress: 3640000 Size: 524288 Protection: read write Mapped to pid: own pid | success or wait | 721054908 | 
| Process information queried | PID: 2116 Info Class: QuotaLimits | success or wait | 721400565 | 
| Process information queried | PID: 2116 Info Class: VmCounters | success or wait | 721401434 | 
| Section loaded | Path: \BaseNamedObjects\DFMap0-1414479 Access: query and write and read Type: commit Baseaddress: 36C0000 Size: 524288 Protection: read write Mapped to pid: own pid | success or wait | 721414678 | 
| Process information queried | PID: 2116 Info Class: SessionInformation | success or wait | 721753932 | 
| Section loaded | Path: C:\WINDOWS\system32\msxml3.dll Access: write and read and execute Type: commit Baseaddress: 3740000 Size: 1175552 Protection: execute Mapped to pid: own pid | success or wait | 721810312 | 
| Section loaded | Path: C:\WINDOWS\system32\msxml3.dll Access: query and write and read and execute Type: image Baseaddress: 74980000 Size: 1191936 Protection: read write Mapped to pid: own pid | success or wait | 721858705 | 
| Section loaded | Path: C:\WINDOWS\system32\msxml3r.dll Access: write and read and execute Type: commit Baseaddress: 3C10000 Size: 45056 Protection: execute Mapped to pid: own pid | success or wait | 723239537 | 
| Section loaded | Path: C:\WINDOWS\system32\msxml3r.dll Access: query and read Type: commit Baseaddress: 3C10000 Size: 45056 Protection: readonly Mapped to pid: own pid | success or wait | 723253244 | 
| Section loaded | Path: \BaseNamedObjects\DfSharedHeap1598E8 Access: query and write and read Type: reserve Baseaddress: 3C40000 Size: 4194304 Protection: read write Mapped to pid: own pid | success or wait | 723303986 | 
| Section loaded | Path: \BaseNamedObjects\DfRoot0001598E8 Access: query and write and read Type: commit Baseaddress: 4040000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723318587 | 
| Process information queried | PID: 2116 Info Class: QuotaLimits | success or wait | 723342793 | 
| Process information queried | PID: 2116 Info Class: VmCounters | success or wait | 723345236 | 
| Section loaded | Path: \BaseNamedObjects\DFMap0-1415443 Access: query and write and read Type: commit Baseaddress: 4050000 Size: 524288 Protection: read write Mapped to pid: own pid | success or wait | 723349377 | 
| Process information queried | PID: 2116 Info Class: QuotaLimits | success or wait | 723671996 | 
| Process information queried | PID: 2116 Info Class: VmCounters | success or wait | 723676202 | 
| Section loaded | Path: \BaseNamedObjects\DFMap0-1415486 Access: query and write and read Type: commit Baseaddress: 40D0000 Size: 524288 Protection: read write Mapped to pid: own pid | success or wait | 723678014 | 
| Section loaded | Path: \BaseNamedObjects\DfSharedHeap159AC9 Access: query and write and read Type: reserve Baseaddress: 4150000 Size: 4194304 Protection: read write Mapped to pid: own pid | success or wait | 723828476 | 
| Section loaded | Path: \BaseNamedObjects\DfRoot000159AD0 Access: query and write and read Type: commit Baseaddress: 4150000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723832709 | 
| Process information queried | PID: 2116 Info Class: QuotaLimits | success or wait | 723846133 | 
| Process information queried | PID: 2116 Info Class: VmCounters | success or wait | 723847810 | 
| Section loaded | Path: \BaseNamedObjects\DFMap0-1415922 Access: query and write and read Type: commit Baseaddress: 4160000 Size: 524288 Protection: read write Mapped to pid: own pid | success or wait | 723848184 | 
| Process information queried | PID: 2116 Info Class: QuotaLimits | success or wait | 723929104 | 
| Process information queried | PID: 2116 Info Class: VmCounters | success or wait | 723929438 | 
| Section loaded | Path: \BaseNamedObjects\DFMap0-1415955 Access: query and write and read Type: commit Baseaddress: 41E0000 Size: 524288 Protection: read write Mapped to pid: own pid | success or wait | 723929815 | 
| Section loaded | Path: unknown Access: query and write and read Type: commit Baseaddress: 4260000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723940935 | 
| Process information queried | PID: 1728 Info Class: BasicInformation | success or wait | 724131252 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.Shared.SFM.EFI Access: query and write and read Type: reserve Baseaddress: 4280000 Size: 524288 Protection: read write Mapped to pid: own pid | success or wait | 724132471 | 
| Section loaded | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\favicon[1].ico Access: query and read Type: commit Baseaddress: 2E40000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 727340609 | 
| Section loaded | Path: C:\WINDOWS\system32\rsaenh.dll Access: query and read Type: commit Baseaddress: 4300000 Size: 208896 Protection: readonly Mapped to pid: own pid | success or wait | 741919581 | 
| Section loaded | Path: C:\WINDOWS\system32\rsaenh.dll Access: query and read Type: commit Baseaddress: 4300000 Size: 208896 Protection: readonly Mapped to pid: own pid | success or wait | 741935937 | 
| Section loaded | Path: \KnownDlls\rsaenh.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 743882913 | 
| Section loaded | Path: C:\WINDOWS\system32\rsaenh.dll Access: query and write and read and execute Type: image Baseaddress: 68000000 Size: 221184 Protection: read write Mapped to pid: own pid | success or wait | 743885677 | 
| Section loaded | Path: C:\WINDOWS\system32\rsaenh.dll Access: query and read Type: commit Baseaddress: 4300000 Size: 208896 Protection: readonly Mapped to pid: own pid | success or wait | 743940336 | 
| Thread created | PID: 2116 TID: 3680 EIP: 7C8106F9 Imagepath: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 763984359 | 
| Thread resumed | TID: 3680 PID: 2116 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 764000798 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | success or wait | 764012417 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 764015340 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 764048401 | 
| Sections | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| File Activities: 
 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Section Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Registry Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Mutant Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Process Activities: 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Thread Activities: 
 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Memory Activities: 
 
 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Chronological sections | |||
| Operation | Data | Completion | Time | 
| Section loaded | Path: \KnownDlls\kernel32.dll Access: write and read and execute Type: unknown Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid | success or wait | 665602146 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 665609684 | 
| Section loaded | Path: unknown Access: query and write and read and execute and extend size Type: reserve Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid | success or wait | 665616024 | 
| Section loaded | Path: \NLS\NlsSectionUnicode Access: read Type: unknown Baseaddress: 270000 Size: 90112 Protection: readonly Mapped to pid: own pid | success or wait | 665635977 | 
| Section loaded | Path: \NLS\NlsSectionLocale Access: read Type: unknown Baseaddress: 290000 Size: 266240 Protection: readonly Mapped to pid: own pid | success or wait | 665640437 | 
| Section loaded | Path: \NLS\NlsSectionSortkey Access: query and read Type: unknown Baseaddress: 2E0000 Size: 266240 Protection: readonly Mapped to pid: own pid | success or wait | 665642353 | 
| Section loaded | Path: \NLS\NlsSectionSortTbls Access: read Type: unknown Baseaddress: 330000 Size: 24576 Protection: readonly Mapped to pid: own pid | success or wait | 665648007 | 
| Section loaded | Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 665649577 | 
| Section loaded | Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 665653632 | 
| Section loaded | Path: \KnownDlls\ADVAPI32.dll Access: write and read and execute Type: unknown Baseaddress: 77DD0000 Size: 634880 Protection: read write Mapped to pid: own pid | success or wait | 665655030 | 
| Section loaded | Path: \KnownDlls\RPCRT4.dll Access: write and read and execute Type: unknown Baseaddress: 77E70000 Size: 602112 Protection: read write Mapped to pid: own pid | success or wait | 665661565 | 
| Section loaded | Path: \KnownDlls\Secur32.dll Access: write and read and execute Type: unknown Baseaddress: 77FE0000 Size: 69632 Protection: read write Mapped to pid: own pid | success or wait | 665673229 | 
| Section loaded | Path: \KnownDlls\USER32.dll Access: write and read and execute Type: unknown Baseaddress: 7E410000 Size: 593920 Protection: read write Mapped to pid: own pid | success or wait | 665700945 | 
| Section loaded | Path: \KnownDlls\GDI32.dll Access: write and read and execute Type: unknown Baseaddress: 77F10000 Size: 299008 Protection: read write Mapped to pid: own pid | success or wait | 665706857 | 
| Section loaded | Path: \KnownDlls\msvcrt.dll Access: write and read and execute Type: unknown Baseaddress: 77C10000 Size: 360448 Protection: read write Mapped to pid: own pid | success or wait | 665741784 | 
| Section loaded | Path: \KnownDlls\SHLWAPI.dll Access: write and read and execute Type: unknown Baseaddress: 77F60000 Size: 483328 Protection: read write Mapped to pid: own pid | success or wait | 665757599 | 
| Section loaded | Path: \KnownDlls\SHELL32.dll Access: write and read and execute Type: unknown Baseaddress: 7C9C0000 Size: 8482816 Protection: read write Mapped to pid: own pid | success or wait | 665776950 | 
| Section loaded | Path: \KnownDlls\ole32.dll Access: write and read and execute Type: unknown Baseaddress: 774E0000 Size: 1302528 Protection: read write Mapped to pid: own pid | success or wait | 665794590 | 
| Section loaded | Path: \KnownDlls\iertutil.dll Access: write and read and execute Type: unknown Baseaddress: 3DFD0000 Size: 2002944 Protection: read write Mapped to pid: own pid | success or wait | 665800751 | 
| Section loaded | Path: \KnownDlls\urlmon.dll Access: write and read and execute Type: unknown Baseaddress: 78130000 Size: 1257472 Protection: read write Mapped to pid: own pid | success or wait | 665806072 | 
| Section loaded | Path: \KnownDlls\OLEAUT32.dll Access: write and read and execute Type: unknown Baseaddress: 77120000 Size: 569344 Protection: read write Mapped to pid: own pid | success or wait | 665809259 | 
| Section loaded | Path: \KnownDlls\ShimEng.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 665819522 | 
| Section loaded | Path: C:\WINDOWS\system32\shimeng.dll Access: query and write and read and execute Type: image Baseaddress: 5CB70000 Size: 155648 Protection: read write Mapped to pid: own pid | success or wait | 665820843 | 
| Section loaded | Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 4A0000 Size: 1208320 Protection: readonly Mapped to pid: own pid | success or wait | 665826845 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 665828516 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 665829788 | 
| Section loaded | Path: C:\WINDOWS\AppPatch\aclayers.dll Access: write and read and execute Type: commit Baseaddress: 350000 Size: 475136 Protection: execute Mapped to pid: own pid | success or wait | 665836011 | 
| Section loaded | Path: C:\WINDOWS\AppPatch\aclayers.dll Access: write and read and execute Type: commit Baseaddress: 350000 Size: 475136 Protection: execute Mapped to pid: own pid | success or wait | 665838383 | 
| Section loaded | Path: C:\WINDOWS\AppPatch\aclayers.dll Access: query and write and read and execute Type: image Baseaddress: 71590000 Size: 495616 Protection: read write Mapped to pid: own pid | success or wait | 665840404 | 
| Section loaded | Path: \KnownDlls\USERENV.dll Access: write and read and execute Type: unknown Baseaddress: 769C0000 Size: 737280 Protection: read write Mapped to pid: own pid | success or wait | 665846368 | 
| Section loaded | Path: \KnownDlls\WINSPOOL.DRV Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 665851596 | 
| Section loaded | Path: C:\WINDOWS\system32\winspool.drv Access: query and write and read and execute Type: image Baseaddress: 73000000 Size: 155648 Protection: read write Mapped to pid: own pid | success or wait | 665852927 | 
| Section loaded | Path: \NLS\NlsSectionCType Access: read Type: unknown Baseaddress: 360000 Size: 12288 Protection: readonly Mapped to pid: own pid | success or wait | 665861011 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 665863182 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 665863812 | 
| Process information queried | PID: 2724 Info Class: ImageInformation | success or wait | 666034442 | 
| Section loaded | Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit Baseaddress: 3B0000 Size: 110592 Protection: execute Mapped to pid: own pid | success or wait | 666075636 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666078452 | 
| Section loaded | Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit Baseaddress: 3B0000 Size: 110592 Protection: execute Mapped to pid: own pid | success or wait | 666079641 | 
| Section loaded | Path: C:\WINDOWS\system32\imm32.dll Access: query and write and read and execute Type: image Baseaddress: 76390000 Size: 118784 Protection: read write Mapped to pid: own pid | success or wait | 666081844 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666089920 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 666100029 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 666100248 | 
| Section loaded | Path: C:\WINDOWS\system32\shell32.dll Access: read Type: commit Baseaddress: 980000 Size: 8462336 Protection: readonly Mapped to pid: own pid | success or wait | 666104736 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666142871 | 
| Section loaded | Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll Access: write and read and execute Type: commit Baseaddress: 980000 Size: 1056768 Protection: execute Mapped to pid: own pid | success or wait | 666145335 | 
| Section loaded | Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll Access: query and write and read and execute Type: image Baseaddress: 773D0000 Size: 1060864 Protection: read write Mapped to pid: own pid | success or wait | 666149075 | 
| Section loaded | Path: C:\WINDOWS\WindowsShell.Manifest Access: write and read and execute Type: commit Baseaddress: 3E0000 Size: 4096 Protection: execute Mapped to pid: own pid | success or wait | 666167145 | 
| Section loaded | Path: C:\WINDOWS\WindowsShell.Manifest Access: query and read Type: commit Baseaddress: 3E0000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 666171478 | 
| Section loaded | Path: C:\WINDOWS\WindowsShell.Manifest Access: read Type: commit Baseaddress: 3E0000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 666173989 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666201374 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666201654 | 
| Section loaded | Path: \KnownDlls\comctl32.dll Access: write and read and execute Type: unknown Baseaddress: 5D090000 Size: 630784 Protection: read write Mapped to pid: own pid | success or wait | 666201996 | 
| Section loaded | Path: C:\WINDOWS\system32\comctl32.dll Access: read Type: commit Baseaddress: 980000 Size: 618496 Protection: readonly Mapped to pid: own pid | success or wait | 666216626 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 666227567 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666230170 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666230587 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666231749 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666272083 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666273744 | 
| Section loaded | Path: \KnownDlls\CRYPT32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 666290717 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and write and read and execute Type: image Baseaddress: 77A80000 Size: 610304 Protection: read write Mapped to pid: own pid | success or wait | 666292289 | 
| Section loaded | Path: \KnownDlls\MSASN1.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 666296617 | 
| Section loaded | Path: C:\WINDOWS\system32\msasn1.dll Access: query and write and read and execute Type: image Baseaddress: 77B20000 Size: 73728 Protection: read write Mapped to pid: own pid | success or wait | 666297976 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666312233 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666312538 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666313590 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666313883 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666314776 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666315080 | 
| Section loaded | Path: \KnownDlls\WS2_32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 666316958 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and write and read and execute Type: image Baseaddress: 71AB0000 Size: 94208 Protection: read write Mapped to pid: own pid | success or wait | 666318265 | 
| Section loaded | Path: \KnownDlls\WS2HELP.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 666323428 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2help.dll Access: query and write and read and execute Type: image Baseaddress: 71AA0000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 666324772 | 
| Section loaded | Path: \KnownDlls\WININET.dll Access: write and read and execute Type: unknown Baseaddress: 3D930000 Size: 942080 Protection: read write Mapped to pid: own pid | success or wait | 666336286 | 
| Section loaded | Path: \KnownDlls\Normaliz.dll Access: write and read and execute Type: unknown Baseaddress: 9A0000 Size: 36864 Protection: read write Mapped to pid: own pid | conflicting addresses | 666342715 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666383295 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666400867 | 
| Section loaded | Path: \KnownDlls\MSIMG32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 666411652 | 
| Section loaded | Path: C:\WINDOWS\system32\msimg32.dll Access: query and write and read and execute Type: image Baseaddress: 76380000 Size: 20480 Protection: read write Mapped to pid: own pid | success or wait | 666412966 | 
| Thread created | PID: 2724 TID: 2864 EIP: 7C8106F9 Imagepath: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 666419499 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 666421039 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 666421702 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 666422502 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@16bc6e5 | success or wait | 666423189 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 666423406 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@cf0d1f | success or wait | 666423902 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 666424107 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 666424362 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1668534 | success or wait | 666424840 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 666425045 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b3409f | success or wait | 666425653 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 666425922 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7C90D76E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666428252 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BAFEA50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666428490 | 
| Thread created | PID: 2724 TID: 2868 EIP: 7C8106F9 Imagepath: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 666429864 | 
| Thread created | PID: 2724 TID: 2872 EIP: 7C8106F9 Imagepath: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 666432074 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 666435418 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 666435557 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666435705 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 666436552 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 666436903 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 666437736 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@16bc6e5 | success or wait | 666438421 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 666438629 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@cf0d1f | success or wait | 666438938 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 666439141 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 666439637 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1668534 | success or wait | 666440130 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 666440335 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b3409f | success or wait | 666440755 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 666441023 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7C90DF1E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666444455 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB186C0 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666444693 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666444935 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 666445719 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@16bc6e5 | success or wait | 666446398 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 666446605 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@cf0d1f | success or wait | 666446911 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 666447116 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 666447360 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1668534 | success or wait | 666447838 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 666448042 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b3409f | success or wait | 666448459 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 666448727 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7C90DC5E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666450931 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB06F28 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666451166 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666451406 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 666452184 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@16bc6e5 | success or wait | 666452860 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 666453069 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@cf0d1f | success or wait | 666453381 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 666453586 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 666453831 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1668534 | success or wait | 666454373 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 666454579 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b3409f | success or wait | 666455003 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 666455271 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7C90D2EE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666457475 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB04B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666457713 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 666458106 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666458314 | 
| File opened | Path: C:\WINDOWS\system32\ntdll.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 666459095 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@16bc6e5 | success or wait | 666459774 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 4 Value: D0 00 00 00 | success or wait | 666459982 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@cf0d1f | success or wait | 666460296 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 20 Value: 4C 01 04 00 7D F2 00 4D 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 666460501 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 D0 07 00 00 3C 03 00 00 00 00 00 F8 20 01 00 00 10 00 00 00 90 07 00 00 00 90 7C 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 20 0B 00 00 04 00 00 30 FD 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 34 00 00 | success or wait | 666460746 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1668534 | success or wait | 666461230 | 
| File read | Path: C:\WINDOWS\system32\ntdll.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 DA CE 07 00 00 10 00 00 00 D0 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 20 4A 00 00 00 E0 07 00 00 32 00 00 00 D4 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 78 BE 02 00 00 30 08 00 00 C0 02 00 | success or wait | 666461435 | 
| File other op | Path: C:\WINDOWS\system32\ntdll.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b3409f | success or wait | 666461860 | 
| Section loaded | Path: C:\WINDOWS\system32\ntdll.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 666462128 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7C90DB3E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666464331 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB17D98 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666464566 | 
| Section loaded | Path: \KnownDlls\nspr4.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 666465424 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 666467381 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 666468611 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 666484480 | 
| File opened | Path: C:\WINDOWS\system32\USER32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 666485311 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@15789a5 | success or wait | 666486011 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 4 Value: D8 00 00 00 | success or wait | 666486229 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@dce12 | success or wait | 666486740 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 1B A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 666486955 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 F4 05 00 00 E2 02 00 00 00 00 00 17 B2 00 00 00 10 00 00 00 B0 05 00 00 00 41 7E 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 10 09 00 00 04 00 00 76 FC 08 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 39 00 00 | success or wait | 666487210 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@543937 | success or wait | 666487705 | 
| File read | Path: C:\WINDOWS\system32\user32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 83 F2 05 00 00 10 00 00 00 F4 05 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 80 11 00 00 00 10 06 00 00 0C 00 00 00 F8 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 88 A0 02 00 00 30 06 00 00 A2 02 00 | success or wait | 666487919 | 
| File other op | Path: C:\WINDOWS\system32\user32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1785762 | success or wait | 666488353 | 
| Section loaded | Path: C:\WINDOWS\system32\user32.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 57344 Protection: readonly Mapped to pid: own pid | success or wait | 666488631 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 7E418BF6 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666490915 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB03E40 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666491161 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 666491480 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 666492277 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b0eadd | success or wait | 666492967 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 666493239 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b6680 | success or wait | 666493805 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 666494015 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 666494266 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@765e8c | success or wait | 666494756 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 666494966 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1395750 | success or wait | 666495637 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 666495915 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D949088 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666498565 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB189C8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666498801 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 666499113 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 666499919 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b0eadd | success or wait | 666500609 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 666500822 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b6680 | success or wait | 666501140 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 666501349 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 666501599 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@765e8c | success or wait | 666502087 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 666502297 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1395750 | success or wait | 666502725 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 666502996 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D95EE89 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666505649 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB18118 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666505882 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 666506194 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 666506996 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b0eadd | success or wait | 666507939 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 666508153 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b6680 | success or wait | 666508470 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 666508679 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 666508930 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@765e8c | success or wait | 666509419 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 666509628 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1395750 | success or wait | 666510056 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 666510328 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94FABE Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666513011 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BAFE1F8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666513246 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 666513859 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 666514646 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b0eadd | success or wait | 666515332 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 666515545 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b6680 | success or wait | 666515862 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 666516071 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 666516322 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@765e8c | success or wait | 666516811 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 666517019 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1395750 | success or wait | 666517447 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 666517720 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D9A608E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666520300 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB07290 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666520533 | 
| File opened | Path: C:\Recycle.Bin\5CBD14A05E0D693 Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: normal Content Overwritten: null | success or wait | 666521284 | 
| File read | Path: C:\Recycle.Bin\5CBD14A05E0D693 Offset: unknown Length: 10807 Value: 50 D7 96 D6 A6 EA BF F3 B7 FB 6D B6 92 9E D2 9E D2 9E D2 9E D2 9E E1 AE E2 AE F4 B8 85 C9 60 83 BD 6F 94 B7 A9 41 EE 2E CF 6F 30 7C CF 42 5B 28 3B 77 3B 77 FB 0A 1A 56 16 86 DC FB A0 A1 40 4A 3C 75 30 2E 9F B9 7C 87 0F 14 67 74 8C 8A DC 66 86 19 1E 35 DC 5C 9A 1C C4 1F 23 22 65 21 A9 27 1D C8 A5 E9 | success or wait | 666522090 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 666541431 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 666542248 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b0eadd | success or wait | 666542727 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 666542821 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b6680 | success or wait | 666542963 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 666543055 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 666543164 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@765e8c | success or wait | 666543379 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 666543471 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1395750 | success or wait | 666543971 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 666544102 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94D508 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666545897 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB07A10 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666546129 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 666546418 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 666547301 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b0eadd | success or wait | 666547991 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 666548204 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b6680 | success or wait | 666548522 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 666548731 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 666548977 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@765e8c | success or wait | 666549464 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 666549672 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1395750 | success or wait | 666550099 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 666550371 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94CF4E Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666553963 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB18B88 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666554203 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 666554490 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 666555300 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b0eadd | success or wait | 666555990 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 666556205 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b6680 | success or wait | 666556524 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 666556734 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 666556982 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@765e8c | success or wait | 666557470 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 666557679 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1395750 | success or wait | 666558105 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 666558376 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94878D Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666560970 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB05310 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666561209 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 666561497 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 666562299 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b0eadd | success or wait | 666562982 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 666563195 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b6680 | success or wait | 666563513 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 666563722 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 666563969 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@765e8c | success or wait | 666564456 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 666564664 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1395750 | success or wait | 666565089 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 666565361 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D940049 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666567955 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB18ED8 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666568187 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 666568475 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 666569282 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b0eadd | success or wait | 666570079 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 666570293 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b6680 | success or wait | 666570612 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 666570871 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 666571123 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@765e8c | success or wait | 666571611 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 666571821 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1395750 | success or wait | 666572248 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 666572518 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94BF83 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666575116 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB04D50 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666575357 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 666575646 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 666576446 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b0eadd | success or wait | 666577130 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 666577341 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b6680 | success or wait | 666577659 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 666577868 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 666578116 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@765e8c | success or wait | 666578604 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 666578813 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1395750 | success or wait | 666579238 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 666579834 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D94654B Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666582422 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB05538 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666582655 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 666583014 | 
| File opened | Path: C:\WINDOWS\system32\WININET.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 666583815 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b0eadd | success or wait | 666584504 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 4 Value: F8 00 00 00 | success or wait | 666584714 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@b6680 | success or wait | 666585032 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D8 ED 0F 4D 00 00 00 00 00 00 00 00 E0 00 02 21 | success or wait | 666585239 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 224 Value: 0B 01 08 00 00 FA 0A 00 00 34 03 00 00 00 00 00 48 17 00 00 00 10 00 00 00 50 0C 00 00 00 93 3D 00 10 00 00 00 02 00 00 06 00 00 00 06 00 00 00 05 00 01 00 00 00 00 00 00 60 0E 00 00 04 00 00 8F D2 0E 00 02 00 40 01 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 F8 18 00 00 | success or wait | 666585487 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@765e8c | success or wait | 666585973 | 
| File read | Path: C:\WINDOWS\system32\wininet.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 B0 F9 0A 00 00 10 00 00 00 FA 0A 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 50 68 00 00 00 10 0B 00 00 34 00 00 00 FE 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 C0 61 02 00 00 80 0B 00 00 62 02 00 | success or wait | 666586182 | 
| File other op | Path: C:\WINDOWS\system32\wininet.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1395750 | success or wait | 666586607 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 65536 Protection: readonly Mapped to pid: own pid | success or wait | 666586878 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 3D963381 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666589465 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BAFE698 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666589697 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute read | success or wait | 666590139 | 
| File opened | Path: C:\WINDOWS\system32\WS2_32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 666590943 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1935e6f | success or wait | 666591627 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 666591841 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1cdfc2 | success or wait | 666592407 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 63 A1 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 666592617 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 22 01 00 00 1C 00 00 00 00 00 00 73 12 00 00 00 10 00 00 00 20 01 00 00 00 AB 71 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 0A 00 00 00 00 00 00 70 01 00 00 04 00 00 20 F0 01 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 04 14 00 00 | success or wait | 666592865 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a666bf | success or wait | 666593355 | 
| File read | Path: C:\WINDOWS\system32\ws2_32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 53 21 01 00 00 10 00 00 00 22 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 14 09 00 00 00 40 01 00 00 0A 00 00 00 26 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 F8 03 00 00 00 50 01 00 00 04 00 00 | success or wait | 666593564 | 
| File other op | Path: C:\WINDOWS\system32\ws2_32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a3ae73 | success or wait | 666593988 | 
| Section loaded | Path: C:\WINDOWS\system32\ws2_32.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 20480 Protection: readonly Mapped to pid: own pid | success or wait | 666594258 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 71AB4C27 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666596263 | 
| Memory attributes changed | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: BB18D30 Length: 2000 New Protection: page execute and read and write New Protection: page execute and read and write | success or wait | 666596497 | 
| File opened | Path: C:\WINDOWS\system32\ADVAPI32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 666597662 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1121b88 | success or wait | 666598351 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 666598564 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1cd846c | success or wait | 666599131 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 48 1D 90 49 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 666599342 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 46 07 00 00 3E 02 00 00 00 00 00 0B 71 00 00 00 10 00 00 00 20 07 00 00 00 DD 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 B0 09 00 00 04 00 00 B8 5B 0A 00 03 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 A4 16 00 00 | success or wait | 666599593 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1b0dec3 | success or wait | 666600081 | 
| File read | Path: C:\WINDOWS\system32\advapi32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C9 45 07 00 00 10 00 00 00 46 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 28 46 00 00 00 60 07 00 00 2C 00 00 00 4A 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 80 A9 01 00 00 B0 07 00 00 AA 01 00 | success or wait | 666600291 | 
| File other op | Path: C:\WINDOWS\system32\advapi32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@f10c77 | success or wait | 666600715 | 
| Section loaded | Path: C:\WINDOWS\system32\advapi32.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 28672 Protection: readonly Mapped to pid: own pid | success or wait | 666600988 | 
| File opened | Path: C:\WINDOWS\system32\CRYPT32.dll Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file and random access Attributes: none Content Overwritten: null | success or wait | 666604910 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@16995a2 | success or wait | 666605596 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 4 Value: F0 00 00 00 | success or wait | 666605809 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@dee55c | success or wait | 666606374 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 20 Value: 4C 01 04 00 D7 A0 02 48 00 00 00 00 00 00 00 00 E0 00 0E 21 | success or wait | 666606584 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 224 Value: 0B 01 07 0A 00 44 08 00 00 DC 00 00 00 00 00 00 32 16 00 00 00 10 00 00 00 20 08 00 00 00 A8 77 00 10 00 00 00 02 00 00 05 00 01 00 05 00 01 00 04 00 00 00 00 00 00 00 00 50 09 00 00 04 00 00 30 C5 09 00 02 00 00 00 00 00 04 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 9C 1A 00 00 | success or wait | 666606835 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a3fb76 | success or wait | 666607994 | 
| File read | Path: C:\WINDOWS\system32\crypt32.dll Offset: unknown Length: 160 Value: 2E 74 65 78 74 00 00 00 C4 43 08 00 00 10 00 00 00 44 08 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2E 64 61 74 61 00 00 00 E8 23 00 00 00 60 08 00 00 24 00 00 00 48 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0 2E 72 73 72 63 00 00 00 50 67 00 00 00 90 08 00 00 68 00 00 | success or wait | 666608206 | 
| File other op | Path: C:\WINDOWS\system32\crypt32.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@d21555 | success or wait | 666608637 | 
| Section loaded | Path: C:\WINDOWS\system32\crypt32.dll Access: query and read Type: commit Baseaddress: 9C0000 Size: 77824 Protection: readonly Mapped to pid: own pid | success or wait | 666608910 | 
| Mutant created | Name: \BaseNamedObjects\Global\ch971pGLCYGJFFTTU5XPPGQTZJ8OdYB | object name exists | 666611901 | 
| Thread created | PID: 2724 TID: 2876 EIP: 7C8106F9 Imagepath: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 666613366 | 
| Thread resumed | TID: 2876 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 666614144 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | success or wait | 666614955 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 666616267 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 666617262 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 666618010 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 666648883 | 
| Memory allocated | PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe Base: 9C0000 Length: 102FF30 Allocation Type: unknown Protection: page execute and read and write | success or wait | 666688023 | 
| Thread created | PID: 2724 TID: 2884 EIP: 7C8106F9 Imagepath: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 666690585 | 
| Thread resumed | TID: 2884 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 666691211 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 666692384 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 666692582 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 666697149 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666699217 | 
| Thread created | PID: 2724 TID: 2888 EIP: 7C8106F9 Imagepath: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 666699651 | 
| Thread resumed | TID: 2888 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 666704994 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666706431 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666707197 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666712498 | 
| Section loaded | Path: \KnownDlls\IEFRAME.dll Access: write and read and execute Type: unknown Baseaddress: 3E1C0000 Size: 11096064 Protection: read write Mapped to pid: own pid | success or wait | 666713341 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666746118 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666746931 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666747718 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666748495 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666749273 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666750047 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666750829 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666751604 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666752380 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666753158 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666753934 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666754708 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666846367 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666849116 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666850371 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666851635 | 
| Section loaded | Path: C:\WINDOWS\system32\en-us\ieframe.dll.mui Access: query and read Type: commit Baseaddress: 1130000 Size: 1241088 Protection: write copy Mapped to pid: own pid | success or wait | 666856661 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666879346 | 
| Section loaded | Path: \BaseNamedObjects\Internet Explorer Immutable Application State (00000844-0000-0000-0000-000000000000) Access: read Type: unknown Baseaddress: 9E0000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 666894946 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 666899782 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 666900117 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 666900462 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 666900788 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 666901128 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 666901776 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666906251 | 
| Section loaded | Path: \KnownDlls\comdlg32.dll Access: write and read and execute Type: unknown Baseaddress: 763B0000 Size: 299008 Protection: read write Mapped to pid: own pid | success or wait | 666907101 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666928061 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666964153 | 
| Section loaded | Path: \KnownDlls\xpshims.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 666964995 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\xpshims.dll Access: query and write and read and execute Type: image Baseaddress: 451F0000 Size: 24576 Protection: read write Mapped to pid: own pid | success or wait | 666967514 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 666989870 | 
| Section loaded | Path: C:\WINDOWS\system32\rpcss.dll Access: write and read and execute Type: commit Baseaddress: F30000 Size: 401408 Protection: execute Mapped to pid: own pid | success or wait | 667013875 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 667103365 | 
| Section loaded | Path: C:\WINDOWS\system32\msctf.dll Access: write and read and execute Type: commit Baseaddress: F30000 Size: 299008 Protection: execute Mapped to pid: own pid | success or wait | 667105621 | 
| Section loaded | Path: C:\WINDOWS\system32\msctf.dll Access: query and write and read and execute Type: image Baseaddress: 74720000 Size: 311296 Protection: read write Mapped to pid: own pid | success or wait | 667111784 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 667132932 | 
| Section loaded | Path: \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-507921405-1960408961-839522115-500 Access: query and write and read Type: commit Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name exists | 667135189 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 667150588 | 
| Section loaded | Path: \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-507921405-1960408961-839522115-500SFM.DefaultS-1-5-21-507921405-1960408961-839522115-500 Access: query and write and read and execute and extend size Type: unknown Baseaddress: F30000 Size: 262144 Protection: read write Mapped to pid: own pid | success or wait | 667152739 | 
| Section loaded | Path: \BaseNamedObjects\ie_lcie_main_844_S-1-5-21-507921405-1960408961-839522115-500 Access: query and write and read Type: commit Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name exists | 667159587 | 
| Section loaded | Path: \BaseNamedObjects\Isolation Process Registry (0DD04C9B-4667-11E1-97AA-08002763FBB4) Access: query and write and read Type: commit Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name exists | 667162460 | 
| Section loaded | Path: \BaseNamedObjects\Isolation Signal Registry (0DD04C9B-4667-11E1-97AA-08002763FBB4, 0) Access: query and write and read Type: commit Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name exists | 667164240 | 
| Thread resumed | TID: 2940 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 667171701 | 
| Thread resumed | TID: 2944 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 667177375 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 667185013 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 667185806 | 
| Process information queried | PID: 2724 Info Class: QuotaLimits | success or wait | 667191985 | 
| Process information queried | PID: 2724 Info Class: VmCounters | success or wait | 667192814 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 667193627 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 667194412 | 
| Thread resumed | TID: 2952 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 667202066 | 
| Thread resumed | TID: 2956 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 667208816 | 
| Process information queried | PID: 2724 Info Class: DefaultHardErrorMode | success or wait | 667213986 | 
| Thread resumed | TID: 2960 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 667215741 | 
| Thread resumed | TID: 2964 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 667227427 | 
| Section loaded | Path: C:\WINDOWS\system32\winlogon.exe Access: write and read and execute Type: commit Baseaddress: 1A60000 Size: 507904 Protection: execute Mapped to pid: own pid | success or wait | 667233553 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\sqmapi.dll Access: write and read and execute Type: commit Baseaddress: FE0000 Size: 135168 Protection: execute Mapped to pid: own pid | success or wait | 667258454 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\sqmapi.dll Access: query and write and read and execute Type: image Baseaddress: 6CD00000 Size: 147456 Protection: read write Mapped to pid: own pid | success or wait | 667265625 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 667286845 | 
| Section loaded | Path: \KnownDlls\xpsp2res.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 667286998 | 
| Section loaded | Path: C:\WINDOWS\system32\xpsp2res.dll Access: query and write and read and execute Type: image Baseaddress: 1A60000 Size: 2904064 Protection: read write Mapped to pid: own pid | conflicting addresses | 667287588 | 
| File other op | Path: \lsarpcNew path: Disposition: PipeInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@76a6d9 | success or wait | 667296104 | 
| File other op | Path: \lsarpcNew path: Disposition: CompletionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1c42c4b | success or wait | 667296268 | 
| Thread resumed | TID: 2968 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 667311914 | 
| Thread resumed | TID: 2972 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 667318733 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 667361291 | 
| Section loaded | Path: \KnownDlls\SETUPAPI.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 667362055 | 
| Section loaded | Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid: own pid | success or wait | 667363139 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 667371993 | 
| Section loaded | Path: \KnownDlls\CLBCATQ.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 667387677 | 
| Section loaded | Path: C:\WINDOWS\system32\clbcatq.dll Access: query and write and read and execute Type: image Baseaddress: 76FD0000 Size: 520192 Protection: read write Mapped to pid: own pid | success or wait | 667388385 | 
| Section loaded | Path: \KnownDlls\COMRes.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 667392206 | 
| Section loaded | Path: C:\WINDOWS\system32\comres.dll Access: query and write and read and execute Type: image Baseaddress: 77050000 Size: 806912 Protection: read write Mapped to pid: own pid | success or wait | 667393576 | 
| Section loaded | Path: \KnownDlls\VERSION.dll Access: write and read and execute Type: unknown Baseaddress: 77C00000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 667401269 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 667430592 | 
| File other op | Path: C:\WINDOWS\Registration\R000000000010.clbNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@37fd24 | success or wait | 667438257 | 
| File other op | Path: C:\WINDOWS\Registration\R000000000010.clbNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1cc55fb | success or wait | 667438880 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\ieproxy.dll Access: write and read and execute Type: commit Baseaddress: FF0000 Size: 249856 Protection: execute Mapped to pid: own pid | success or wait | 667479969 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\ieproxy.dll Access: query and write and read and execute Type: image Baseaddress: 439B0000 Size: 262144 Protection: read write Mapped to pid: own pid | success or wait | 667487594 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 667491741 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 667492099 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 667493407 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 667502314 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 667502474 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 667502625 | 
| Thread resumed | TID: 3036 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 667541925 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 667567737 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 667579623 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet FilesNew path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@210a0e | success or wait | 667582378 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5New path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11b1e39 | success or wait | 667583493 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 667586690 | 
| Section loaded | Path: \BaseNamedObjects\Local\IEFrame!GetAsyncKeyStateSharedMem!2116 Access: query and write and read Type: commit Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name exists | 667594151 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\HistoryNew path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@15d54a7 | success or wait | 667598205 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\History\History.IE5New path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@60c384 | success or wait | 667600204 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5New path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11b1e39 | success or wait | 667602168 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.datNew path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c449c6 | success or wait | 667603025 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Local Settings_Temporary Internet Files_Content.IE5_index.dat_32768 Access: write Type: unknown Baseaddress: 1010000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 667603360 | 
| File other op | Path: C:\Documents and Settings\Administrator\CookiesNew path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@c77e26 | success or wait | 667604345 | 
| File other op | Path: C:\Documents and Settings\Administrator\Cookies\index.datNew path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@12b1e53 | success or wait | 667605327 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Cookies_index.dat_16384 Access: write Type: unknown Baseaddress: 1020000 Size: 16384 Protection: read write Mapped to pid: own pid | success or wait | 667605635 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\History\History.IE5New path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@60c384 | success or wait | 667606628 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.datNew path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1d3e3f3 | success or wait | 667607529 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Local Settings_History_History.IE5_index.dat_32768 Access: write Type: unknown Baseaddress: 2030000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 667607835 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5New path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@11b1e39 | success or wait | 667608794 | 
| File other op | Path: C:\Documents and Settings\Administrator\Local Settings\History\History.IE5New path: Disposition: BasicInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@60c384 | success or wait | 667609674 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 667888580 | 
| Section loaded | Path: \BaseNamedObjects\windows_ie_global_counters Access: write and read Type: unknown Baseaddress: 2040000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 667889399 | 
| Process information queried | PID: 2116 Info Class: SessionInformation | success or wait | 667889781 | 
| Section loaded | Path: \KnownDlls\MLANG.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 667906373 | 
| Section loaded | Path: C:\WINDOWS\system32\mlang.dll Access: query and write and read and execute Type: image Baseaddress: 75CF0000 Size: 593920 Protection: read write Mapped to pid: own pid | success or wait | 667907338 | 
| Section loaded | Path: C:\WINDOWS\system32\mlang.dll Access: read Type: commit Baseaddress: 2080000 Size: 589824 Protection: readonly Mapped to pid: own pid | success or wait | 667914454 | 
| Section loaded | Path: \KnownDlls\UxTheme.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 667937886 | 
| Section loaded | Path: C:\WINDOWS\system32\uxtheme.dll Access: query and write and read and execute Type: image Baseaddress: 5AD70000 Size: 229376 Protection: read write Mapped to pid: own pid | success or wait | 667939214 | 
| Section loaded | Path: C:\WINDOWS\system32\msctfime.ime Access: write and read and execute Type: commit Baseaddress: 2080000 Size: 180224 Protection: execute Mapped to pid: own pid | success or wait | 667948832 | 
| Section loaded | Path: C:\WINDOWS\system32\msctfime.ime Access: query and read Type: commit Baseaddress: 2080000 Size: 180224 Protection: readonly Mapped to pid: own pid | success or wait | 667956182 | 
| Section loaded | Path: C:\WINDOWS\system32\msctfime.ime Access: write and read and execute Type: commit Baseaddress: 2080000 Size: 180224 Protection: execute Mapped to pid: own pid | success or wait | 667959402 | 
| Section loaded | Path: C:\WINDOWS\system32\msctfime.ime Access: query and read Type: commit Baseaddress: 2080000 Size: 180224 Protection: readonly Mapped to pid: own pid | success or wait | 667960806 | 
| Section loaded | Path: \KnownDlls\apphelp.dll Access: write and read and execute Type: unknown Baseaddress: 77B40000 Size: 139264 Protection: read write Mapped to pid: own pid | success or wait | 667962539 | 
| Section loaded | Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 2080000 Size: 1208320 Protection: readonly Mapped to pid: own pid | success or wait | 667968212 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 667969188 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 667973704 | 
| Section loaded | Path: \BaseNamedObjects\ShimSharedMemory Access: write Type: unknown Baseaddress: 2060000 Size: 57344 Protection: read write Mapped to pid: own pid | success or wait | 667975439 | 
| Section loaded | Path: C:\WINDOWS\system32\msctfime.ime Access: write and read and execute Type: commit Baseaddress: 2080000 Size: 180224 Protection: execute Mapped to pid: own pid | success or wait | 667976669 | 
| Section loaded | Path: C:\WINDOWS\system32\msctfime.ime Access: query and write and read and execute Type: image Baseaddress: 755C0000 Size: 188416 Protection: read write Mapped to pid: own pid | success or wait | 667978029 | 
| Section loaded | Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 2090000 Size: 1208320 Protection: readonly Mapped to pid: own pid | success or wait | 667999035 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 668004014 | 
| Section loaded | Path: unknown Access: query and write and read Type: commit Baseaddress: 20B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 668011893 | 
| Section loaded | Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 20B0000 Size: 1208320 Protection: readonly Mapped to pid: own pid | success or wait | 668031839 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 668037089 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 668046839 | 
| Section loaded | Path: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll Access: write and read and execute Type: commit Baseaddress: 20B0000 Size: 77824 Protection: execute Mapped to pid: own pid | success or wait | 668049221 | 
| Section loaded | Path: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll Access: query and write and read and execute Type: image Baseaddress: 10000000 Size: 69632 Protection: read write Mapped to pid: own pid | success or wait | 668051596 | 
| Section loaded | Path: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcr80.dll Access: query and write and read and execute Type: image Baseaddress: 20C0000 Size: 634880 Protection: read write Mapped to pid: own pid | conflicting addresses | 668067515 | 
| Section loaded | Path: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcp80.dll Access: query and write and read and execute Type: image Baseaddress: 7C420000 Size: 552960 Protection: read write Mapped to pid: own pid | success or wait | 668089596 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668303552 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668303763 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668303968 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668304173 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668304377 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668304581 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668304784 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668304994 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668305209 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668305420 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668305630 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668305841 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668306051 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668306260 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668306470 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668306680 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668306890 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668307099 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668307309 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668307519 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668307728 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668307938 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668308143 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668308363 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668308796 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668309029 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668309231 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668309431 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668309632 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668309834 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668310035 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668310118 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668310198 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668313642 | 
| Process information queried | PID: 2724 Info Class: Cookie | success or wait | 668313727 | 
| Section loaded | Path: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll Access: write and read and execute Type: commit Baseaddress: 2170000 Size: 65536 Protection: execute Mapped to pid: own pid | success or wait | 668352689 | 
| Section loaded | Path: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll Access: query and write and read and execute Type: image Baseaddress: 2170000 Size: 65536 Protection: read write Mapped to pid: own pid | conflicting addresses | 668354879 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 668386707 | 
| Section loaded | Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 2190000 Size: 1208320 Protection: readonly Mapped to pid: own pid | success or wait | 668394045 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 668397814 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 668407159 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Access: write and read and execute Type: commit Baseaddress: 2190000 Size: 1253376 Protection: execute Mapped to pid: own pid | success or wait | 668409654 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Access: query and write and read and execute Type: image Baseaddress: 2190000 Size: 1282048 Protection: read write Mapped to pid: own pid | conflicting addresses | 668412813 | 
| Section loaded | Path: \KnownDlls\WINTRUST.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 668508410 | 
| Section loaded | Path: C:\WINDOWS\system32\wintrust.dll Access: query and write and read and execute Type: image Baseaddress: 76C30000 Size: 188416 Protection: read write Mapped to pid: own pid | success or wait | 668509288 | 
| Section loaded | Path: \KnownDlls\IMAGEHLP.dll Access: write and read and execute Type: unknown Baseaddress: 76C90000 Size: 163840 Protection: read write Mapped to pid: own pid | success or wait | 668513274 | 
| Section loaded | Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll Access: query and write and read and execute Type: image Baseaddress: 4EC50000 Size: 1748992 Protection: read write Mapped to pid: own pid | success or wait | 668521794 | 
| Section loaded | Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 23F0000 Size: 1208320 Protection: readonly Mapped to pid: own pid | success or wait | 668568635 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 668572975 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 668580902 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\jp2ssv.dll Access: write and read and execute Type: commit Baseaddress: 23F0000 Size: 45056 Protection: execute Mapped to pid: own pid | success or wait | 668583625 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\jp2ssv.dll Access: query and write and read and execute Type: image Baseaddress: 6D430000 Size: 49152 Protection: read write Mapped to pid: own pid | success or wait | 668586307 | 
| Section loaded | Path: \KnownDlls\MSVCR71.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 668591603 | 
| Section loaded | Path: C:\Program Files\Java\jre6\bin\msvcr71.dll Access: query and write and read and execute Type: image Baseaddress: 7C340000 Size: 352256 Protection: read write Mapped to pid: own pid | success or wait | 668592395 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 668620731 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 668620937 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 668621119 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 669739438 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 669739604 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 669739759 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 670858297 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 670858456 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 670858600 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 672105724 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 672110586 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 672113289 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 673268710 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 673304834 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 673308451 | 
| Section loaded | Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 2400000 Size: 1208320 Protection: readonly Mapped to pid: own pid | success or wait | 673478453 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 673523983 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 673563283 | 
| Section loaded | Path: C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll Access: write and read and execute Type: commit Baseaddress: 2400000 Size: 81920 Protection: execute Mapped to pid: own pid | success or wait | 673570450 | 
| Section loaded | Path: C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll Access: query and write and read and execute Type: image Baseaddress: 6DAF0000 Size: 73728 Protection: read write Mapped to pid: own pid | success or wait | 673575985 | 
| Section loaded | Path: C:\WINDOWS\system32\mswsock.dll Access: write and read and execute Type: commit Baseaddress: 2400000 Size: 245760 Protection: execute Mapped to pid: own pid | success or wait | 673600205 | 
| Section loaded | Path: C:\WINDOWS\system32\mswsock.dll Access: query and write and read and execute Type: image Baseaddress: 71A50000 Size: 258048 Protection: read write Mapped to pid: own pid | success or wait | 673604673 | 
| Section loaded | Path: \KnownDlls\hnetcfg.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 673619710 | 
| Section loaded | Path: C:\WINDOWS\system32\hnetcfg.dll Access: query and write and read and execute Type: image Baseaddress: 662B0000 Size: 360448 Protection: read write Mapped to pid: own pid | success or wait | 673621552 | 
| Section loaded | Path: C:\WINDOWS\system32\wshtcpip.dll Access: write and read and execute Type: commit Baseaddress: 2400000 Size: 20480 Protection: execute Mapped to pid: own pid | success or wait | 673645994 | 
| Section loaded | Path: C:\WINDOWS\system32\wshtcpip.dll Access: query and write and read and execute Type: image Baseaddress: 71A90000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 673650365 | 
| Thread resumed | TID: 3116 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 673747996 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 673785948 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 673814652 | 
| Section loaded | Path: \KnownDlls\SXS.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 673916313 | 
| Section loaded | Path: C:\WINDOWS\system32\sxs.dll Access: query and write and read and execute Type: image Baseaddress: 7E720000 Size: 720896 Protection: read write Mapped to pid: own pid | success or wait | 673918885 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a79eb | success or wait | 674312812 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a79eb | success or wait | 674318724 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@3a71ed | success or wait | 674319431 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10daff6 | success or wait | 674321357 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@19b4e60 | success or wait | 674336896 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@136b8d7 | success or wait | 674337545 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a1644b | success or wait | 674339510 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@bfb235 | success or wait | 674340170 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a1644b | success or wait | 674346843 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@14cc34b | success or wait | 674348148 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@a980fa | success or wait | 674348859 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@14cc34b | success or wait | 674351131 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@52d2c4 | success or wait | 674352465 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@18b6b0e | success or wait | 674357101 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@52d2c4 | success or wait | 674359471 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@19b4e60 | success or wait | 674360119 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@19b4e60 | success or wait | 674360770 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@219c51 | success or wait | 674364032 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9db918 | success or wait | 674365739 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@19b4e60 | success or wait | 674372485 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@19b4e60 | success or wait | 674373133 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e2e869 | success or wait | 674373778 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@19b4e60 | success or wait | 674376456 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 674386807 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 674392114 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 674394748 | 
| Section loaded | Path: C:\WINDOWS\system32\ieframe.dll Access: query and read Type: commit Baseaddress: 2590000 Size: 69632 Protection: readonly Mapped to pid: own pid | success or wait | 674398243 | 
| Section loaded | Path: C:\WINDOWS\system32\stdole2.tlb Access: query and read Type: commit Baseaddress: 25B0000 Size: 16384 Protection: readonly Mapped to pid: own pid | success or wait | 674488015 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 675505723 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 675511496 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 675514498 | 
| Section loaded | Path: C:\WINDOWS\system32\actxprxy.dll Access: write and read and execute Type: commit Baseaddress: 2590000 Size: 98304 Protection: execute Mapped to pid: own pid | success or wait | 676245315 | 
| Section loaded | Path: C:\WINDOWS\system32\actxprxy.dll Access: query and write and read and execute Type: image Baseaddress: 71D40000 Size: 110592 Protection: read write Mapped to pid: own pid | success or wait | 676255846 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 676724266 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 676727031 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 676728128 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a79eb | success or wait | 676808491 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a79eb | success or wait | 676809064 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@3a71ed | success or wait | 676809245 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@10daff6 | success or wait | 676809797 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@19b4e60 | success or wait | 676810574 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@136b8d7 | success or wait | 676810757 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a1644b | success or wait | 676811346 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@bfb235 | success or wait | 676811528 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@1a1644b | success or wait | 676811908 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@14cc34b | success or wait | 676812279 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@a980fa | success or wait | 676812462 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@14cc34b | success or wait | 676812827 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@52d2c4 | success or wait | 676813197 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@18b6b0e | success or wait | 676813380 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@52d2c4 | success or wait | 676813932 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@19b4e60 | success or wait | 676814115 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@19b4e60 | success or wait | 676814299 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@219c51 | success or wait | 676814482 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@9db918 | success or wait | 676814855 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@19b4e60 | success or wait | 676815224 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@19b4e60 | success or wait | 676815406 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@e2e869 | success or wait | 676815589 | 
| File other op | Path: C:\WINDOWS\system32\ieframe.dllNew path: Disposition: PositionInformation Data : abstraction.selector.functions.gen.NtFunc$FunctionData@19b4e60 | success or wait | 676816159 | 
| Section loaded | Path: C:\WINDOWS\system32\ieframe.dll Access: query and read Type: commit Baseaddress: 2590000 Size: 69632 Protection: readonly Mapped to pid: own pid | success or wait | 676817009 | 
| Thread resumed | TID: 3432 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 677756529 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 677795328 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 677797513 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 677798569 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 677867809 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Local Settings_Application Data_Microsoft_Feeds Cache_index.dat_32768 Access: write Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 677892639 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Local Settings_Application Data_Microsoft_Feeds Cache_index.dat_32768 Access: query and write and read Type: commit Baseaddress: 26B0000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 677892991 | 
| Section loaded | Path: \BaseNamedObjects\Local\IEHistJournalFm_24c20119-753b-4f33-887d-f2381810562d_150C75A_C::DOCUMENTS AND SETTINGS:ADMINISTRATOR:LOCAL SETTINGS:TEMPORARY INTERNET FILES:SUGGESTEDSITES.DAT Access: query and write and read Type: commit Baseaddress: 26C0000 Size: 5246976 Protection: read write Mapped to pid: own pid | success or wait | 677910108 | 
| Section loaded | Path: \BaseNamedObjects\Local\UrlZonesSM_Administrator Access: query and write and read Type: commit Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name exists | 677912850 | 
| Section loaded | Path: \KnownDlls\RASAPI32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 677947501 | 
| Section loaded | Path: C:\WINDOWS\system32\rasapi32.dll Access: query and write and read and execute Type: image Baseaddress: 76EE0000 Size: 245760 Protection: read write Mapped to pid: own pid | success or wait | 677948118 | 
| Section loaded | Path: \KnownDlls\rasman.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 677950986 | 
| Section loaded | Path: C:\WINDOWS\system32\rasman.dll Access: query and write and read and execute Type: image Baseaddress: 76E90000 Size: 73728 Protection: read write Mapped to pid: own pid | success or wait | 677951612 | 
| Section loaded | Path: \KnownDlls\NETAPI32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 677954037 | 
| Section loaded | Path: C:\WINDOWS\system32\netapi32.dll Access: query and write and read and execute Type: image Baseaddress: 5B860000 Size: 348160 Protection: read write Mapped to pid: own pid | success or wait | 677954687 | 
| Section loaded | Path: \KnownDlls\TAPI32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 677959061 | 
| Section loaded | Path: C:\WINDOWS\system32\tapi32.dll Access: query and write and read and execute Type: image Baseaddress: 76EB0000 Size: 192512 Protection: read write Mapped to pid: own pid | success or wait | 677959710 | 
| Section loaded | Path: \KnownDlls\rtutils.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 677963219 | 
| Section loaded | Path: C:\WINDOWS\system32\rtutils.dll Access: query and write and read and execute Type: image Baseaddress: 76E80000 Size: 57344 Protection: read write Mapped to pid: own pid | success or wait | 677963911 | 
| Section loaded | Path: \KnownDlls\WINMM.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 677967398 | 
| Section loaded | Path: C:\WINDOWS\system32\winmm.dll Access: query and write and read and execute Type: image Baseaddress: 76B40000 Size: 184320 Protection: read write Mapped to pid: own pid | success or wait | 677968057 | 
| Section loaded | Path: C:\WINDOWS\system32\tapi32.dll Access: read Type: commit Baseaddress: 2BE0000 Size: 184320 Protection: readonly Mapped to pid: own pid | success or wait | 678001616 | 
| Section loaded | Path: \KnownDlls\msapsspc.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 678229609 | 
| Section loaded | Path: C:\WINDOWS\system32\msapsspc.dll Access: query and write and read and execute Type: image Baseaddress: 71E50000 Size: 86016 Protection: read write Mapped to pid: own pid | success or wait | 678233568 | 
| Section loaded | Path: \KnownDlls\MSVCRT40.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 678257736 | 
| Section loaded | Path: C:\WINDOWS\system32\msvcrt40.dll Access: query and write and read and execute Type: image Baseaddress: 78080000 Size: 69632 Protection: read write Mapped to pid: own pid | success or wait | 678268969 | 
| Section loaded | Path: \KnownDlls\schannel.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 678367243 | 
| Section loaded | Path: C:\WINDOWS\system32\schannel.dll Access: query and write and read and execute Type: image Baseaddress: 767F0000 Size: 163840 Protection: read write Mapped to pid: own pid | success or wait | 678376070 | 
| Section loaded | Path: \KnownDlls\digest.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 678525023 | 
| Section loaded | Path: C:\WINDOWS\system32\digest.dll Access: query and write and read and execute Type: image Baseaddress: 75B00000 Size: 86016 Protection: read write Mapped to pid: own pid | success or wait | 678527117 | 
| Section loaded | Path: \KnownDlls\sensapi.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 678552073 | 
| Section loaded | Path: C:\WINDOWS\system32\sensapi.dll Access: query and write and read and execute Type: image Baseaddress: 722B0000 Size: 20480 Protection: read write Mapped to pid: own pid | success or wait | 678563520 | 
| Section loaded | Path: \BaseNamedObjects\SENS Information Cache Access: read Type: unknown Baseaddress: 2BE0000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 678582541 | 
| Section loaded | Path: \KnownDlls\msnsspc.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 678583328 | 
| Section loaded | Path: C:\WINDOWS\system32\msnsspc.dll Access: query and write and read and execute Type: image Baseaddress: 747B0000 Size: 290816 Protection: read write Mapped to pid: own pid | success or wait | 678605356 | 
| Section loaded | Path: \KnownDlls\MSVCRT40.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 678623788 | 
| Section loaded | Path: C:\WINDOWS\system32\msvcrt40.dll Access: query and write and read and execute Type: image Baseaddress: 78080000 Size: 69632 Protection: read write Mapped to pid: own pid | success or wait | 678625749 | 
| Section loaded | Path: C:\WINDOWS\system32\msv1_0.dll Access: write and read and execute Type: commit Baseaddress: 2C20000 Size: 139264 Protection: execute Mapped to pid: own pid | success or wait | 678724980 | 
| Section loaded | Path: C:\WINDOWS\system32\msv1_0.dll Access: query and write and read and execute Type: image Baseaddress: 77C70000 Size: 151552 Protection: read write Mapped to pid: own pid | success or wait | 678738129 | 
| Section loaded | Path: \KnownDlls\cryptdll.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 678745618 | 
| Section loaded | Path: C:\WINDOWS\system32\cryptdll.dll Access: query and write and read and execute Type: image Baseaddress: 76790000 Size: 49152 Protection: read write Mapped to pid: own pid | success or wait | 678747568 | 
| Section loaded | Path: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll Access: query and read Type: commit Baseaddress: 2BF0000 Size: 53248 Protection: readonly Mapped to pid: own pid | success or wait | 678763363 | 
| Section loaded | Path: \KnownDlls\iphlpapi.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 678769878 | 
| Section loaded | Path: C:\WINDOWS\system32\iphlpapi.dll Access: query and write and read and execute Type: image Baseaddress: 76D60000 Size: 102400 Protection: read write Mapped to pid: own pid | success or wait | 678776168 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 680019448 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 680022246 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 680023344 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 680204500 | 
| Section loaded | Path: C:\WINDOWS\system32\en-us\urlmon.dll.mui Access: query and read Type: commit Baseaddress: 2C40000 Size: 40960 Protection: write copy Mapped to pid: own pid | success or wait | 680215057 | 
| Section loaded | Path: \BaseNamedObjects\Local\!PrivacIE!SharedMem!Settings Access: query and write and read Type: commit Baseaddress: 2C50000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 680258691 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 680329105 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 680336604 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 680344035 | 
| Thread resumed | TID: 3652 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 680356887 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\iecompat.dll Access: write and read and execute Type: commit Baseaddress: 2D60000 Size: 4096 Protection: execute Mapped to pid: own pid | success or wait | 680389143 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\iecompat.dll Access: query and read Type: commit Baseaddress: 2D60000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 680392104 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\iecompat.dll Access: write and read and execute Type: commit Baseaddress: 2D60000 Size: 4096 Protection: execute Mapped to pid: own pid | success or wait | 680395936 | 
| Section loaded | Path: C:\Program Files\Internet Explorer\iecompat.dll Access: query and read Type: commit Baseaddress: 2D60000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 680398352 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_IECompatCache_index.dat_16384 Access: write Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 680414535 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_IECompatCache_index.dat_16384 Access: query and write and read Type: commit Baseaddress: 2D60000 Size: 16384 Protection: read write Mapped to pid: own pid | success or wait | 680414914 | 
| Section loaded | Path: \BaseNamedObjects\windows_ie_global_counters Access: write and read Type: unknown Baseaddress: 2D70000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 680418595 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 680421655 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 680479958 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 680480334 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2D80000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 680480955 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 680486782 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 680487144 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 2D80000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 680487556 | 
| Section loaded | Path: \KnownDlls\rasadhlp.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 680505289 | 
| Section loaded | Path: C:\WINDOWS\system32\rasadhlp.dll Access: query and write and read and execute Type: image Baseaddress: 76FC0000 Size: 24576 Protection: read write Mapped to pid: own pid | success or wait | 680506308 | 
| Section loaded | Path: \BaseNamedObjects\ie_lcie_ConnHashTable<2116>_S-1-5-21-507921405-1960408961-839522115-500 Access: query and write and read Type: commit Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name exists | 680540249 | 
| Section loaded | Path: \KnownDlls\DNSAPI.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 680552853 | 
| Section loaded | Path: C:\WINDOWS\system32\dnsapi.dll Access: query and write and read and execute Type: image Baseaddress: 76F20000 Size: 159744 Protection: read write Mapped to pid: own pid | success or wait | 680554811 | 
| Thread resumed | TID: 3656 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 680565933 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 681094637 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 681096669 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 681098556 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 682215408 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 682220435 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 682225835 | 
| Thread resumed | TID: 3748 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 682498981 | 
| Thread resumed | TID: 3752 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 682512040 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 683334326 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 683339683 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 683344802 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 684452646 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 684457819 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 684462857 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Cookies_index.dat_32768 Access: write Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 685133494 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Cookies_index.dat_32768 Access: query and write and read Type: commit Baseaddress: 1020000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 685134009 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_IETldCache_index.dat_262144 Access: write Type: unknown Baseaddress: 2E00000 Size: 262144 Protection: read write Mapped to pid: own pid | success or wait | 685172351 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 685571245 | 
| Thread delayed | Time: 0 TID: 2864 | success or wait | 685576476 | 
| Section loaded | Path: \NLS\NlsSectionCP20127 Access: read Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 692409051 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 692683294 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 692683471 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 3180000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 692683842 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\google_fr[1].txt Offset: unknown Length: 4096 Value: 3C 21 64 6F 63 74 79 70 65 20 68 74 6D 6C 3E 3C 68 74 6D 6C 20 69 74 65 6D 73 63 6F 70 65 3D 22 69 74 65 6D 73 63 6F 70 65 22 20 69 74 65 6D 74 79 70 65 3D 22 68 74 74 70 3A 2F 2F 73 63 68 65 6D 61 2E 6F 72 67 2F 57 65 62 50 61 67 65 22 3E 3C 68 65 61 64 3E 3C 6D 65 74 61 20 63 6F 6E 74 65 6E 74 3D | success or wait | 692696768 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\google_fr[1].txt Offset: unknown Length: 4096 Value: 3B 62 6F 72 64 65 72 2D 73 74 79 6C 65 3A 73 6F 6C 69 64 20 64 61 73 68 65 64 20 64 61 73 68 65 64 3B 62 6F 72 64 65 72 2D 63 6F 6C 6F 72 3A 74 72 61 6E 73 70 61 72 65 6E 74 3B 62 6F 72 64 65 72 2D 74 6F 70 2D 63 6F 6C 6F 72 3A 23 63 30 63 30 63 30 3B 64 69 73 70 6C 61 79 3A 2D 6D 6F 7A 2D 69 6E 6C | success or wait | 692740087 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 692816248 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.dll Access: write and read and execute Type: commit Baseaddress: 3280000 Size: 5963776 Protection: execute Mapped to pid: own pid | success or wait | 692822691 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.dll Access: query and write and read and execute Type: image Baseaddress: 3CEA0000 Size: 5976064 Protection: read write Mapped to pid: own pid | success or wait | 692855438 | 
| Section loaded | Path: \KnownDlls\msls31.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 692895966 | 
| Section loaded | Path: C:\WINDOWS\system32\msls31.dll Access: query and write and read and execute Type: image Baseaddress: 3280000 Size: 167936 Protection: read write Mapped to pid: own pid | conflicting addresses | 692896969 | 
| Section loaded | Path: \BaseNamedObjects\#MSHTML#PERF#00000AA4 Access: write Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 693253056 | 
| Section loaded | Path: C:\Program Files\Microsoft Office\OFFICE11\OUTLLIB.DLL Access: write and read and execute Type: commit Baseaddress: 32B0000 Size: 7606272 Protection: execute Mapped to pid: own pid | success or wait | 693277210 | 
| Section loaded | Path: C:\Program Files\Microsoft Office\OFFICE11\OUTLLIB.DLL Access: query and read Type: commit Baseaddress: 32B0000 Size: 7606272 Protection: readonly Mapped to pid: own pid | success or wait | 693280900 | 
| Section loaded | Path: C:\Program Files\Microsoft Office\OFFICE11\OUTLLIB.DLL Access: write and read and execute Type: commit Baseaddress: 32B0000 Size: 7606272 Protection: execute Mapped to pid: own pid | success or wait | 693298430 | 
| Section loaded | Path: C:\Program Files\Microsoft Office\OFFICE11\OUTLLIB.DLL Access: query and read Type: commit Baseaddress: 32B0000 Size: 7606272 Protection: readonly Mapped to pid: own pid | success or wait | 693300608 | 
| Section loaded | Path: \BaseNamedObjects\Local\!PrivacIE!SharedMem!Settings Access: query and write and read Type: commit Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name exists | 693311417 | 
| Section loaded | Path: \BaseNamedObjects\Local\!PrivacIE!SharedMem!Counter Access: query and write and read Type: commit Baseaddress: 32B0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 693313374 | 
| Section loaded | Path: C:\WINDOWS\WindowsShell.Manifest Access: write and read and execute Type: commit Baseaddress: 32C0000 Size: 4096 Protection: execute Mapped to pid: own pid | success or wait | 693357108 | 
| Section loaded | Path: C:\WINDOWS\WindowsShell.Manifest Access: query and read Type: commit Baseaddress: 32C0000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 693368692 | 
| Section loaded | Path: C:\WINDOWS\WindowsShell.Manifest Access: read Type: commit Baseaddress: 32C0000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 693370012 | 
| Section loaded | Path: \KnownDlls\PSAPI.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 693391615 | 
| Section loaded | Path: C:\WINDOWS\system32\psapi.dll Access: query and write and read and execute Type: image Baseaddress: 76BF0000 Size: 45056 Protection: read write Mapped to pid: own pid | success or wait | 693392426 | 
| Process information queried | PID: 2724 Info Class: BasicInformation | success or wait | 693397673 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 693418307 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 693439516 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 693558719 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\google_fr[1].txt Offset: unknown Length: 8192 Value: 30 2C 30 2C 2E 31 32 29 3B 2D 77 65 62 6B 69 74 2D 62 6F 78 2D 73 68 61 64 6F 77 3A 30 20 32 70 78 20 34 70 78 20 72 67 62 61 28 30 2C 30 2C 30 2C 2E 31 32 29 3B 62 6F 78 2D 73 68 61 64 6F 77 3A 30 20 32 70 78 20 34 70 78 20 72 67 62 61 28 30 2C 30 2C 30 2C 2E 31 32 29 3B 70 6F 73 69 74 69 6F 6E 3A | success or wait | 693572198 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\google_fr[1].txt Offset: unknown Length: 8192 Value: 6E 74 3B 74 6F 70 3A 31 30 32 70 78 20 21 69 6D 70 6F 72 74 61 6E 74 7D 2E 67 62 70 6C 2C 2E 67 62 70 72 7B 6D 61 72 67 69 6E 2D 74 6F 70 3A 34 70 78 7D 2E 67 62 69 35 74 7B 63 6F 6C 6F 72 3A 23 36 36 36 3B 64 69 73 70 6C 61 79 3A 62 6C 6F 63 6B 3B 6D 61 72 67 69 6E 3A 31 70 78 20 31 35 70 78 3B 74 | success or wait | 693576636 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\google_fr[1].txt Offset: unknown Length: 8192 Value: 69 65 6E 74 28 74 6F 70 2C 23 64 64 34 62 33 39 2C 23 62 30 32 38 31 61 29 3B 62 61 63 6B 67 72 6F 75 6E 64 2D 69 6D 61 67 65 3A 2D 6D 73 2D 6C 69 6E 65 61 72 2D 67 72 61 64 69 65 6E 74 28 74 6F 70 2C 23 64 64 34 62 33 39 2C 23 62 30 32 38 31 61 29 3B 62 61 63 6B 67 72 6F 75 6E 64 2D 69 6D 61 67 65 | success or wait | 693581693 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\google_fr[1].txt Offset: unknown Length: 8098 Value: 2E 67 62 65 6D 23 67 62 71 31 2C 2E 67 62 65 6D 69 23 67 62 20 23 67 62 71 31 7B 6D 61 72 67 69 6E 2D 6C 65 66 74 3A 32 38 70 78 7D 2E 67 62 65 6D 23 67 62 71 6C 2C 2E 67 62 65 6D 69 23 67 62 20 23 67 62 71 6C 2C 2E 67 62 65 73 23 67 62 71 6C 2C 2E 67 62 65 73 69 23 67 62 20 23 67 62 71 6C 2C 2E 67 | success or wait | 693585831 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\google_fr[1].txt Offset: unknown Length: 94 Value: 7B 6D 61 72 67 69 6E 3A 30 20 61 75 74 6F 3B 6D 69 6E 2D 77 69 64 74 68 3A 39 38 30 70 78 7D 2E 6A 68 70 20 69 6E 70 75 74 5B 74 79 70 65 3D 22 73 75 62 6D 69 74 22 5D 7B 62 61 63 6B 67 72 6F 75 6E 64 2D 69 6D 61 67 65 3A 2D 6D 73 2D 6C 69 6E 65 61 72 2D 67 72 61 64 69 65 6E 74 28 | success or wait | 693587535 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\google_fr[1].txt Offset: unknown Length: 8192 Value: 74 6F 70 2C 23 66 35 66 35 66 35 2C 23 66 31 66 31 66 31 29 3B 66 69 6C 74 65 72 3A 70 72 6F 67 69 64 3A 44 58 49 6D 61 67 65 54 72 61 6E 73 66 6F 72 6D 2E 4D 69 63 72 6F 73 6F 66 74 2E 67 72 61 64 69 65 6E 74 28 73 74 61 72 74 43 6F 6C 6F 72 53 74 72 3D 27 23 66 35 66 35 66 35 27 2C 45 6E 64 43 6F | success or wait | 693591897 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\google_fr[1].txt Offset: unknown Length: 8098 Value: 63 22 2C 73 29 3B 70 28 22 6D 64 69 22 2C 66 61 29 3B 70 28 22 62 6E 63 22 2C 74 29 3B 70 28 22 71 47 43 22 2C 43 29 3B 70 28 22 71 6D 22 2C 78 29 3B 70 28 22 71 64 22 2C 75 29 3B 70 28 22 6C 62 22 2C 42 29 3B 70 28 22 6D 63 66 22 2C 68 61 29 3B 70 28 22 62 63 66 22 2C 67 61 29 3B 70 28 22 61 71 22 | success or wait | 693596014 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\google_fr[1].txt Offset: unknown Length: 94 Value: 3D 22 2C 28 6E 65 77 20 44 61 74 65 29 2E 67 65 74 54 69 6D 65 28 29 2C 22 26 6F 67 65 3D 22 2C 61 2C 22 26 6F 67 65 78 3D 22 2C 64 28 22 33 37 31 30 32 22 29 2C 22 26 6F 67 66 3D 22 2C 69 2E 62 76 2E 66 2C 22 26 6F 67 70 3D 22 2C 64 28 22 31 22 29 2C 22 26 6F 67 72 70 3D 22 2C 64 | success or wait | 693597619 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\google_fr[1].txt Offset: unknown Length: 6325 Value: 28 22 22 29 2C 22 26 6F 67 73 72 3D 22 2C 4D 61 74 68 2E 72 6F 75 6E 64 28 31 2F 63 29 2C 22 26 6F 67 76 3D 22 2C 64 28 22 31 33 34 30 39 31 38 32 34 38 2E 31 33 34 30 38 32 39 37 30 36 22 29 2C 67 3F 22 26 6F 67 67 76 3D 22 2B 64 28 67 29 3A 22 22 2C 22 26 6F 67 64 3D 22 2C 64 28 22 66 72 22 29 2C | success or wait | 693600830 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\google_fr[1].txt Offset: unknown Length: 1867 Value: 29 29 29 3B 75 26 26 28 75 2E 73 74 79 6C 65 2E 64 69 73 70 6C 61 79 3D 22 22 2C 66 2D 3D 75 2E 63 6C 69 65 6E 74 57 69 64 74 68 2B 6A 29 3B 6E 26 26 28 6E 2E 73 74 79 6C 65 2E 64 69 73 70 6C 61 79 3D 22 22 2C 66 2D 3D 6E 2E 63 6C 69 65 6E 74 57 69 64 74 68 2B 6A 29 3B 50 26 26 21 44 26 26 28 66 2D | success or wait | 693602807 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\google_fr[1].txt Offset: unknown Length: 8192 Value: 20 22 75 74 22 3A 58 28 22 67 62 65 75 69 22 29 3B 0A 62 72 65 61 6B 3B 63 61 73 65 20 22 74 79 22 3A 58 28 22 67 62 65 74 69 22 29 3B 62 72 65 61 6B 3B 63 61 73 65 20 22 73 6D 22 3A 58 28 22 67 62 65 73 69 22 29 3B 62 72 65 61 6B 3B 63 61 73 65 20 22 6D 64 22 3A 58 28 22 67 62 65 6D 69 22 29 3B 62 | success or wait | 693607176 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\google_fr[1].txt Offset: unknown Length: 6325 Value: 2F 3F 68 6C 3D 66 72 26 74 61 62 3D 77 38 22 3E 3C 73 70 61 6E 20 63 6C 61 73 73 3D 67 62 74 62 32 3E 3C 2F 73 70 61 6E 3E 3C 73 70 61 6E 20 63 6C 61 73 73 3D 67 62 74 73 3E 50 6C 61 79 3C 2F 73 70 61 6E 3E 3C 2F 61 3E 3C 2F 6C 69 3E 3C 6C 69 20 63 6C 61 73 73 3D 67 62 74 3E 3C 61 20 6F 6E 63 6C 69 | success or wait | 693610703 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\google_fr[1].txt Offset: unknown Length: 1867 Value: 61 72 2D 67 72 61 64 69 65 6E 74 28 74 6F 70 2C 23 34 64 39 30 66 65 2C 23 34 37 38 37 65 64 29 3B 62 61 63 6B 67 72 6F 75 6E 64 2D 69 6D 61 67 65 3A 20 6C 69 6E 65 61 72 2D 67 72 61 64 69 65 6E 74 28 74 6F 70 2C 23 34 64 39 30 66 65 2C 23 34 37 38 37 65 64 29 3B 66 69 6C 74 65 72 3A 70 72 6F 67 69 | success or wait | 693612294 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\google_fr[1].txt Offset: unknown Length: 8192 Value: 69 63 6B 3D 22 67 6F 6F 67 6C 65 2E 70 72 6F 6D 6F 73 26 26 67 6F 6F 67 6C 65 2E 70 72 6F 6D 6F 73 2E 74 6F 61 73 74 26 26 20 67 6F 6F 67 6C 65 2E 70 72 6F 6D 6F 73 2E 74 6F 61 73 74 2E 63 6C 28 29 22 3E 49 6E 73 74 61 6C 6C 65 72 20 47 6F 6F 67 6C 65 20 43 68 72 6F 6D 65 3C 2F 61 3E 20 3C 2F 64 69 | success or wait | 693616346 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\google_fr[1].txt Offset: unknown Length: 1650 Value: 78 6A 73 69 27 5D 2C 70 63 3A 5B 5D 2C 63 73 73 3A 64 6F 63 75 6D 65 6E 74 2E 67 65 74 45 6C 65 6D 65 6E 74 42 79 49 64 28 27 67 73 74 79 6C 65 27 29 2E 69 6E 6E 65 72 48 54 4D 4C 2C 6D 61 69 6E 3A 6D 73 74 72 2C 62 6C 3A 5B 27 6D 6E 67 62 27 2C 27 67 62 5F 27 5D 0A 7D 3B 7D 29 28 29 3B 3C 2F 73 63 | success or wait | 693617489 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\google_fr[1].txt Offset: unknown Length: 2316 Value: 2C 61 6E 69 6D 2C 62 62 64 2C 63 2C 73 62 2C 68 76 2C 77 74 61 2C 63 72 2C 63 64 6F 73 2C 70 6A 2C 74 62 70 72 2C 74 62 75 69 2C 72 73 6E 2C 6F 62 2C 6D 62 2C 6C 63 2C 64 75 2C 61 64 61 2C 62 69 68 75 2C 6C 75 2C 6D 2C 74 6E 67 2C 68 73 6D 2C 6A 2C 70 2C 70 63 63 2C 63 73 69 74 6C 2F 72 74 5C 78 33 | success or wait | 693619367 | 
| Thread resumed | TID: 3948 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 693622017 | 
| Section loaded | Path: C:\WINDOWS\system32\en-us\ieframe.dll.mui Access: query and read Type: commit Baseaddress: 34E0000 Size: 1241088 Protection: write copy Mapped to pid: own pid | success or wait | 693643335 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 693734274 | 
| Section loaded | Path: C:\WINDOWS\system32\msimtf.dll Access: write and read and execute Type: commit Baseaddress: 3610000 Size: 159744 Protection: execute Mapped to pid: own pid | success or wait | 693738879 | 
| Section loaded | Path: C:\WINDOWS\system32\msimtf.dll Access: query and write and read and execute Type: image Baseaddress: 746F0000 Size: 172032 Protection: read write Mapped to pid: own pid | success or wait | 693741875 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 693818872 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 693832739 | 
| Section loaded | Path: \BaseNamedObjects\CTF.AsmListCache.FMPDefaultS-1-5-21-507921405-1960408961-839522115-500 Access: query and write and read and execute and extend size Type: unknown Baseaddress: 32C0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 693840930 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 693973693 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 693976809 | 
| Section loaded | Path: C:\WINDOWS\system32\jscript.dll Access: write and read and execute Type: commit Baseaddress: 3810000 Size: 729088 Protection: execute Mapped to pid: own pid | success or wait | 693980600 | 
| Section loaded | Path: C:\WINDOWS\system32\jscript.dll Access: query and write and read and execute Type: image Baseaddress: 3D7A0000 Size: 737280 Protection: read write Mapped to pid: own pid | success or wait | 693986122 | 
| Section loaded | Path: C:\WINDOWS\system32\stdole2.tlb Access: query and read Type: commit Baseaddress: 3810000 Size: 16384 Protection: readonly Mapped to pid: own pid | success or wait | 694163812 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 694321885 | 
| Section loaded | Path: C:\WINDOWS\system32\iepeers.dll Access: write and read and execute Type: commit Baseaddress: 3C20000 Size: 184320 Protection: execute Mapped to pid: own pid | success or wait | 694325931 | 
| Section loaded | Path: C:\WINDOWS\system32\iepeers.dll Access: query and write and read and execute Type: image Baseaddress: 42070000 Size: 192512 Protection: read write Mapped to pid: own pid | success or wait | 694328674 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 694407721 | 
| Section loaded | Path: C:\WINDOWS\system32\dxtrans.dll Access: write and read and execute Type: commit Baseaddress: 3C30000 Size: 217088 Protection: execute Mapped to pid: own pid | success or wait | 694419154 | 
| Section loaded | Path: C:\WINDOWS\system32\dxtrans.dll Access: query and write and read and execute Type: image Baseaddress: 35C50000 Size: 233472 Protection: read write Mapped to pid: own pid | success or wait | 694422072 | 
| Section loaded | Path: \KnownDlls\ATL.DLL Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 694426259 | 
| Section loaded | Path: C:\WINDOWS\system32\atl.dll Access: query and write and read and execute Type: image Baseaddress: 76B20000 Size: 69632 Protection: read write Mapped to pid: own pid | success or wait | 694427231 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 694744683 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 694764901 | 
| Section loaded | Path: C:\WINDOWS\system32\ddrawex.dll Access: write and read and execute Type: commit Baseaddress: 3C30000 Size: 28672 Protection: execute Mapped to pid: own pid | success or wait | 694771019 | 
| Section loaded | Path: C:\WINDOWS\system32\ddrawex.dll Access: query and write and read and execute Type: image Baseaddress: 3C30000 Size: 40960 Protection: read write Mapped to pid: own pid | conflicting addresses | 694774070 | 
| Section loaded | Path: \KnownDlls\DDRAW.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 694781896 | 
| Section loaded | Path: C:\WINDOWS\system32\ddraw.dll Access: query and write and read and execute Type: image Baseaddress: 73760000 Size: 307200 Protection: read write Mapped to pid: own pid | success or wait | 694783037 | 
| Section loaded | Path: \KnownDlls\DCIMAN32.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 694788921 | 
| Section loaded | Path: C:\WINDOWS\system32\dciman32.dll Access: query and write and read and execute Type: image Baseaddress: 73BC0000 Size: 24576 Protection: read write Mapped to pid: own pid | success or wait | 694791521 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 694913963 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 694937978 | 
| Section loaded | Path: C:\WINDOWS\system32\dxtmsft.dll Access: write and read and execute Type: commit Baseaddress: 3C40000 Size: 348160 Protection: execute Mapped to pid: own pid | success or wait | 694943754 | 
| Section loaded | Path: C:\WINDOWS\system32\dxtmsft.dll Access: query and write and read and execute Type: image Baseaddress: 35CB0000 Size: 356352 Protection: read write Mapped to pid: own pid | success or wait | 694946740 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 694973800 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 694991846 | 
| Thread resumed | TID: 1268 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 694998343 | 
| Thread resumed | TID: 1956 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 695000703 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 695040361 | 
| Section loaded | Path: C:\WINDOWS\system32\dxtmsft.dll Access: query and read Type: commit Baseaddress: 3E40000 Size: 69632 Protection: readonly Mapped to pid: own pid | success or wait | 695082416 | 
| Section loaded | Path: C:\WINDOWS\system32\dxtrans.dll Access: query and read Type: commit Baseaddress: 3E60000 Size: 81920 Protection: readonly Mapped to pid: own pid | success or wait | 695429532 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 695578520 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 695605437 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 695623818 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 695624669 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 695624856 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 3E80000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 695625261 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 695630109 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 695633989 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 3E80000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 695634385 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 695647294 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 695648025 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 695648211 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 3E80000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 695648591 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 695652066 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 695652247 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 3E80000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 695652620 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 695671771 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 695672738 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 695673801 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 695674154 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 3E80000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 695674707 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 695677459 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 695677838 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 3E80000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 695678418 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Shared\SkypePnr.dll Access: query and read Type: commit Baseaddress: 3EA0000 Size: 4399104 Protection: readonly Mapped to pid: own pid | success or wait | 695745911 | 
| Section loaded | Path: C:\WINDOWS\system32\rsaenh.dll Access: query and read Type: commit Baseaddress: 3EA0000 Size: 208896 Protection: readonly Mapped to pid: own pid | success or wait | 695764712 | 
| Section loaded | Path: C:\WINDOWS\system32\rsaenh.dll Access: query and read Type: commit Baseaddress: 3EA0000 Size: 208896 Protection: readonly Mapped to pid: own pid | success or wait | 695766217 | 
| Section loaded | Path: \KnownDlls\rsaenh.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 695887191 | 
| Section loaded | Path: C:\WINDOWS\system32\rsaenh.dll Access: query and write and read and execute Type: image Baseaddress: 68000000 Size: 221184 Protection: read write Mapped to pid: own pid | success or wait | 695887827 | 
| Section loaded | Path: C:\WINDOWS\system32\rsaenh.dll Access: query and read Type: commit Baseaddress: 3EA0000 Size: 208896 Protection: readonly Mapped to pid: own pid | success or wait | 695909928 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 697395581 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 697400342 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 3EA0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 697404721 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Shared\SkypePnr.dll Access: query and read Type: commit Baseaddress: 3EA0000 Size: 4399104 Protection: readonly Mapped to pid: own pid | success or wait | 697451643 | 
| Thread resumed | TID: 1904 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 697500504 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_PrivacIE_index.dat_98304 Access: write Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 697510947 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_PrivacIE_index.dat_98304 Access: query and write and read Type: commit Baseaddress: 3FA0000 Size: 98304 Protection: read write Mapped to pid: own pid | success or wait | 697511510 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\chrome-48[1].png Offset: unknown Length: 1834 Value: 89 50 4E 47 0D 0A 1A 0A 00 00 00 0D 49 48 44 52 00 00 00 30 00 00 00 30 08 03 00 00 00 60 DC 09 B5 00 00 02 FA 50 4C 54 45 FF FF FF F8 CD 0C EB B9 1D 33 85 40 E6 41 3A E4 38 34 D5 9C 28 E4 AF 22 DE 22 27 D1 20 23 EC 59 4B D1 96 2A 4B B5 49 42 A1 45 EE 63 52 3D 92 43 DC A4 27 3D 92 43 39 8C 42 E4 3B | success or wait | 697520067 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Shared\SkypePnr.dll Access: query and read Type: commit Baseaddress: 3FC0000 Size: 4399104 Protection: readonly Mapped to pid: own pid | success or wait | 697531437 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Shared\SkypePnr.dll Access: query and read Type: commit Baseaddress: 3FC0000 Size: 4399104 Protection: readonly Mapped to pid: own pid | success or wait | 697532933 | 
| Thread resumed | TID: 1696 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 697562204 | 
| Section loaded | Path: \KnownDlls\ImgUtil.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 697574828 | 
| Section loaded | Path: C:\WINDOWS\system32\imgutil.dll Access: query and write and read and execute Type: image Baseaddress: 1B000000 Size: 49152 Protection: read write Mapped to pid: own pid | success or wait | 697578215 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Shared\SkypePnr.dll Access: query and read Type: commit Baseaddress: 41C0000 Size: 4399104 Protection: readonly Mapped to pid: own pid | success or wait | 697663264 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 697671083 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 697769200 | 
| Section loaded | Path: C:\WINDOWS\system32\pngfilt.dll Access: write and read and execute Type: commit Baseaddress: 3E80000 Size: 49152 Protection: execute Mapped to pid: own pid | success or wait | 697799307 | 
| Section loaded | Path: C:\WINDOWS\system32\pngfilt.dll Access: query and write and read and execute Type: image Baseaddress: 1B060000 Size: 57344 Protection: read write Mapped to pid: own pid | success or wait | 697814452 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 698873903 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 698874075 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 41C0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 698874440 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\3FZRZ9KZ\mgyhp_sm[1].png Offset: unknown Length: 188 Value: 89 50 4E 47 0D 0A 1A 0A 00 00 00 0D 49 48 44 52 00 00 00 0E 00 00 00 0E 08 03 00 00 00 28 96 DD E3 00 00 00 84 50 4C 54 45 FF FF FF BA BD C0 BC CC DE CE D9 E7 DE E2 F2 C3 D3 E7 D3 DF ED C2 C8 CC E7 AB 54 DE 96 3D 49 49 52 E3 E7 F7 F1 F2 FC EC EC F7 E9 B9 5C 84 8C 93 D0 BB AB DA 93 52 5A 5B 7A DB 8E | success or wait | 698876228 | 
| Thread resumed | TID: 1084 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 699139094 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\3FZRZ9KZ\mgyhp_sm[1].png Offset: unknown Length: 143 Value: D8 66 00 00 00 75 49 44 41 54 78 5E 4D CE 55 12 83 40 0C 00 D0 D8 2A 4E DD DD EF 7F BF 66 A7 40 C9 57 DE 44 61 88 EB AE CF 26 61 0D EF CF 72 90 2F CB A6 E7 3E C9 87 66 33 D6 E9 52 2C C6 CA 8B EC 06 50 FF 25 F6 01 2E 3F FB B0 FA 89 A7 E0 32 91 5A C5 DB C8 E6 00 28 D6 B2 D6 5E 6D 34 4A 40 CB 46 3B 13 | success or wait | 699471053 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 699471889 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 699472069 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 43C0000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 699472455 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\3FZRZ9KZ\logo3w[1].png Offset: unknown Length: 187 Value: 89 50 4E 47 0D 0A 1A 0A 00 00 00 0D 49 48 44 52 00 00 01 13 00 00 00 5F 08 03 00 00 00 FC 9A D3 29 00 00 02 FD 50 4C 54 45 01 22 B2 19 1F AA 9F 05 21 B0 03 25 92 0E 24 C4 03 29 BD 0E 27 D2 0B 2C AC 18 28 90 21 2B C9 11 2D DE 0C 32 CC 16 29 D8 18 30 DD 17 2C E4 1A 36 E6 1B 31 A1 31 37 8F 36 3C 2C 49 | success or wait | 699477637 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\3FZRZ9KZ\logo3w[1].png Offset: unknown Length: 6820 Value: 51 D7 5D 5C 95 70 6E B4 68 63 B5 71 22 CE 70 02 9F 78 49 DC 6E 00 F8 61 56 AE 80 40 F9 67 5F B5 7A 77 CD 7F 11 AA 7F 7C 79 89 B3 E3 7C 00 A0 87 5E BC 85 32 97 8B 79 C9 7C 7B A2 87 85 9D 8D 73 F9 74 69 C9 8A 1E E6 85 00 EF 7A 73 8A 95 AD 9C 93 90 5C AA 6E F0 8F 00 E7 91 08 71 9D EF BE 96 56 DF 89 86 | success or wait | 699708830 | 
| Section loaded | Path: \KnownDlls\cryptnet.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 699789890 | 
| Section loaded | Path: C:\WINDOWS\system32\cryptnet.dll Access: query and write and read and execute Type: image Baseaddress: 75E60000 Size: 77824 Protection: read write Mapped to pid: own pid | success or wait | 699791700 | 
| Section loaded | Path: \KnownDlls\WINHTTP.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 699800854 | 
| Section loaded | Path: C:\WINDOWS\system32\winhttp.dll Access: query and write and read and execute Type: image Baseaddress: 4D4F0000 Size: 364544 Protection: read write Mapped to pid: own pid | success or wait | 699802712 | 
| Section loaded | Path: \KnownDlls\WLDAP32.dll Access: write and read and execute Type: unknown Baseaddress: 76F60000 Size: 180224 Protection: read write Mapped to pid: own pid | success or wait | 699813769 | 
| Process information queried | PID: 2724 Info Class: QuotaLimits | success or wait | 699836009 | 
| Process information queried | PID: 2724 Info Class: VmCounters | success or wait | 699836460 | 
| Thread resumed | TID: 2092 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 700009726 | 
| Thread resumed | TID: 2376 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 707272147 | 
| Thread resumed | TID: 2372 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 707347463 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Shared\SkypeBrowserOptions.dll Access: query and read Type: commit Baseaddress: 4540000 Size: 495616 Protection: readonly Mapped to pid: own pid | success or wait | 716748559 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Shared\SkypeBrowserOptions.dll Access: query and read Type: commit Baseaddress: 4540000 Size: 495616 Protection: readonly Mapped to pid: own pid | success or wait | 716758030 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Shared\SkypeBrowserOptions.dll Access: query and read Type: commit Baseaddress: 4540000 Size: 495616 Protection: readonly Mapped to pid: own pid | success or wait | 716759367 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Shared\SkypeBrowserOptions.dll Access: query and read Type: commit Baseaddress: 4540000 Size: 495616 Protection: readonly Mapped to pid: own pid | success or wait | 716760845 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Shared\SkypeBrowserOptions.dll Access: query and read Type: commit Baseaddress: 4540000 Size: 495616 Protection: readonly Mapped to pid: own pid | success or wait | 716763033 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Access: query and read Type: commit Baseaddress: 4820000 Size: 1253376 Protection: readonly Mapped to pid: own pid | success or wait | 716998611 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Access: query and read Type: commit Baseaddress: 4820000 Size: 1253376 Protection: readonly Mapped to pid: own pid | success or wait | 717007509 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Access: query and read Type: commit Baseaddress: 4820000 Size: 1253376 Protection: readonly Mapped to pid: own pid | success or wait | 717008837 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Access: query and read Type: commit Baseaddress: 4820000 Size: 1253376 Protection: readonly Mapped to pid: own pid | success or wait | 717010237 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Access: query and read Type: commit Baseaddress: 4820000 Size: 1253376 Protection: readonly Mapped to pid: own pid | success or wait | 717012389 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe Access: query and read Type: commit Baseaddress: 4540000 Size: 106496 Protection: readonly Mapped to pid: own pid | success or wait | 718340736 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe Access: query and read Type: commit Baseaddress: 4540000 Size: 106496 Protection: readonly Mapped to pid: own pid | success or wait | 718351473 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe Access: query and read Type: commit Baseaddress: 4540000 Size: 106496 Protection: readonly Mapped to pid: own pid | success or wait | 718354802 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe Access: query and read Type: commit Baseaddress: 4540000 Size: 106496 Protection: readonly Mapped to pid: own pid | success or wait | 718356380 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe Access: query and read Type: commit Baseaddress: 4540000 Size: 106496 Protection: readonly Mapped to pid: own pid | success or wait | 718359078 | 
| Thread resumed | TID: 2792 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 719471571 | 
| Thread resumed | TID: 2796 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 719484334 | 
| Thread resumed | TID: 2804 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 719583354 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 719632671 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Shared\SkypePnr.dll Access: write and read and execute Type: commit Baseaddress: 4D20000 Size: 4399104 Protection: execute Mapped to pid: own pid | success or wait | 719639019 | 
| Section loaded | Path: C:\Program Files\Skype\Toolbars\Shared\SkypePnr.dll Access: query and write and read and execute Type: image Baseaddress: 4D20000 Size: 4407296 Protection: read write Mapped to pid: own pid | conflicting addresses | 719644396 | 
| Section loaded | Path: \NLS\NlsSectionCP1251 Access: read Type: unknown Baseaddress: 45F0000 Size: 69632 Protection: readonly Mapped to pid: own pid | success or wait | 720015016 | 
| Section loaded | Path: \NLS\NlsSectionCP1250 Access: read Type: unknown Baseaddress: 4610000 Size: 69632 Protection: readonly Mapped to pid: own pid | success or wait | 720019666 | 
| Section loaded | Path: \NLS\NlsSectionCP1253 Access: read Type: unknown Baseaddress: 4700000 Size: 69632 Protection: readonly Mapped to pid: own pid | success or wait | 720026230 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\google_fr[1].txt Offset: unknown Length: 4226 Value: 70 71 22 3A 22 22 2C 22 70 73 79 22 3A 22 70 22 2C 22 72 67 65 6E 22 3A 74 72 75 65 2C 22 73 63 64 22 3A 31 30 2C 22 73 63 65 22 3A 34 2C 22 73 74 6F 6B 22 3A 22 31 35 7A 7A 42 35 64 66 5F 52 79 48 43 4F 56 6D 63 54 46 46 4A 70 6F 70 32 57 55 22 7D 2C 31 35 32 3A 7B 7D 2C 34 33 3A 7B 22 71 69 72 22 | success or wait | 720127694 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\google_fr[1].txt Offset: unknown Length: 841 Value: 7C 61 2E 73 72 63 45 6C 65 6D 65 6E 74 3B 67 28 63 2C 68 29 7D 76 61 72 20 69 3D 64 6F 63 75 6D 65 6E 74 2E 67 65 74 45 6C 65 6D 65 6E 74 73 42 79 54 61 67 4E 61 6D 65 28 22 69 6D 67 22 29 3B 62 3D 69 2E 6C 65 6E 67 74 68 3B 64 3D 30 3B 66 6F 72 28 76 61 72 20 6A 3D 30 2C 6B 3B 6A 3C 62 3B 2B 2B 6A | success or wait | 720130022 | 
| Section loaded | Path: \KnownDlls\msi.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 720153499 | 
| Section loaded | Path: C:\WINDOWS\system32\msi.dll Access: query and write and read and execute Type: image Baseaddress: 7D1E0000 Size: 2867200 Protection: read write Mapped to pid: own pid | success or wait | 720155860 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 720189284 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 720199159 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 720732445 | 
| Section loaded | Path: C:\Program Files\Common Files\Microsoft Shared\INK\SKCHUI.DLL Access: write and read and execute Type: commit Baseaddress: 5260000 Size: 368640 Protection: execute Mapped to pid: own pid | success or wait | 720751419 | 
| Section loaded | Path: C:\Program Files\Common Files\Microsoft Shared\INK\SKCHUI.DLL Access: query and write and read and execute Type: image Baseaddress: 5260000 Size: 372736 Protection: read write Mapped to pid: own pid | conflicting addresses | 720770732 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 720872612 | 
| Section loaded | Path: C:\WINDOWS\system32\en-us\mshtml.dll.mui Access: query and read Type: commit Baseaddress: 53F0000 Size: 12288 Protection: write copy Mapped to pid: own pid | success or wait | 721461459 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 721498299 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 721498800 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 721513234 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 721529354 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 721537900 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 721550667 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 721624939 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Local Settings_History_History.IE5_MSHist012012012420120125_index.dat_32768 Access: write Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 721681903 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Local Settings_History_History.IE5_MSHist012012012420120125_index.dat_32768 Access: query and write and read Type: commit Baseaddress: 5400000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 721682502 | 
| Section loaded | Path: unknown Access: query and write and read Type: commit Baseaddress: 5410000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 721738683 | 
| Section loaded | Path: unknown Access: query and write and read Type: commit Baseaddress: 5410000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 721749361 | 
| Section loaded | Path: unknown Access: query and write and read Type: commit Baseaddress: 5410000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 721757792 | 
| Section loaded | Path: unknown Access: query and write and read Type: commit Baseaddress: 5410000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 721764950 | 
| Section loaded | Path: unknown Access: query and write and read Type: commit Baseaddress: 5410000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 721770957 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 721785884 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 721948304 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 721951831 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 721956089 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 721957612 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 5410000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 721959761 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 721971199 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 721972772 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 5410000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 721974830 | 
| Section loaded | Path: \BaseNamedObjects\MSIMGSIZECacheMap Access: query and write and read and execute and extend size Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 721991879 | 
| Section loaded | Path: \BaseNamedObjects\MSIMGSIZECacheMap Access: query and write and read Type: commit Baseaddress: 5410000 Size: 16384 Protection: read write Mapped to pid: own pid | success or wait | 722032572 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 722049238 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 722134625 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 722136585 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 722137034 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 5560000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 722138017 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 722166014 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 722166459 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 5560000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 722167704 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL..KHLEFB Access: query and write and read Type: commit Baseaddress: 5560000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 722268578 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 722296210 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 722298929 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 722303870 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 722311217 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 5570000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 722312638 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 722324199 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 722325119 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 5570000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 722326515 | 
| Section loaded | Path: C:\WINDOWS\system32\winrnr.dll Access: write and read and execute Type: commit Baseaddress: 5570000 Size: 20480 Protection: execute Mapped to pid: own pid | success or wait | 722341109 | 
| Section loaded | Path: C:\WINDOWS\system32\winrnr.dll Access: query and write and read and execute Type: image Baseaddress: 76FB0000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 722352309 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 723235592 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 723242797 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 723246397 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 723247428 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 5570000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 723248533 | 
| Section loaded | Path: \KnownDlls\MPRAPI.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 723249974 | 
| Section loaded | Path: C:\WINDOWS\system32\mprapi.dll Access: query and write and read and execute Type: image Baseaddress: 76D40000 Size: 98304 Protection: read write Mapped to pid: own pid | success or wait | 723251870 | 
| Section loaded | Path: \KnownDlls\ACTIVEDS.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 723256620 | 
| Section loaded | Path: C:\WINDOWS\system32\activeds.dll Access: query and write and read and execute Type: image Baseaddress: 77CC0000 Size: 204800 Protection: read write Mapped to pid: own pid | success or wait | 723258174 | 
| Section loaded | Path: \KnownDlls\adsldpc.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 723261989 | 
| Section loaded | Path: C:\WINDOWS\system32\adsldpc.dll Access: query and write and read and execute Type: image Baseaddress: 76E10000 Size: 151552 Protection: read write Mapped to pid: own pid | success or wait | 723263240 | 
| Section loaded | Path: \KnownDlls\SAMLIB.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 723294408 | 
| Section loaded | Path: C:\WINDOWS\system32\samlib.dll Access: query and write and read and execute Type: image Baseaddress: 71BF0000 Size: 77824 Protection: read write Mapped to pid: own pid | success or wait | 723295250 | 
| Thread resumed | TID: 2984 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 723327565 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 723330935 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 723331287 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 5670000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 723331845 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.Shared.SFM.EMG Access: query and write and read and execute and extend size Type: unknown Baseaddress: 5670000 Size: 524288 Protection: read write Mapped to pid: own pid | success or wait | 723340826 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.B.DKMEFB Access: query and write and read Type: commit Baseaddress: 5560000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723345777 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.C.DKMEFB Access: query and write and read Type: commit Baseaddress: 56F0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723348505 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.D.DKMEFB Access: query and write and read Type: commit Baseaddress: 5700000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723351467 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.E.DKMEFB Access: query and write and read Type: commit Baseaddress: 5710000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723353499 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.F.DKMEFB Access: query and write and read Type: commit Baseaddress: 5720000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723355818 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.G.DKMEFB Access: query and write and read Type: commit Baseaddress: 5730000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723358822 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.H.DKMEFB Access: query and write and read Type: commit Baseaddress: 5740000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723604118 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.I.BPMEFB Access: query and write and read Type: commit Baseaddress: 5750000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723647218 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.J.BPMEFB Access: query and write and read Type: commit Baseaddress: 5760000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723650394 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.K.ABNEFB Access: query and write and read Type: commit Baseaddress: 5560000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723721006 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.L.ABNEFB Access: query and write and read Type: commit Baseaddress: 5560000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723751632 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.M.ABNEFB Access: query and write and read Type: commit Baseaddress: 5560000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723759660 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.N.ACNEFB Access: query and write and read Type: commit Baseaddress: 5560000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723768922 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.O.ACNEFB Access: query and write and read Type: commit Baseaddress: 5560000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723778630 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.P.ACNEFB Access: query and write and read Type: commit Baseaddress: 5560000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723788936 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.AB.ACNEFB Access: query and write and read Type: commit Baseaddress: 5560000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723798722 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.BB.ACNEFB Access: query and write and read Type: commit Baseaddress: 5560000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723806134 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EJL.CB.ACNEFB Access: query and write and read Type: commit Baseaddress: 5560000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723814618 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.AD.ACNEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 5560000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723835373 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.BD.PCNEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 5560000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723835845 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.CD.PCNEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 5560000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723836262 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.DD.PCNEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 5560000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723836692 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.ED.PCNEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 5560000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723837104 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.FD.PCNEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 5560000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723837518 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.GD.PCNEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 5560000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723841702 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.HD.PCNEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 5560000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723842139 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.EMG.ID.PCNEFB Access: query and write and read and execute and extend size Type: unknown Baseaddress: 5560000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 723842554 | 
| Section loaded | Path: C:\WINDOWS\system32\iepeers.dll Access: query and read Type: commit Baseaddress: 5560000 Size: 49152 Protection: readonly Mapped to pid: own pid | success or wait | 724093508 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 726503894 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 726504108 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 5420000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 726504487 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\nav_logo107[1].png Offset: unknown Length: 684 Value: 89 50 4E 47 0D 0A 1A 0A 00 00 00 0D 49 48 44 52 00 00 00 A7 00 00 01 85 08 06 00 00 00 98 05 E3 65 00 00 6F DC 49 44 41 54 78 DA ED 9D 07 7C D6 C4 1B C7 8F 55 66 07 14 3A 28 94 B2 A1 65 94 BD A1 EC BD 41 64 17 41 96 A0 65 CA 10 05 15 04 65 29 4B 04 2D 88 20 2E D6 5F 05 65 6F 99 05 64 D3 D2 52 5A 0A | success or wait | 726506449 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\nav_logo107[1].png Offset: unknown Length: 4812 Value: 11 D4 82 08 E7 A8 55 69 64 C8 E7 40 06 AC 7F 40 7A FC B6 98 74 D4 41 DA 9C AE DB E7 C0 D9 81 86 D1 A5 28 55 19 C7 C5 AE A3 AC F7 39 43 99 DF 5D A0 D8 52 6B 28 DA AB CC 7B 34 1C AF 51 19 9D E5 5C E8 40 50 25 A9 C8 82 72 64 E3 A7 FD 08 AC 58 48 52 3F A3 D7 E6 8B 39 1A 9C 53 37 43 F1 91 EB 32 96 B6 5B | success or wait | 726576703 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 726657255 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 726657474 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 5460000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 726657892 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\favicon[1].ico Offset: unknown Length: 682 Value: 00 00 01 00 01 00 10 10 00 00 01 00 20 00 68 04 00 00 16 00 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 EC F4 FB FF 7C C5 EB FF 4F B6 EF FF 45 B1 F1 FF 4D B6 EF FF 93 CE F6 FF F6 FB F9 FF DE E1 D1 FF 49 78 | success or wait | 726661067 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\nav_logo107[1].png Offset: unknown Length: 1916 Value: 9D 02 DA 37 3E BB 95 D9 FB 69 50 29 87 26 E8 57 15 6F F0 76 24 6D 99 47 92 86 B4 0A 6B 3C E5 79 76 17 12 85 B2 C1 DB D9 AA F7 D6 73 AB 6A 43 9F 0E 77 EE 15 BC CB A1 CB 9D 5F EC 3B 5C F9 DE B1 EB C5 6F DC 06 3F BA D6 64 72 24 34 9E 14 01 15 BA 3E 01 BB B6 17 FE 28 54 A4 78 55 AC 86 EE B4 F2 5C 1C EA | success or wait | 726703004 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\nav_logo107[1].png Offset: unknown Length: 780 Value: 1B 79 D8 8B 02 DA B5 73 B9 07 B5 5A 6D 3E 5B D2 03 36 95 A8 74 BE 79 31 AB 6E AC 15 AB 1B 5B 7F B2 D9 96 E7 57 E2 F7 49 56 93 6F 4C 2C 1C 1D 34 BF 08 C4 7F 5D 14 62 77 95 3A 75 7E 9D 7D 1B 3E BE 0D 27 6B 90 B4 23 AE 8D 33 7F 2B 73 E2 F9 52 CA EB 18 F2 53 15 5B D2 82 75 66 DB 48 0D FD 8D FD 2A 93 4C | success or wait | 726704195 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\nav_logo107[1].png Offset: unknown Length: 1060 Value: 36 AE DF AC B6 71 9C D2 D8 AA 78 43 06 65 25 66 E1 8A F2 EA 8B C3 19 FC 95 4D 8E 05 C5 C6 D0 A8 C6 85 5A 6C EC 5B 68 F2 BE 71 85 3F 3B 3B B3 F0 D7 17 E7 91 D5 47 DE 25 33 97 0F 20 DD D8 28 4B 55 56 A5 A2 7F 58 E4 9B 4F 17 E9 60 CC 65 35 57 25 91 71 6B 93 C8 84 AF 92 C9 F8 AF 92 C8 1B 9F C5 35 EA BE | success or wait | 726705221 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\nav_logo107[1].png Offset: unknown Length: 3832 Value: 3E 66 C5 7E B1 50 A1 C3 3F C7 D9 0C 78 DD 90 6E CD 61 41 A4 FE 98 C7 A4 DE A8 00 52 6F E4 3D 52 F7 CD 07 A4 DA B0 40 52 9D 86 E3 FE 8A 5D 0E B5 B4 6B FF 38 D3 06 1B 92 9E 1B 17 F1 E7 B2 2A F5 F6 23 AE 3D FD 89 C3 E0 6F 49 A1 B7 69 56 6F 5B 6B 70 6A 32 5C CE 7D C3 BF 76 EA 1B A7 1B 31 73 E8 7C F7 5F | success or wait | 726794256 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\nav_logo107[1].png Offset: unknown Length: 920 Value: 40 A9 3B 80 C7 E3 70 A2 CF 89 C7 E4 96 8D 8B 57 E5 58 7E 9D 35 A7 42 18 30 1E AF 56 39 9C F8 9B F7 11 F2 D6 30 AF DE 31 0F DC C6 6B C1 FD 4C 5E ED 63 7C 04 04 D3 F0 63 61 3A EE B3 62 39 B8 65 C6 F3 C3 7C 78 35 CC E3 0A AD 27 E6 87 50 F2 3F 13 F7 63 79 57 92 D0 62 F2 2E 26 7E AE C2 73 E7 61 78 5D D0 | success or wait | 726817285 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\nav_logo107[1].png Offset: unknown Length: 2380 Value: D3 A7 4F D7 F5 79 A6 A6 A6 BE 52 38 D7 C6 5D BB 04 C9 01 77 21 F9 E1 3D F3 88 E6 85 79 62 DE 0C CE B5 17 EF A6 7E 97 91 09 97 CC 35 17 14 F3 A2 79 6E C5 BC F3 EA E2 1D A6 D7 CD 14 71 BF C9 7F 0F 01 35 12 56 CF D8 5A 96 93 D9 86 07 E9 82 F0 A1 75 C4 46 D1 BC 79 F3 74 80 6E DE BC 19 CE 9F 3F 0F 69 69 | success or wait | 726839728 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\nav_logo107[1].png Offset: unknown Length: 1106 Value: 73 B6 AE C1 C2 39 A0 3E DC 3F 15 95 4F 0A 4C 74 2F 6A 50 2D A5 7A CE D6 35 58 F8 69 81 EF A9 F3 4F 2D 11 4E 4B B5 9C FC 66 AE 51 80 73 2C 8B 73 9B AA 9E 1E 38 F9 CD 5C A3 50 C8 B1 2C CE 6D AA 7A 06 C2 D9 85 81 18 2B 0A 8F 65 E1 5D 0C 84 B3 0B 03 31 56 14 1E CB C2 BB A8 84 D3 C7 08 29 DD 7C 1F 23 54 | success or wait | 726842739 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\nav_logo107[1].png Offset: unknown Length: 270 Value: 0A 4E 5F 7D 6F 1F 11 31 E0 A3 C7 72 FA AA 78 FB 88 90 01 1F AD 5A 7F F5 70 A2 5A 53 A5 E9 29 57 1A 8B A7 A6 AB A6 35 55 9A 9E 32 A5 B1 78 C4 0C 70 0A AD A7 39 E0 14 5A 4F A3 E0 CC 77 93 79 2D 18 4E D4 64 3D E5 9A 6C E0 08 D1 64 3D 65 9A AC D4 8F 68 60 B5 EE 25 65 3D 4D A8 D6 BD 64 AC 67 C1 1A 5B B7 | success or wait | 726865560 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\nav_logo107[1].png Offset: unknown Length: 3486 Value: 37 02 CE A9 AC 9C 53 5F BB C7 34 8C 05 53 0F 9C A4 A0 C2 29 2A 97 94 9A B2 B2 36 35 13 9C 4D 59 39 9B 6A CF 10 BD E2 67 88 64 E0 5C 2F 5C 9B E1 02 AF 17 AD 89 91 55 E6 0B E0 D1 75 39 D6 1B 52 4E 2A 9E 11 37 DF 8D 55 8B 6E DA 33 44 9A 34 15 A4 EF 10 99 FB 9F 65 CE 97 02 98 AB 1F 56 85 E5 C4 BE C2 B5 | success or wait | 726918527 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\nav_logo107[1].png Offset: unknown Length: 768 Value: 22 74 1C 4C BE E0 36 83 31 4F E0 34 D4 4F 95 6A ED E3 F2 FD E6 4D B9 1A 45 BC 31 84 E1 AA 5B EB 6A C1 94 EA 4A C2 EE 22 DE 95 74 F2 46 AC 4E BC 2B 89 EB CE A3 24 90 EB 4A C2 EE 22 DE 95 D4 73 58 98 4E BC 2B 89 6B F9 97 D1 60 28 9C 86 00 2A 05 67 66 56 56 2E 30 B9 D2 69 15 AF 16 CE 0C 1A 57 2A 3C 99 | success or wait | 726941410 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\nav_logo107[1].png Offset: unknown Length: 2562 Value: 93 0E 36 13 63 D3 29 96 53 F8 04 83 A0 8C 39 D7 62 F6 EA 8B 30 6B 75 EE FD B8 8D C2 FD EF BF FF 3E EA 32 D5 A4 B9 73 E7 92 45 8B 16 91 4F 3F FD 54 B7 C6 6D 1A BE 98 EA 10 C6 33 E2 21 35 67 AA E2 7A 3B E1 D5 02 CA 4F 9A FB 98 CF A2 D3 64 E3 A2 05 D5 0D 6F 5E 7B 11 2E EE 63 1E 3B 9D 24 9B 1E 2D 28 1F | success or wait | 726970587 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\nav_logo107[1].png Offset: unknown Length: 274 Value: 0C B1 42 75 5E 91 CA FB FC F9 F3 89 78 A1 70 8D DB 18 2E 53 AD 7B 51 45 8B 2C A7 37 CB 47 6F 7C A6 68 16 2E 59 AD 1B F2 0A C6 82 96 C6 12 7D CE 3C B1 9C 82 FC 87 9F 3C 79 32 62 E7 CE 9D 67 71 8D DB 7A 7C CE 40 11 9C C3 F5 F8 9C 81 22 38 03 F5 F9 9C 6A 5F C1 58 D0 D2 58 62 6B DD EC 3E A7 20 6F FB 5E | success or wait | 726972508 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\nav_logo107[1].png Offset: unknown Length: 3843 Value: 19 3D 2B E9 C2 85 0B 6B 43 42 42 20 23 23 03 B2 B2 B2 CC 22 CC 0B F3 C4 BC 35 A8 5E 12 9C F9 A9 9A 57 58 F6 1A 32 9F F3 FC F9 F3 A9 99 99 99 90 17 C2 BC B5 69 76 79 34 65 4E A1 E5 1E A8 76 9F CA 96 7B A0 DA 7D E6 D6 D9 B3 67 75 96 2E 2F 84 79 E7 15 68 69 5B C9 09 D8 6C D8 8D 4E DD 92 FD 05 61 7D E9 | success or wait | 727123699 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\favicon[1].ico Offset: unknown Length: 468 Value: 37 96 00 FF 39 96 00 FF 3A 91 01 FF 3F 93 00 FF 42 87 01 FF ED E1 DB FF FF FF FE FF F6 F1 E8 FF B5 6C 28 FF BB 54 00 FF B9 5D 0E FF E4 CF B9 FF FF FF FE FF 9B B1 99 FF 20 70 1D FF 37 95 00 FF 3D 96 03 FF 3B 93 00 FF 36 89 09 FF 2D 65 3A FF 0F 2B 8A FF FD FF FF FF FD FF FF FF D2 A9 82 FF B9 53 00 FF | success or wait | 727243698 | 
| Section loaded | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\favicon[1].ico Access: query and read Type: commit Baseaddress: 5460000 Size: 4096 Protection: readonly Mapped to pid: own pid | success or wait | 727276558 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 728218752 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 728219246 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 5460000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 728220282 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 30 Value: 76 61 72 20 5F 3D 5F 7C 7C 7B 7D 3B 28 66 75 6E 63 74 69 6F 6E 28 5F 29 7B 0A 74 72 79 7B | success or wait | 728228101 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 0A 5F 2E 62 61 3D 66 75 6E 63 74 69 6F 6E 28 65 29 7B 74 68 72 6F 77 20 65 3B 7D 3B 5F 2E 6B 3D 76 6F 69 64 20 30 3B 5F 2E 6C 3D 21 30 3B 5F 2E 70 3D 6E 75 6C 6C 3B 5F 2E 77 3D 21 31 3B 5F 2E 63 61 3D 66 75 6E 63 74 69 6F 6E 28 29 7B 72 65 74 75 72 6E 20 66 75 6E 63 74 69 6F 6E 28 65 29 7B 72 65 74 | success or wait | 728547637 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 70 65 6F 66 20 65 2E 70 72 6F 70 65 72 74 79 49 73 45 6E 75 6D 65 72 61 62 6C 65 26 26 21 65 2E 70 72 6F 70 65 72 74 79 49 73 45 6E 75 6D 65 72 61 62 6C 65 28 22 63 61 6C 6C 22 29 29 72 65 74 75 72 6E 22 66 75 6E 63 74 69 6F 6E 22 7D 65 6C 73 65 20 72 65 74 75 72 6E 22 6E 75 6C 6C 22 3B 0A 65 6C 73 | success or wait | 728550948 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 985 Value: 79 70 65 2E 62 69 6E 64 26 26 2D 31 21 3D 77 69 6E 64 6F 77 2E 46 75 6E 63 74 69 6F 6E 2E 70 72 6F 74 6F 74 79 70 65 2E 62 69 6E 64 2E 74 6F 53 74 72 69 6E 67 28 29 2E 69 6E 64 65 78 4F 66 28 22 6E 61 74 69 76 65 20 63 6F 64 65 22 29 3F 5F 2E 62 61 61 3A 5F 2E 63 61 61 3B 72 65 74 75 72 6E 20 5F 2E | success or wait | 728553017 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 5F 2E 72 62 2E 73 70 6C 69 63 65 2E 63 61 6C 6C 28 65 2C 62 2C 31 29 3B 72 65 74 75 72 6E 20 64 7D 3B 5F 2E 73 62 3D 66 75 6E 63 74 69 6F 6E 28 65 29 7B 76 61 72 20 61 3D 65 2E 6C 65 6E 67 74 68 3B 69 66 28 30 3C 61 29 7B 66 6F 72 28 76 61 72 20 62 3D 28 30 2C 77 69 6E 64 6F 77 2E 41 72 72 61 79 29 | success or wait | 728556019 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 6F 77 2E 4F 62 6A 65 63 74 2E 70 72 6F 74 6F 74 79 70 65 2E 68 61 73 4F 77 6E 50 72 6F 70 65 72 74 79 2E 63 61 6C 6C 28 64 2C 62 29 26 26 28 65 5B 62 5D 3D 64 5B 62 5D 29 7D 7D 3B 5F 2E 64 61 61 3D 66 75 6E 63 74 69 6F 6E 28 65 29 7B 69 66 28 22 66 75 6E 63 74 69 6F 6E 22 3D 3D 74 79 70 65 6F 66 20 | success or wait | 728558160 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 995 Value: 75 6E 63 74 69 6F 6E 28 65 29 7B 69 66 28 65 2E 77 6C 21 3D 65 2E 42 2E 6C 65 6E 67 74 68 29 7B 66 6F 72 28 76 61 72 20 61 3D 30 2C 62 3D 30 3B 61 3C 65 2E 42 2E 6C 65 6E 67 74 68 3B 29 7B 76 61 72 20 64 3D 65 2E 42 5B 61 5D 3B 28 30 2C 5F 2E 4A 62 29 28 65 2E 4D 2C 64 29 26 26 28 65 2E 42 5B 62 2B | success or wait | 728561095 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 985 Value: 29 7C 7C 28 28 30 3D 3D 6D 5B 32 5D 2E 6C 65 6E 67 74 68 29 3C 28 30 3D 3D 6F 5B 32 5D 2E 6C 65 6E 67 74 68 29 3F 2D 31 3A 28 30 3D 3D 6D 5B 32 5D 2E 6C 65 6E 67 74 68 29 3E 28 30 3D 3D 6F 5B 32 5D 2E 6C 65 6E 67 74 68 29 3F 31 3A 30 29 7C 7C 28 6D 5B 32 5D 3C 6F 5B 32 5D 3F 2D 31 3A 6D 5B 32 5D 3E | success or wait | 728564048 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 66 29 74 72 79 7B 76 61 72 20 68 3D 66 2E 63 61 6C 6C 28 63 7C 7C 65 2E 6C 61 2C 61 29 3B 28 30 2C 5F 2E 4B 61 29 28 68 29 26 26 28 65 2E 79 44 3D 65 2E 79 44 26 26 28 68 3D 3D 61 7C 7C 68 20 69 6E 73 74 61 6E 63 65 6F 66 20 77 69 6E 64 6F 77 2E 45 72 72 6F 72 29 2C 65 2E 4D 3D 61 3D 68 29 3B 61 20 | success or wait | 728583437 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 28 29 7B 74 68 69 73 2E 71 76 3D 7B 7D 3B 74 68 69 73 2E 4D 3D 5B 5D 3B 74 68 69 73 2E 57 3D 5B 5D 3B 74 68 69 73 2E 42 3D 5B 5D 3B 74 68 69 73 2E 6B 61 3D 5B 5D 3B 74 68 69 73 2E 6C 61 3D 7B 7D 3B 74 68 69 73 2E 5A 3D 74 68 69 73 2E 74 61 3D 6E 65 77 20 5F 2E 69 63 28 5B 5D 2C 22 22 29 7D 3B 0A 5F | success or wait | 728585692 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 722 Value: 30 2C 5F 2E 62 61 29 28 28 30 2C 77 69 6E 64 6F 77 2E 45 72 72 6F 72 29 28 22 4D 6F 64 75 6C 65 20 61 6C 72 65 61 64 79 20 6C 6F 61 64 65 64 3A 20 22 2B 61 5B 62 5D 29 29 3B 66 6F 72 28 76 61 72 20 64 3D 5B 5D 2C 62 3D 30 3B 62 3C 61 2E 6C 65 6E 67 74 68 3B 62 2B 2B 29 64 3D 64 2E 63 6F 6E 63 61 74 | success or wait | 728590829 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 61 2E 70 75 73 68 28 61 29 7D 3B 5F 2E 41 63 3D 66 75 6E 63 74 69 6F 6E 28 65 2C 61 29 7B 65 2E 5A 3D 65 2E 71 76 5B 61 5D 7D 3B 5F 2E 42 63 3D 66 75 6E 63 74 69 6F 6E 28 65 29 7B 21 65 2E 5A 7C 7C 65 2E 5A 2E 67 65 74 49 64 28 29 3B 65 2E 5A 3D 5F 2E 70 7D 3B 5F 2E 43 63 3D 66 75 6E 63 74 69 6F 6E | success or wait | 728593873 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 61 3D 5F 2E 6C 2C 5F 2E 47 63 2E 6F 70 65 72 61 3D 5F 2E 6C 2C 62 3D 61 3D 2F 4F 70 65 72 61 5B 5C 2F 5C 73 5D 28 5C 53 2B 29 2F 29 3A 30 3C 3D 65 2E 69 6E 64 65 78 4F 66 28 22 4D 53 49 45 22 29 3F 28 5F 2E 46 63 2E 6E 64 3D 5F 2E 6C 2C 5F 2E 47 63 2E 6E 64 3D 5F 2E 6C 2C 62 3D 61 3D 2F 4D 53 49 45 | success or wait | 728595996 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 65 6E 67 69 6E 65 2E 49 45 22 2C 5F 2E 46 63 2E 6E 64 2C 5F 2E 6B 29 3B 28 30 2C 5F 2E 71 61 29 28 22 67 6F 6F 67 6C 65 2E 62 72 6F 77 73 65 72 2E 65 6E 67 69 6E 65 2E 47 45 43 4B 4F 22 2C 5F 2E 46 63 2E 68 79 2C 5F 2E 6B 29 3B 28 30 2C 5F 2E 71 61 29 28 22 67 6F 6F 67 6C 65 2E 62 72 6F 77 73 65 72 | success or wait | 728598132 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 647 Value: 5D 7C 7C 22 22 2C 69 3D 63 5B 67 5D 7C 7C 22 22 2C 6A 3D 28 30 2C 77 69 6E 64 6F 77 2E 52 65 67 45 78 70 29 28 22 28 5C 5C 64 2A 29 28 5C 5C 44 2A 29 22 2C 22 67 22 29 2C 6D 3D 28 30 2C 77 69 6E 64 6F 77 2E 52 65 67 45 78 70 29 28 22 28 5C 5C 64 2A 29 28 5C 5C 44 2A 29 22 2C 22 67 22 29 3B 64 6F 7B | success or wait | 728599813 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 44 Value: 3D 3D 65 2C 65 3D 30 3D 3D 65 7C 7C 31 3D 3D 65 3F 22 48 65 69 67 68 74 22 3A 22 57 69 64 74 68 22 3B 69 66 28 5F 2E 46 63 2E 48 73 | success or wait | 728601477 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 26 26 28 5F 2E 47 63 2E 50 74 7C 7C 5F 2E 47 63 2E 50 78 7C 7C 5F 2E 47 63 2E 48 44 29 29 7B 69 66 28 5F 2E 47 63 2E 48 44 29 72 65 74 75 72 6E 20 61 3D 77 69 6E 64 6F 77 2E 73 63 72 65 65 6E 2E 77 69 64 74 68 2C 36 30 30 3D 3D 61 3F 22 57 69 64 74 68 22 3D 3D 65 3F 36 30 30 3A 31 30 32 34 3A 31 30 | success or wait | 728745132 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 5B 5D 7D 62 3D 65 2E 6D 61 74 63 68 28 5F 2E 50 63 29 3B 64 3D 62 5B 32 5D 26 26 28 30 2C 77 69 6E 64 6F 77 2E 52 65 67 45 78 70 29 28 22 5C 5C 62 22 2B 62 5B 32 5D 2B 22 5C 5C 62 22 29 3B 62 3D 28 61 7C 7C 77 69 6E 64 6F 77 2E 64 6F 63 75 6D 65 6E 74 29 2E 67 65 74 45 6C 65 6D 65 6E 74 73 42 79 54 | success or wait | 728745680 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 761 Value: 73 74 65 6E 65 72 28 61 2C 62 2C 5F 2E 77 29 3A 65 2E 61 74 74 61 63 68 45 76 65 6E 74 28 22 6F 6E 22 2B 61 2C 62 29 7D 3B 5F 2E 5A 63 3D 66 75 6E 63 74 69 6F 6E 28 65 2C 61 2C 62 29 7B 65 2E 72 65 6D 6F 76 65 45 76 65 6E 74 4C 69 73 74 65 6E 65 72 3F 65 2E 72 65 6D 6F 76 65 45 76 65 6E 74 4C 69 73 | success or wait | 728747848 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 6A 2C 68 28 63 29 29 72 65 74 75 72 6E 20 63 7D 72 65 74 75 72 6E 22 66 75 6E 63 74 69 6F 6E 22 3D 3D 74 79 70 65 6F 66 20 64 3F 62 3A 63 7D 3B 0A 5F 2E 65 64 3D 66 75 6E 63 74 69 6F 6E 28 65 2C 61 2C 62 29 7B 69 66 28 21 28 30 2C 5F 2E 64 64 29 28 33 32 2C 5B 65 2C 61 2C 62 5D 2C 30 2C 5F 2E 6C 29 | success or wait | 728752181 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 22 2B 61 3A 22 22 29 7D 3B 5F 2E 69 64 3D 66 75 6E 63 74 69 6F 6E 28 29 7B 76 61 72 20 65 3D 77 69 6E 64 6F 77 2E 6C 6F 63 61 74 69 6F 6E 3B 72 65 74 75 72 6E 20 65 2E 68 61 73 68 3F 65 2E 68 72 65 66 2E 73 75 62 73 74 72 28 65 2E 68 72 65 66 2E 69 6E 64 65 78 4F 66 28 22 23 22 29 29 3A 22 22 7D 3B | success or wait | 728754576 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 376 Value: 6E 28 65 29 7B 66 6F 72 28 76 61 72 20 61 3D 30 3B 61 3C 5F 2E 73 64 2E 6C 65 6E 67 74 68 3B 61 2B 2B 29 69 66 28 5F 2E 73 64 5B 61 5D 3D 3D 65 29 72 65 74 75 72 6E 3B 5F 2E 73 64 2E 70 75 73 68 28 65 29 3B 5F 2E 74 64 7C 7C 28 5F 2E 75 64 3D 77 69 6E 64 6F 77 2E 6F 72 69 65 6E 74 61 74 69 6F 6E 2C | success or wait | 728755824 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 64 3D 66 75 6E 63 74 69 6F 6E 28 29 7B 69 66 28 21 28 22 6F 72 69 65 6E 74 61 74 69 6F 6E 22 69 6E 20 77 69 6E 64 6F 77 26 26 21 28 30 2C 5F 2E 71 64 29 28 29 26 26 77 69 6E 64 6F 77 2E 6F 72 69 65 6E 74 61 74 69 6F 6E 3D 3D 5F 2E 75 64 7C 7C 77 69 6E 64 6F 77 2E 69 6E 6E 65 72 57 69 64 74 68 3D 3D | success or wait | 728828226 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 29 7C 7C 30 3D 3D 61 29 26 26 65 2E 6F 66 66 73 65 74 48 65 69 67 68 74 29 61 3D 65 2E 6F 66 66 73 65 74 48 65 69 67 68 74 2D 28 30 2C 5F 2E 7A 64 29 28 65 2C 22 70 61 64 64 69 6E 67 2D 74 6F 70 22 29 2D 28 30 2C 5F 2E 7A 64 29 28 65 2C 22 70 61 64 64 69 6E 67 2D 62 6F 74 74 6F 6D 22 29 2D 28 30 2C | success or wait | 728830375 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 7C 22 72 65 6C 61 74 69 76 65 22 3D 3D 61 29 29 72 65 74 75 72 6E 20 65 7D 72 65 74 75 72 6E 20 5F 2E 70 7D 3B 0A 5F 2E 44 64 3D 66 75 6E 63 74 69 6F 6E 28 65 29 7B 76 61 72 20 61 3B 74 72 79 7B 61 3D 65 2E 6F 66 66 73 65 74 50 61 72 65 6E 74 7D 63 61 74 63 68 28 62 29 7B 61 3D 28 30 2C 5F 2E 43 64 | success or wait | 728832646 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 628 Value: 76 65 6E 74 3B 5F 2E 46 63 2E 6E 64 3F 65 2E 63 61 6E 63 65 6C 42 75 62 62 6C 65 3D 5F 2E 6C 3A 65 2E 73 74 6F 70 50 72 6F 70 61 67 61 74 69 6F 6E 26 26 65 2E 73 74 6F 70 50 72 6F 70 61 67 61 74 69 6F 6E 28 29 7D 3B 5F 2E 50 64 3D 66 75 6E 63 74 69 6F 6E 28 65 29 7B 65 2E 73 74 79 6C 65 2E 64 69 73 | success or wait | 728834242 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 41 72 72 61 79 2E 70 72 6F 74 6F 74 79 70 65 2E 69 6E 64 65 78 4F 66 2E 63 61 6C 6C 28 65 2C 61 2C 62 29 3B 66 6F 72 28 62 3D 62 3D 3D 5F 2E 70 3F 30 3A 30 3E 62 3F 77 69 6E 64 6F 77 2E 4D 61 74 68 2E 6D 61 78 28 30 2C 65 2E 6C 65 6E 67 74 68 2B 62 29 3A 62 3B 62 3C 65 2E 6C 65 6E 67 74 68 3B 62 2B | success or wait | 728837242 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 65 6D 65 6E 74 73 42 79 54 61 67 4E 61 6D 65 28 22 41 22 29 3B 77 69 6E 64 6F 77 2E 67 6F 6F 67 6C 65 2E 62 61 73 65 5F 68 72 65 66 3D 28 30 2C 5F 2E 59 64 29 28 77 69 6E 64 6F 77 2E 67 6F 6F 67 6C 65 2E 62 61 73 65 5F 68 72 65 66 2C 65 2C 61 29 3B 66 6F 72 28 76 61 72 20 66 3D 30 2C 67 3B 67 3D 63 | success or wait | 728839388 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 797 Value: 68 69 73 2E 42 2C 22 6D 6F 75 73 65 6F 76 65 72 22 2C 74 68 69 73 2E 6C 61 29 3B 28 30 2C 5F 2E 59 63 29 28 74 68 69 73 2E 42 2C 22 6D 6F 75 73 65 6F 75 74 22 2C 74 68 69 73 2E 57 29 3B 28 30 2C 5F 2E 59 63 29 28 74 68 69 73 2E 42 2C 22 66 6F 63 75 73 22 2C 74 68 69 73 2E 6C 61 29 3B 28 30 2C 5F 2E | success or wait | 728841271 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 70 65 6E 28 22 22 29 29 3B 64 2E 47 4F 4F 47 4C 45 5F 46 45 45 44 42 41 43 4B 5F 53 54 41 52 54 5F 41 52 47 55 4D 45 4E 54 53 3D 61 72 67 75 6D 65 6E 74 73 3B 66 3F 66 2E 61 70 70 6C 79 28 64 2C 61 72 67 75 6D 65 6E 74 73 29 3A 28 64 3D 64 2E 64 6F 63 75 6D 65 6E 74 2C 66 3D 64 2E 63 72 65 61 74 65 | success or wait | 728844262 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 61 61 2C 66 75 6E 63 74 69 6F 6E 28 61 29 7B 69 66 28 61 20 69 6E 20 5F 2E 69 65 29 72 65 74 75 72 6E 20 5F 2E 69 65 5B 61 5D 3B 76 61 72 20 65 3D 61 2E 63 68 61 72 43 6F 64 65 41 74 28 30 29 2C 62 3D 22 5C 5C 75 22 3B 31 36 3E 65 3F 62 2B 3D 22 30 30 30 22 3A 32 35 36 3E 65 3F 62 2B 3D 22 30 30 22 | success or wait | 728846372 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1008 Value: 2E 70 6D 63 3D 5F 2E 70 2C 77 69 6E 64 6F 77 2E 67 6F 6F 67 6C 65 2E 73 6D 63 3D 5F 2E 70 29 3B 22 69 6E 69 74 22 3D 3D 65 3F 5F 2E 6E 65 3D 5F 2E 6C 3A 22 64 69 73 70 6F 73 65 22 3D 3D 65 26 26 28 5F 2E 6E 65 3D 5F 2E 77 29 7D 7D 3B 5F 2E 6F 65 3D 66 75 6E 63 74 69 6F 6E 28 65 2C 61 2C 62 29 7B 74 | success or wait | 728848481 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 45 65 3D 66 75 6E 63 74 69 6F 6E 28 29 7B 76 61 72 20 65 3D 5F 2E 6D 63 2E 66 61 28 29 3B 69 66 28 21 5F 2E 46 65 29 7B 65 2E 45 48 3D 5F 2E 6C 3B 76 61 72 20 61 3D 6E 65 77 20 5F 2E 44 65 28 77 69 6E 64 6F 77 2E 67 6F 6F 67 6C 65 2E 78 6A 73 75 29 3B 65 2E 6E 4A 3D 61 3B 5F 2E 46 65 3D 5F 2E 6C 7D | success or wait | 728851501 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 64 6F 77 2E 4D 61 74 68 2E 6D 61 78 28 30 2C 65 2E 6C 65 6E 67 74 68 2B 62 29 3A 62 3B 69 66 28 28 30 2C 5F 2E 58 61 29 28 65 29 29 72 65 74 75 72 6E 21 28 30 2C 5F 2E 58 61 29 28 61 29 7C 7C 31 21 3D 61 2E 6C 65 6E 67 74 68 3F 2D 31 3A 65 2E 69 6E 64 65 78 4F 66 28 61 2C 62 29 3B 66 6F 72 28 3B 62 | success or wait | 728852373 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 29 28 65 29 3F 65 2E 73 70 6C 69 74 28 22 22 29 3A 65 2C 66 3D 30 3B 66 3C 64 3B 66 2B 2B 29 69 66 28 66 20 69 6E 20 63 26 26 21 61 2E 63 61 6C 6C 28 62 2C 63 5B 66 5D 2C 66 2C 65 29 29 72 65 74 75 72 6E 20 5F 2E 77 3B 72 65 74 75 72 6E 20 5F 2E 6C 7D 3B 0A 5F 2E 4A 65 3D 22 53 74 6F 70 49 74 65 72 | success or wait | 728854535 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 428 Value: 5F 2E 4B 62 29 28 74 68 69 73 29 2C 5F 2E 6C 29 3A 5F 2E 77 7D 3B 5F 2E 49 2E 67 65 74 3D 66 75 6E 63 74 69 6F 6E 20 24 6A 28 61 2C 62 29 7B 72 65 74 75 72 6E 28 30 2C 5F 2E 4A 62 29 28 74 68 69 73 2E 4D 2C 61 29 3F 74 68 69 73 2E 4D 5B 61 5D 3A 62 7D 3B 5F 2E 49 2E 73 65 74 3D 66 75 6E 63 74 69 6F | success or wait | 728855854 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 72 65 61 74 65 64 22 29 29 3B 62 3E 3D 64 2E 6C 65 6E 67 74 68 26 26 28 30 2C 5F 2E 62 61 29 28 5F 2E 4A 65 29 3B 76 61 72 20 68 3D 64 5B 62 2B 2B 5D 3B 72 65 74 75 72 6E 20 61 3F 68 3A 63 5B 68 5D 7D 7D 3B 72 65 74 75 72 6E 20 68 7D 3B 0A 5F 2E 4F 65 3D 5F 2E 4E 65 3D 5F 2E 4D 65 3D 5F 2E 4C 65 3D | success or wait | 728857541 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 70 72 6F 74 6F 74 79 70 65 2E 64 69 73 70 6F 73 65 3D 66 75 6E 63 74 69 6F 6E 20 24 6F 28 29 7B 74 68 69 73 2E 41 61 7C 7C 28 74 68 69 73 2E 41 61 3D 5F 2E 6C 2C 74 68 69 73 2E 57 64 28 29 29 7D 3B 5F 2E 54 62 2E 70 72 6F 74 6F 74 79 70 65 2E 57 64 3D 66 75 6E 63 74 69 6F 6E 20 24 70 28 29 7B 74 68 | success or wait | 728861979 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 638 Value: 2E 70 72 6F 74 6F 74 79 70 65 2E 6D 65 73 73 61 67 65 3D 22 41 6C 72 65 61 64 79 20 63 61 6C 6C 65 64 22 3B 28 30 2C 5F 2E 67 62 29 28 5F 2E 66 63 2C 5F 2E 68 62 29 3B 5F 2E 66 63 2E 70 72 6F 74 6F 74 79 70 65 2E 6D 65 73 73 61 67 65 3D 22 44 65 66 65 72 72 65 64 20 77 61 73 20 63 61 6E 63 65 6C 6C | success or wait | 728863587 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 157 Value: 28 29 7B 5F 2E 69 63 2E 44 62 2E 57 64 2E 63 61 6C 6C 28 74 68 69 73 29 3B 28 30 2C 5F 2E 55 62 29 28 74 68 69 73 2E 76 42 29 7D 3B 0A 28 30 2C 5F 2E 67 62 29 28 5F 2E 6D 63 2C 5F 2E 54 62 29 3B 28 30 2C 5F 2E 50 61 29 28 5F 2E 6D 63 29 3B 5F 2E 49 3D 5F 2E 6D 63 2E 70 72 6F 74 6F 74 79 70 65 3B 5F | success or wait | 728865517 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 4E 3D 5F 2E 70 3B 5F 2E 49 2E 52 57 3D 66 75 6E 63 74 69 6F 6E 20 24 43 28 61 2C 62 29 7B 69 66 28 28 30 2C 5F 2E 58 61 29 28 61 29 29 7B 66 6F 72 28 76 61 72 20 64 3D 61 2E 73 70 6C 69 74 28 22 2F 22 29 2C 63 3D 5B 5D 2C 66 3D 30 3B 66 3C 64 2E 6C 65 6E 67 74 68 3B 66 2B 2B 29 7B 76 61 72 20 67 3D | success or wait | 728874209 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 432 Value: 2E 65 78 70 6F 72 74 53 79 6D 62 6F 6C 22 2C 5F 2E 66 62 2C 5F 2E 6B 29 3B 28 30 2C 5F 2E 71 61 29 28 22 67 6F 6F 67 6C 65 2E 65 78 70 6F 72 74 50 72 6F 70 65 72 74 79 22 2C 66 75 6E 63 74 69 6F 6E 28 65 2C 61 2C 62 29 7B 65 5B 61 5D 3D 62 7D 2C 5F 2E 6B 29 3B 28 30 2C 5F 2E 71 61 29 28 22 67 6F 6F | success or wait | 728875550 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 72 65 56 65 72 73 69 6F 6E 73 22 2C 5F 2E 4A 63 2C 5F 2E 6B 29 3B 28 30 2C 5F 2E 71 61 29 28 22 67 6F 6F 67 6C 65 2E 62 72 6F 77 73 65 72 2E 69 73 45 6E 67 69 6E 65 56 65 72 73 69 6F 6E 22 2C 5F 2E 4B 63 2C 5F 2E 6B 29 3B 28 30 2C 5F 2E 71 61 29 28 22 67 6F 6F 67 6C 65 2E 62 72 6F 77 73 65 72 2E 69 | success or wait | 728950569 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 2E 68 6F 73 74 3B 28 30 2C 5F 2E 71 61 29 28 22 67 6F 6F 67 6C 65 2E 6E 61 76 2E 67 6F 22 2C 5F 2E 65 64 2C 5F 2E 6B 29 3B 28 30 2C 5F 2E 71 61 29 28 22 67 6F 6F 67 6C 65 2E 6E 61 76 2E 73 65 61 72 63 68 22 2C 5F 2E 67 64 2C 5F 2E 6B 29 3B 28 30 2C 5F 2E 71 61 29 28 22 67 6F 6F 67 6C 65 2E 6E 61 76 | success or wait | 728952760 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 2E 71 61 29 28 22 67 6F 6F 67 6C 65 2E 73 74 79 6C 65 2E 69 73 52 74 6C 22 2C 5F 2E 79 64 2C 5F 2E 6B 29 3B 20 28 30 2C 5F 2E 71 61 29 28 22 67 6F 6F 67 6C 65 2E 73 74 79 6C 65 2E 61 64 64 43 6C 61 73 73 22 2C 5F 2E 49 64 2C 5F 2E 6B 29 3B 28 30 2C 5F 2E 71 61 29 28 22 67 6F 6F 67 6C 65 2E 73 74 79 | success or wait | 728954865 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 976 Value: 7D 2C 5F 2E 6B 29 3B 28 30 2C 5F 2E 71 61 29 28 22 67 6F 6F 67 6C 65 2E 75 74 69 6C 2E 72 61 74 65 4C 69 6D 69 74 46 75 6E 63 74 69 6F 6E 22 2C 5F 2E 52 64 2C 5F 2E 6B 29 3B 28 30 2C 5F 2E 71 61 29 28 22 67 6F 6F 67 6C 65 2E 75 74 69 6C 2E 69 73 51 75 65 72 79 45 6D 70 74 79 22 2C 5F 2E 53 64 2C 5F | success or wait | 728956935 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 61 28 29 26 26 28 77 69 6E 64 6F 77 2E 63 6C 65 61 72 54 69 6D 65 6F 75 74 28 74 68 69 73 2E 74 61 29 2C 74 68 69 73 2E 41 61 3D 77 69 6E 64 6F 77 2E 73 65 74 54 69 6D 65 6F 75 74 28 28 30 2C 5F 2E 64 62 29 28 74 68 69 73 2E 4D 55 2C 74 68 69 73 29 2C 31 33 30 29 29 7D 3B 5F 2E 49 2E 6E 53 3D 66 75 | success or wait | 728959920 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 64 3B 62 6F 72 64 65 72 2D 63 6F 6C 6F 72 3A 23 66 66 66 20 74 72 61 6E 73 70 61 72 65 6E 74 3B 62 6F 72 64 65 72 2D 74 6F 70 2D 77 69 64 74 68 3A 30 3B 63 6F 6E 74 65 6E 74 3A 27 27 3B 64 69 73 70 6C 61 79 3A 62 6C 6F 63 6B 3B 66 6F 6E 74 2D 73 69 7A 65 3A 30 70 78 3B 68 65 69 67 68 74 3A 30 3B 6C | success or wait | 728962094 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1012 Value: 3A 74 68 69 73 2E 5A 2E 73 74 79 6C 65 2E 6C 65 66 74 3D 22 31 38 70 78 22 29 3B 74 68 69 73 2E 4D 2E 73 74 79 6C 65 2E 76 69 73 69 62 69 6C 69 74 79 3D 22 76 69 73 69 62 6C 65 22 7D 7D 3B 5F 2E 49 2E 75 4E 3D 66 75 6E 63 74 69 6F 6E 20 24 50 28 29 7B 74 68 69 73 2E 4D 26 26 28 28 30 2C 5F 2E 55 63 | success or wait | 728964344 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\rs=AItRSTPlPDh3JqT4hZcG--RlbldBDxGPAA[1] Offset: unknown Length: 1024 Value: 30 5D 29 7B 77 69 6E 64 6F 77 2E 67 6F 6F 67 6C 65 2E 6A 2E 63 66 67 3D 5F 2E 67 66 5B 31 5D 3B 62 72 65 61 6B 7D 7D 65 6C 73 65 20 77 69 6E 64 6F 77 2E 67 6F 6F 67 6C 65 2E 70 6D 63 26 26 28 77 69 6E 64 6F 77 2E 67 6F 6F 67 6C 65 2E 6A 2E 63 66 67 3D 77 69 6E 64 6F 77 2E 67 6F 6F 67 6C 65 2E 70 6D | success or wait | 728967403 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 734034986 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 734041367 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 5920000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 734048621 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 28 66 75 6E 63 74 69 6F 6E 28 29 7B 74 72 79 7B 76 61 72 20 69 3D 76 6F 69 64 20 30 2C 6B 3D 21 30 2C 6C 3D 6E 75 6C 6C 2C 6D 3D 21 31 2C 6E 2C 70 3D 74 68 69 73 2C 71 3D 66 75 6E 63 74 69 6F 6E 28 61 2C 62 2C 63 29 7B 61 3D 61 2E 73 70 6C 69 74 28 22 2E 22 29 3B 63 3D 63 7C 7C 70 3B 21 28 61 5B 30 | success or wait | 734069140 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 72 65 74 75 72 6E 22 6F 62 6A 65 63 74 22 3D 3D 62 26 26 61 21 3D 6C 7C 7C 22 66 75 6E 63 74 69 6F 6E 22 3D 3D 62 7D 2C 64 61 3D 66 75 6E 63 74 69 6F 6E 28 61 2C 62 2C 63 29 7B 72 65 74 75 72 6E 20 61 2E 63 61 6C 6C 2E 61 70 70 6C 79 28 61 2E 62 69 6E 64 2C 61 72 67 75 6D 65 6E 74 73 29 7D 2C 65 61 | success or wait | 734071157 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 512 Value: 2F 67 2C 6C 61 3D 2F 5C 22 2F 67 2C 68 61 3D 2F 5B 26 3C 3E 5C 22 5D 2F 3B 76 61 72 20 77 3D 41 72 72 61 79 2E 70 72 6F 74 6F 74 79 70 65 2C 6E 61 3D 77 2E 69 6E 64 65 78 4F 66 3F 66 75 6E 63 74 69 6F 6E 28 61 2C 62 2C 63 29 7B 72 65 74 75 72 6E 20 77 2E 69 6E 64 65 78 4F 66 2E 63 61 6C 6C 28 61 2C | success or wait | 734071683 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 5B 5D 2C 66 3D 30 2C 67 3D 75 28 61 29 3F 0A 61 2E 73 70 6C 69 74 28 22 22 29 3A 61 2C 68 3D 30 3B 68 3C 64 3B 68 2B 2B 29 69 66 28 68 20 69 6E 20 67 29 7B 76 61 72 20 6A 3D 67 5B 68 5D 3B 62 2E 63 61 6C 6C 28 63 2C 6A 2C 68 2C 61 29 26 26 28 65 5B 66 2B 2B 5D 3D 6A 29 7D 72 65 74 75 72 6E 20 65 7D | success or wait | 734072748 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 61 2E 69 6E 64 65 78 4F 66 28 22 4D 53 49 45 22 29 3B 7A 61 3D 28 79 61 3D 21 77 61 26 26 2D 31 21 3D 43 61 2E 69 6E 64 65 78 4F 66 28 22 57 65 62 4B 69 74 22 29 29 26 26 2D 31 21 3D 43 61 2E 69 6E 64 65 78 4F 66 28 22 4D 6F 62 69 6C 65 22 29 3B 41 61 3D 21 77 61 26 26 21 79 61 26 26 22 47 65 63 6B | success or wait | 734073497 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 366 Value: 29 29 3F 31 3A 30 29 7C 7C 28 28 30 3D 3D 72 5B 32 5D 2E 6C 65 6E 67 74 68 29 3C 28 30 3D 3D 74 5B 32 5D 2E 6C 65 6E 67 74 68 29 3F 2D 31 3A 28 30 3D 3D 72 5B 32 5D 2E 6C 65 6E 67 74 68 29 3E 28 30 3D 3D 74 5B 32 5D 2E 6C 65 6E 67 74 68 29 3F 31 3A 30 29 7C 7C 28 72 5B 32 5D 3C 74 5B 32 5D 3F 2D 31 | success or wait | 734074247 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 26 26 61 2E 6D 61 74 63 68 28 2F 5C 53 2B 2F 67 29 7C 7C 5B 5D 7D 2C 24 61 3D 66 75 6E 63 74 69 6F 6E 28 61 2C 62 29 7B 76 61 72 20 63 3D 59 61 28 61 29 2C 64 3D 72 61 28 61 72 67 75 6D 65 6E 74 73 2C 31 29 2C 65 3D 63 2E 6C 65 6E 67 74 68 2B 64 2E 6C 65 6E 67 74 68 3B 5A 61 28 63 2C 64 29 3B 61 2E | success or wait | 734075304 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 4E 61 6D 65 3B 22 66 75 6E 63 74 69 6F 6E 22 3D 3D 74 79 70 65 6F 66 20 68 2E 73 70 6C 69 74 26 26 30 3C 3D 6E 61 28 68 2E 73 70 6C 69 74 28 2F 5C 73 2B 2F 29 2C 61 29 26 26 28 66 5B 65 2B 2B 5D 3D 63 29 7D 66 2E 6C 65 6E 67 74 68 3D 65 3B 72 65 74 75 72 6E 20 66 7D 72 65 74 75 72 6E 20 67 7D 2C 6A | success or wait | 734076056 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 474 Value: 6F 64 65 54 79 70 65 29 29 7B 76 61 72 20 67 3B 61 3A 7B 69 66 28 66 26 26 22 6E 75 6D 62 65 72 22 3D 3D 74 79 70 65 6F 66 20 66 2E 6C 65 6E 67 74 68 29 7B 69 66 28 63 61 28 66 29 29 7B 67 3D 22 66 75 6E 63 74 69 6F 6E 22 3D 3D 74 79 70 65 6F 66 20 66 2E 69 74 65 6D 7C 7C 22 73 74 72 69 6E 67 22 3D | success or wait | 734076544 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 29 2E 72 65 70 6C 61 63 65 28 2F 28 5C 72 5C 6E 7C 5C 72 7C 5C 6E 29 2F 67 2C 22 22 29 29 3A 62 2E 70 75 73 68 28 61 2E 6E 6F 64 65 56 61 6C 75 65 29 3B 65 6C 73 65 20 69 66 28 61 2E 6E 6F 64 65 4E 61 6D 65 20 69 6E 20 6F 62 29 62 2E 70 75 73 68 28 6F 62 5B 61 2E 6E 6F 64 65 4E 61 6D 65 5D 29 3B 65 | success or wait | 734091099 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 5B 62 5D 3B 2B 2B 62 29 61 2E 70 75 73 68 28 63 5B 30 5D 29 3B 72 65 74 75 72 6E 20 61 2E 6A 6F 69 6E 28 22 2C 22 29 7D 2C 69 29 3B 76 61 72 20 79 62 2C 46 62 3D 66 75 6E 63 74 69 6F 6E 28 29 7B 7A 62 28 29 3B 71 28 22 67 62 61 72 2E 61 64 64 48 6F 76 65 72 22 2C 41 62 2C 69 29 3B 71 28 22 67 62 61 | success or wait | 734091914 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 576 Value: 77 69 64 74 68 3D 61 2E 6F 66 66 73 65 74 57 69 64 74 68 2C 62 2E 68 65 69 67 68 74 3D 61 2E 6F 66 66 73 65 74 48 65 69 67 68 74 2C 0A 62 3B 76 61 72 20 63 3D 61 2E 73 74 79 6C 65 2C 64 3D 63 2E 64 69 73 70 6C 61 79 2C 65 3D 63 2E 76 69 73 69 62 69 6C 69 74 79 2C 66 3D 63 2E 70 6F 73 69 74 69 6F 6E | success or wait | 734092451 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 2E 73 74 79 6C 65 2E 68 65 69 67 68 74 3D 61 2E 6F 66 66 73 65 74 48 65 69 67 68 74 2D 35 2B 22 70 78 22 2C 63 2E 73 74 79 6C 65 2E 77 69 64 74 68 3D 61 2E 6F 66 66 73 65 74 57 69 64 74 68 2D 33 2B 22 70 78 22 29 7D 7D 2C 53 62 3D 66 75 6E 63 74 69 6F 6E 28 61 2C 62 29 7B 69 66 28 61 29 7B 76 61 72 | success or wait | 734093550 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 22 29 29 7B 76 61 72 20 63 3D 61 2E 63 6C 61 73 73 4E 61 6D 65 3B 4E 28 61 2C 62 29 7C 7C 28 61 2E 63 6C 61 73 73 4E 61 6D 65 2B 3D 28 22 22 21 3D 63 3F 22 20 22 3A 22 22 29 2B 62 29 7D 7D 2C 54 62 3D 66 75 6E 63 74 69 6F 6E 28 61 2C 62 29 7B 76 61 72 20 63 3D 61 2E 63 6C 61 73 73 4E 61 6D 65 2C 64 | success or wait | 734094292 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 465 Value: 74 53 74 79 6C 65 2E 64 69 72 65 63 74 69 6F 6E 3A 6A 2E 73 74 79 6C 65 2E 64 69 72 65 63 74 69 6F 6E 3B 4E 62 3D 22 72 74 6C 22 3D 3D 6F 7D 6A 3D 4E 62 3F 6D 3A 6B 3B 62 3D 4E 62 3F 6D 3A 6B 3B 22 67 62 64 22 3D 3D 67 26 26 28 62 3D 21 62 29 3B 22 67 62 7A 22 3D 3D 67 26 26 28 62 3D 21 62 2C 6A 3D | success or wait | 734094772 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 0A 76 61 72 20 4F 61 2C 55 2C 54 3D 50 62 28 29 3B 69 66 28 62 29 7B 69 66 28 4F 61 3D 6A 3F 4D 61 74 68 2E 6D 61 78 28 54 2D 78 2D 47 2C 4A 29 3A 54 2D 78 2D 68 2C 55 3D 2D 28 54 2D 78 2D 68 2D 4F 61 29 2C 47 62 28 29 29 7B 76 61 72 20 75 63 3D 48 62 28 29 3B 28 36 3D 3D 75 63 7C 7C 37 3D 3D 75 63 | success or wait | 734095849 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 20 62 3D 61 2E 67 65 74 45 6C 65 6D 65 6E 74 73 42 79 54 61 67 4E 61 6D 65 28 22 61 22 29 2C 61 3D 5B 5D 2C 63 3D 4D 28 22 67 62 71 66 77 22 29 2C 64 3D 30 2C 65 3B 65 3D 62 5B 64 5D 3B 64 2B 2B 29 61 2E 70 75 73 68 28 65 29 3B 69 66 28 63 29 7B 76 61 72 20 66 3D 4D 28 22 67 62 71 66 71 77 22 29 2C | success or wait | 734096588 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 667 Value: 68 69 6C 64 4E 6F 64 65 73 28 29 3B 29 61 2E 72 65 6D 6F 76 65 43 68 69 6C 64 28 61 2E 66 69 72 73 74 43 68 69 6C 64 29 7D 2C 0A 42 62 3D 66 75 6E 63 74 69 6F 6E 28 61 29 7B 55 62 28 61 29 7D 2C 43 62 3D 66 75 6E 63 74 69 6F 6E 28 61 29 7B 61 3D 3D 4B 26 26 55 62 28 29 7D 2C 50 3D 66 75 6E 63 74 69 | success or wait | 734097169 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 26 26 28 61 3D 61 2E 6F 77 6E 65 72 44 6F 63 75 6D 65 6E 74 2C 62 2E 6C 65 66 74 2D 3D 61 2E 64 6F 63 75 6D 65 6E 74 45 6C 65 6D 65 6E 74 2E 63 6C 69 65 6E 74 4C 65 66 74 2B 61 2E 62 6F 64 79 2E 63 6C 69 65 6E 74 4C 65 66 74 2C 62 2E 74 6F 70 2D 3D 61 2E 64 6F 63 75 6D 65 6E 74 45 6C 65 6D 65 6E 74 | success or wait | 734098218 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 66 2E 78 2B 3D 65 2E 63 6C 69 65 6E 74 4C 65 66 74 7C 7C 30 2C 66 2E 79 2B 3D 65 2E 63 6C 69 65 6E 74 54 6F 70 7C 7C 30 29 3B 69 66 28 41 26 26 22 66 69 78 65 64 22 3D 3D 51 28 65 2C 22 70 6F 73 69 74 69 6F 6E 22 29 29 7B 66 2E 78 2B 3D 63 2E 62 6F 64 79 2E 73 63 72 6F 6C 6C 4C 65 66 74 3B 66 2E 79 | success or wait | 734098955 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 946 Value: 7C 7C 21 74 68 69 73 2E 4E 3F 42 28 45 72 72 6F 72 28 22 4D 69 73 73 69 6E 67 20 44 4F 4D 22 29 2C 22 73 62 72 22 2C 22 69 6E 69 74 22 29 3A 28 74 68 69 73 2E 61 61 3D 68 62 28 22 67 62 73 62 74 22 2C 74 68 69 73 2E 7A 29 2C 74 68 69 73 2E 24 3D 68 62 28 22 67 62 73 62 62 22 2C 74 68 69 73 2E 7A 29 | success or wait | 734101290 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 61 3D 61 2E 6D 68 3B 74 68 69 73 2E 51 61 3D 61 2E 64 3B 74 68 69 73 2E 42 3D 61 2E 65 3B 74 68 69 73 2E 54 3D 61 2E 70 3B 74 68 69 73 2E 4B 61 3D 61 2E 70 70 6C 3B 74 68 69 73 2E 6A 61 3D 61 2E 70 70 3B 74 68 69 73 2E 48 61 3D 61 2E 70 70 6D 3B 74 68 69 73 2E 54 61 3D 61 2E 73 3B 74 68 69 73 2E 49 | success or wait | 734102362 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 28 62 3D 5B 5D 2C 70 62 28 66 2C 62 2C 6B 29 2C 62 3D 62 2E 6A 6F 69 6E 28 22 22 29 29 2C 62 3D 62 2E 72 65 70 6C 61 63 65 28 2F 20 5C 78 41 44 20 2F 67 2C 22 20 22 29 2E 72 65 70 6C 61 63 65 28 2F 5C 78 41 44 2F 67 2C 22 22 29 2C 62 3D 62 2E 72 65 70 6C 61 63 65 28 2F 5C 75 32 30 30 42 2F 67 2C 22 | success or wait | 734103098 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 612 Value: 73 2E 62 2E 6B 28 29 3B 74 68 69 73 2E 4B 3D 6D 3B 6F 63 28 74 68 69 73 2C 6D 29 7D 3B 0A 6E 2E 4D 61 3D 66 75 6E 63 74 69 6F 6E 28 61 2C 62 2C 63 2C 64 2C 65 2C 66 2C 67 2C 68 2C 6A 2C 6F 29 7B 74 72 79 7B 76 61 72 20 72 3D 4D 28 22 67 62 6D 70 61 73 22 29 3B 69 66 28 61 29 66 6F 72 28 76 61 72 20 | success or wait | 734103644 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 2C 61 29 3B 53 2E 61 70 70 65 6E 64 43 68 69 6C 64 28 47 29 3B 45 2E 61 70 70 65 6E 64 43 68 69 6C 64 28 53 29 7D 76 61 72 20 4A 3D 50 28 22 73 70 61 6E 22 2C 22 67 62 6D 70 6E 77 22 29 2C 54 3D 50 28 22 73 70 61 6E 22 2C 22 67 62 70 73 22 29 3B 4A 2E 61 70 70 65 6E 64 43 68 69 6C 64 28 54 29 3B 54 | success or wait | 734104750 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 28 22 67 62 6D 70 69 22 2C 22 67 62 6D 70 69 64 22 29 7D 63 61 74 63 68 28 61 29 7B 42 28 61 2C 22 73 70 22 2C 22 70 70 65 22 29 7D 7D 3B 52 2E 70 72 6F 74 6F 74 79 70 65 2E 4C 61 3D 66 75 6E 63 74 69 6F 6E 28 29 7B 74 72 79 7B 76 61 72 20 61 3D 71 63 28 29 3B 69 66 28 61 29 66 6F 72 28 76 61 72 20 | success or wait | 734105494 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 43 68 69 6C 64 26 26 61 2E 66 69 72 73 74 43 68 69 6C 64 2E 6E 6F 64 65 56 61 6C 75 65 3F 61 2E 66 69 72 73 74 43 68 69 6C 64 2E 6E 6F 64 65 56 61 6C 75 65 3A 22 22 7D 3B 6E 3D 52 2E 70 72 6F 74 6F 74 79 70 65 3B 0A 6E 2E 56 61 3D 66 75 6E 63 74 69 6F 6E 28 61 29 7B 74 72 79 7B 74 68 69 73 2E 6A 61 | success or wait | 734106260 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 305 Value: 29 29 3B 69 66 28 72 29 7B 76 61 72 20 74 3D 72 2E 6D 61 74 63 68 28 6A 63 29 3B 6A 3D 21 74 3F 6E 65 77 20 79 28 30 2C 30 29 3A 6E 65 77 20 79 28 70 61 72 73 65 46 6C 6F 61 74 28 74 5B 31 5D 29 2C 70 61 72 73 65 46 6C 6F 61 74 28 74 5B 32 5D 29 29 7D 65 6C 73 65 20 6A 3D 6E 65 77 20 79 28 30 2C 30 | success or wait | 734106669 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 78 2B 43 2D 28 62 2D 32 30 29 2C 44 3D 68 63 28 61 29 2E 68 65 69 67 68 74 2C 45 3D 4D 61 74 68 2E 6D 69 6E 28 44 2D 62 2C 74 68 69 73 2E 4A 61 29 3B 61 2E 73 74 79 6C 65 2E 6D 61 78 48 65 69 67 68 74 3D 4D 61 74 68 2E 6D 61 78 28 37 34 2C 45 29 2B 22 70 78 22 3B 62 63 28 63 29 3B 74 68 69 73 2E 62 | success or wait | 734119937 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 67 62 61 72 2E 6C 6F 67 67 65 72 2E 5F 61 65 6D 3D 45 63 7D 7D 29 3B 76 61 72 20 42 63 3D 66 75 6E 63 74 69 6F 6E 28 61 29 7B 76 61 72 20 62 3D 61 2E 6D 61 74 63 68 28 46 63 29 3B 72 65 74 75 72 6E 20 62 3F 6E 65 77 20 47 63 28 62 5B 31 5D 7C 7C 22 22 2C 62 5B 32 5D 7C 7C 22 22 2C 62 5B 33 5D 7C 7C | success or wait | 734120734 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 374 Value: 2C 64 2C 65 29 7B 74 68 69 73 2E 7A 61 3D 61 3B 74 68 69 73 2E 6E 61 6D 65 3D 0A 62 3B 74 68 69 73 2E 79 61 3D 63 3B 74 68 69 73 2E 72 62 3D 64 3B 74 68 69 73 2E 47 3D 65 7D 2C 44 63 3D 66 75 6E 63 74 69 6F 6E 28 61 29 7B 76 61 72 20 62 3D 5B 61 2E 7A 61 3F 61 2E 7A 61 2B 22 2E 22 3A 22 22 2C 61 2E | success or wait | 734121178 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 63 3D 2F 5C 73 2A 3B 5C 73 2A 2F 3B 4A 63 2E 70 72 6F 74 6F 74 79 70 65 2E 69 73 45 6E 61 62 6C 65 64 3D 66 75 6E 63 74 69 6F 6E 28 29 7B 72 65 74 75 72 6E 20 6E 61 76 69 67 61 74 6F 72 2E 63 6F 6F 6B 69 65 45 6E 61 62 6C 65 64 7D 3B 4A 63 2E 70 72 6F 74 6F 74 79 70 65 2E 73 65 74 3D 66 75 6E 63 74 | success or wait | 734122252 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 50 72 6F 70 65 72 74 79 28 66 29 26 26 28 62 3D 74 68 69 73 2E 41 5B 66 5D 2C 2D 31 3D 3D 4C 63 2E 67 65 74 28 22 4F 47 50 22 2C 22 22 29 2E 69 6E 64 65 78 4F 66 28 22 2D 22 2B 62 2E 6B 65 79 29 29 29 7B 69 66 28 61 3D 4D 63 5B 62 2E 62 61 5D 29 28 61 3D 64 6F 63 75 6D 65 6E 74 2E 67 65 74 45 6C 65 | success or wait | 734122993 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 681 Value: 3D 64 3B 64 3D 76 28 61 2E 61 62 2C 61 29 3B 63 2E 6F 63 3D 64 3B 64 3D 76 28 61 2E 62 62 2C 61 29 3B 63 2E 6F 65 3D 64 3B 64 3D 76 28 61 2E 65 62 2C 61 29 3B 63 2E 6F 69 3D 64 3B 72 65 74 75 72 6E 20 63 7D 3B 76 61 72 20 52 63 3D 66 75 6E 63 74 69 6F 6E 28 61 2C 62 2C 63 29 7B 74 68 69 73 2E 44 3D | success or wait | 734123622 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 62 3D 66 75 6E 63 74 69 6F 6E 28 61 29 7B 69 66 28 28 61 3D 57 28 74 68 69 73 2C 61 29 29 26 26 30 3D 3D 61 2E 61 29 54 63 28 74 68 69 73 2C 61 29 2C 61 2E 61 3D 31 7D 3B 76 61 72 20 54 63 3D 66 75 6E 63 74 69 6F 6E 28 61 2C 62 29 7B 69 66 28 61 2E 59 29 7B 76 61 72 20 63 3D 73 65 74 54 69 6D 65 6F | success or wait | 734125067 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 61 2C 62 2C 63 2C 64 2C 65 2C 66 29 7B 66 3D 66 7C 7C 7B 7D 3B 64 26 26 28 66 2E 5F 77 67 3D 64 2E 76 2E 6E 29 3B 65 21 3D 3D 69 26 26 2D 31 21 3D 65 26 26 28 66 2E 5F 63 3D 65 29 3B 42 28 61 2C 62 2C 63 2C 66 29 7D 2C 55 63 3D 66 75 6E 63 74 69 6F 6E 28 61 2C 62 2C 63 2C 64 29 7B 64 3D 64 7C 7C 7B | success or wait | 734125812 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 650 Value: 3B 69 66 28 66 64 28 64 29 29 7B 76 61 72 20 65 3D 64 2E 77 2C 66 3D 22 22 3B 69 66 28 65 2E 66 21 3D 6C 29 7B 76 61 72 20 67 3D 5B 5D 3B 64 64 28 65 2C 22 74 22 2C 67 29 3B 66 6F 72 28 76 61 72 20 68 3D 30 2C 6A 3B 6A 3D 62 64 5B 68 5D 3B 2B 2B 68 29 64 64 28 65 2C 6A 2C 67 29 3B 66 3D 67 2E 6A 6F | success or wait | 734126379 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 6F 64 3D 66 75 6E 63 74 69 6F 6E 28 29 7B 69 66 28 28 30 3C 5A 63 7C 7C 30 3C 24 63 29 26 26 21 6E 64 29 7B 6D 64 28 29 3B 76 61 72 20 61 3D 30 2C 62 3D 6D 2C 63 3D 48 2E 77 67 2E 72 67 2C 64 3B 66 6F 72 28 64 20 69 6E 20 63 29 7B 76 61 72 20 65 3D 63 5B 64 5D 3B 66 64 28 65 29 3F 2B 2B 61 3A 33 3D | success or wait | 734127462 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 74 2E 67 65 74 45 6C 65 6D 65 6E 74 42 79 49 64 28 22 67 62 71 66 71 63 22 29 2C 65 3D 64 6F 63 75 6D 65 6E 74 2E 67 65 74 45 6C 65 6D 65 6E 74 42 79 49 64 28 22 67 62 71 66 77 66 22 29 2C 66 3D 64 6F 63 75 6D 65 6E 74 2E 67 65 74 45 6C 65 6D 65 6E 74 42 79 49 64 28 22 67 62 71 66 77 65 22 29 3B 61 | success or wait | 734129273 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 2C 31 45 33 29 3B 77 64 3D 69 7D 2C 42 64 3D 66 75 6E 63 74 69 6F 6E 28 61 29 7B 66 6F 72 28 76 61 72 20 62 3D 61 5B 30 5D 2C 63 3D 5B 5D 2C 64 3D 31 3B 33 3E 3D 64 3B 64 2B 2B 29 7B 76 61 72 20 65 3B 65 3D 28 65 3D 2F 5E 28 2E 2A 3F 29 5C 24 28 5C 64 29 5C 24 28 2E 2A 29 24 2F 2E 65 78 65 63 28 62 | success or wait | 734130009 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 390 Value: 6F 72 6D 3D 62 2E 4F 54 72 61 6E 73 66 6F 72 6D 3D 62 2E 74 72 61 6E 73 66 6F 72 6D 3D 22 73 63 61 6C 65 28 2E 32 29 22 7D 2C 44 64 3D 66 75 6E 63 74 69 6F 6E 28 29 7B 76 61 72 20 61 3D 64 6F 63 75 6D 65 6E 74 2E 67 65 74 45 6C 65 6D 65 6E 74 42 79 49 64 28 22 67 62 62 62 62 22 29 2E 73 74 79 6C 65 | success or wait | 734130451 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 28 6D 29 2C 73 65 74 54 69 6D 65 6F 75 74 28 44 64 2C 30 29 2C 30 3C 63 26 26 28 78 64 3D 73 65 74 54 69 6D 65 6F 75 74 28 41 64 2C 31 45 33 2A 63 29 29 7D 63 61 74 63 68 28 64 29 7B 42 28 64 2C 22 62 62 22 2C 22 73 22 29 7D 7D 2C 69 29 3B 71 28 22 67 62 61 72 2E 62 62 72 22 2C 66 75 6E 63 74 69 6F | success or wait | 734131502 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 22 29 3B 69 66 28 65 29 65 2E 73 72 63 3D 61 2C 62 26 26 28 65 2E 61 6C 74 3D 62 29 2C 63 26 26 28 65 2E 77 69 64 74 68 3D 63 29 2C 64 26 26 28 65 2E 68 65 69 67 68 74 3D 64 29 3B 65 6C 73 65 7B 76 61 72 20 66 3D 64 6F 63 75 6D 65 6E 74 2E 67 65 74 45 6C 65 6D 65 6E 74 42 79 49 64 28 22 67 62 71 6C | success or wait | 734132240 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 747 Value: 61 72 20 62 3D 6E 65 77 20 49 6D 61 67 65 28 30 2C 30 29 3B 62 2E 6F 6E 6C 6F 61 64 3D 66 75 6E 63 74 69 6F 6E 28 29 7B 63 28 29 7D 3B 62 2E 6F 6E 65 72 72 6F 72 3D 62 2E 6F 6E 61 62 6F 72 74 3D 66 75 6E 63 74 69 6F 6E 28 29 7B 63 28 6B 29 7D 3B 65 3D 6E 65 77 20 44 61 74 65 3B 62 2E 73 72 63 3D 61 | success or wait | 734132891 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 64 5B 65 5D 2E 6A 62 28 29 29 2C 63 5B 64 5B 65 5D 2E 73 61 28 29 5D 3D 64 5B 65 5D 2E 6C 62 28 29 2C 0A 63 2E 6D 62 2E 70 75 73 68 28 64 5B 65 5D 2E 73 61 28 29 29 3B 62 3D 5B 22 2F 2F 22 2C 5B 61 2E 72 61 28 29 2C 22 73 31 2E 76 34 2E 69 70 76 36 2D 65 78 70 2E 6C 2E 67 6F 6F 67 6C 65 2E 63 6F 6D | success or wait | 734133944 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 22 72 6E 64 22 2C 22 68 6D 61 63 22 5D 2C 57 64 3D 30 3B 57 64 3C 56 64 2E 6C 65 6E 67 74 68 3B 57 64 2B 2B 29 69 66 28 21 48 2E 76 36 62 5B 56 64 5B 57 64 5D 5D 29 62 72 65 61 6B 20 61 3B 76 61 72 20 58 64 3D 48 2E 76 36 62 2E 70 2B 22 2D 22 2B 48 2E 76 36 62 2E 72 6E 64 2B 22 2D 22 2B 48 2E 76 36 | success or wait | 734134685 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 369 Value: 29 7D 2C 6C 65 3D 66 75 6E 63 74 69 6F 6E 28 61 29 7B 76 61 72 20 62 3D 58 28 5A 2C 22 75 73 22 2C 5B 5D 29 3B 62 2E 70 75 73 68 28 61 29 3B 76 61 72 20 63 3D 2F 5E 68 74 74 70 73 3A 28 2E 2A 29 24 2F 2E 65 78 65 63 28 61 29 3B 63 26 26 62 2E 70 75 73 68 28 22 68 74 74 70 3A 22 2B 63 5B 31 5D 29 3B | success or wait | 734135122 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 28 61 3D 61 2E 75 29 26 26 6C 65 28 61 29 7D 5D 29 3B 6D 65 2E 6D 3D 66 75 6E 63 74 69 6F 6E 28 61 29 7B 76 61 72 20 62 3D 5A 2E 6D 73 7C 7C 22 68 74 74 70 73 3A 2F 2F 61 70 69 73 2E 67 6F 6F 67 6C 65 2E 63 6F 6D 22 2C 61 3D 61 5B 30 5D 3B 69 66 28 21 61 7C 7C 30 3C 3D 61 2E 69 6E 64 65 78 4F 66 28 | success or wait | 734136171 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 1024 Value: 2C 66 3D 63 5B 24 2E 41 62 5D 2C 67 3D 58 28 6B 65 28 64 29 2C 22 72 22 2C 5B 5D 29 2E 73 6F 72 74 28 29 2C 68 3D 58 28 6B 65 28 64 29 2C 22 4C 22 2C 5B 5D 29 2E 73 6F 72 74 28 29 2C 6A 3D 66 75 6E 63 74 69 6F 6E 28 61 29 7B 68 2E 70 75 73 68 2E 61 70 70 6C 79 28 68 2C 72 29 3B 76 61 72 20 62 3D 28 | success or wait | 734151289 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LLFPAG1G\sem_feed2a2e2d54cd5f40fb4b5f5244fff2[1].js Offset: unknown Length: 455 Value: 6C 61 63 65 28 2F 5C 2F 24 2F 2C 22 22 29 3B 69 66 28 77 65 28 62 2C 5A 2E 6D 29 29 72 65 74 75 72 6E 20 62 2B 61 5B 31 5D 7D 7D 3B 76 61 72 20 78 65 3D 2F 28 5B 5E 5C 2F 5D 2A 5C 2F 5C 2F 5B 5E 5C 2F 5D 2A 29 28 5C 2F 6A 73 5C 2F 2E 2A 29 24 2F 2C 76 65 3D 66 75 6E 63 74 69 6F 6E 28 61 29 7B 76 61 | success or wait | 734151785 | 
| Section loaded | Path: \BaseNamedObjects\DfRoot000159EBC Access: query and write and read Type: commit Baseaddress: 5420000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 734879728 | 
| Section loaded | Path: \KnownDlls\XmlLite.dll Access: write and read and execute Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 734881541 | 
| Section loaded | Path: C:\WINDOWS\system32\xmllite.dll Access: query and write and read and execute Type: image Baseaddress: 47060000 Size: 135168 Protection: read write Mapped to pid: own pid | success or wait | 734883065 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 734914401 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 734931743 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 734932705 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 734933839 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 734934210 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 6110000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 734934794 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 734941317 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 734941669 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 6110000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 734942217 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 735050432 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 735051354 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 735052429 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 735052784 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 6110000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 735053344 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 735056441 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 735056873 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 6110000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 735060323 | 
| Thread resumed | TID: 3236 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 735481148 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 735502312 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 735503299 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 735504431 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 735504807 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 6310000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 735505419 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 735508423 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 735508791 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 6310000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 735509359 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 735648498 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 735649422 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 735650524 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 735650881 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 6310000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 735651460 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 735654252 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 735654606 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 6310000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 735658258 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Local Settings_Application Data_Microsoft_Internet Explorer_DOMStore_index.dat_16384 Access: write Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 735736979 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Local Settings_Application Data_Microsoft_Internet Explorer_DOMStore_index.dat_16384 Access: query and write and read Type: commit Baseaddress: 5430000 Size: 16384 Protection: read write Mapped to pid: own pid | success or wait | 735737463 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 735889297 | 
| Section loaded | Path: unknown Access: query and write and read Type: commit Baseaddress: 5440000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 735896090 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Local Settings_Application Data_Microsoft_Internet Explorer_DOMStore_index.dat_32768 Access: write Type: unknown Baseaddress: unknown Size: unknown Protection: unknown Mapped to pid: unknown | object name not found | 735926375 | 
| Section loaded | Path: \BaseNamedObjects\Local\C:_Documents and Settings_Administrator_Local Settings_Application Data_Microsoft_Internet Explorer_DOMStore_index.dat_32768 Access: query and write and read Type: commit Baseaddress: 5430000 Size: 32768 Protection: read write Mapped to pid: own pid | success or wait | 735927520 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 736079010 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 736079492 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 6310000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 736080524 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 46 Value: 28 66 75 6E 63 74 69 6F 6E 28 29 7B 76 61 72 20 6A 65 3D 67 6F 6F 67 6C 65 2E 6A 2C 64 72 3D 30 2C 66 70 3D 27 62 30 36 35 39 30 39 36 37 | success or wait | 736088371 | 
| Thread resumed | TID: 3244 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 736127838 | 
| Section loaded | Path: C:\WINDOWS\system32\en-us\jscript.dll.mui Access: query and read Type: commit Baseaddress: 5440000 Size: 16384 Protection: write copy Mapped to pid: own pid | success or wait | 736146680 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 736234375 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 38 35 64 32 39 64 33 27 2C 5F 6C 6F 63 3D 27 27 2C 5F 73 73 3D 30 3B 6A 65 2E 61 63 28 7B 63 73 73 3A 27 62 6F 64 79 7B 63 6F 6C 6F 72 3A 23 30 30 30 3B 6D 61 72 67 69 6E 3A 30 3B 6F 76 65 72 66 6C 6F 77 2D 79 3A 73 63 72 6F 6C 6C 7D 62 6F 64 79 2C 23 6C 65 66 74 6E 61 76 2C 23 74 62 64 69 2C 23 68 | success or wait | 736435898 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 6C 65 3A 6E 6F 72 6D 61 6C 7D 2E 6D 73 6C 67 20 63 69 74 65 7B 64 69 73 70 6C 61 79 3A 6E 6F 6E 65 7D 2E 6E 67 7B 63 6F 6C 6F 72 3A 23 64 64 34 62 33 39 7D 68 31 2C 6F 6C 2C 75 6C 2C 6C 69 7B 6D 61 72 67 69 6E 3A 30 3B 70 61 64 64 69 6E 67 3A 30 7D 6C 69 2E 68 65 61 64 2C 6C 69 2E 67 2C 62 6F 64 79 | success or wait | 736440757 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 267 Value: 7D 68 33 2C 2E 6D 65 64 7B 66 6F 6E 74 2D 73 69 7A 65 3A 6D 65 64 69 75 6D 3B 66 6F 6E 74 2D 77 65 69 67 68 74 3A 6E 6F 72 6D 61 6C 3B 70 61 64 64 69 6E 67 3A 30 3B 6D 61 72 67 69 6E 3A 30 7D 2E 65 7B 6D 61 72 67 69 6E 3A 32 70 78 20 30 20 2E 37 35 65 6D 7D 2E 73 6C 6B 20 64 69 76 7B 70 61 64 64 69 | success or wait | 736443771 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 62 61 63 6B 67 72 6F 75 6E 64 3A 23 66 30 66 37 66 39 7D 23 62 73 66 7B 62 6F 72 64 65 72 2D 62 6F 74 74 6F 6D 3A 31 70 78 20 73 6F 6C 69 64 20 23 36 62 39 30 64 61 7D 23 63 6E 74 7B 63 6C 65 61 72 3A 62 6F 74 68 7D 23 72 65 73 7B 70 61 64 64 69 6E 67 2D 72 69 67 68 74 3A 31 65 6D 3B 6D 61 72 67 69 | success or wait | 736459851 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 64 7B 63 6F 6C 6F 72 3A 23 32 32 32 21 69 6D 70 6F 72 74 61 6E 74 3B 66 6F 6E 74 2D 77 65 69 67 68 74 3A 62 6F 6C 64 7D 61 2E 73 73 2D 75 6E 73 65 6C 65 63 74 65 64 7B 63 6F 6C 6F 72 3A 23 31 32 63 21 69 6D 70 6F 72 74 61 6E 74 7D 2E 73 73 2D 73 65 6C 65 63 74 65 64 20 2E 6D 61 72 6B 7B 64 69 73 70 | success or wait | 736463609 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 64 65 72 3A 30 3B 6D 61 72 67 69 6E 2D 6C 65 66 74 3A 30 3B 6D 61 72 67 69 6E 2D 72 69 67 68 74 3A 31 70 78 3B 76 65 72 74 69 63 61 6C 2D 61 6C 69 67 6E 3A 74 6F 70 7D 2E 73 6F 6E 7B 70 6F 73 69 74 69 6F 6E 3A 72 65 6C 61 74 69 76 65 7D 2E 73 6F 20 2E 73 6F 68 7B 62 61 63 6B 67 72 6F 75 6E 64 2D 63 | success or wait | 736468213 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 497 Value: 7B 64 69 73 70 6C 61 79 3A 6E 6F 6E 65 7D 2E 73 6E 77 7B 20 77 68 69 74 65 2D 73 70 61 63 65 3A 6E 6F 77 72 61 70 7D 64 69 76 2E 73 6F 20 2E 69 6E 6C 73 6F 7B 63 75 72 73 6F 72 3A 70 6F 69 6E 74 65 72 3B 2D 77 65 62 6B 69 74 2D 75 73 65 72 2D 73 65 6C 65 63 74 3A 20 6E 6F 6E 65 3B 2D 6B 68 74 6D 6C | success or wait | 736471116 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 36 70 78 3B 6D 61 72 67 69 6E 2D 6C 65 66 74 3A 39 70 78 3B 6D 61 72 67 69 6E 2D 72 69 67 68 74 3A 36 70 78 3B 6D 61 72 67 69 6E 2D 74 6F 70 3A 30 70 78 3B 70 61 64 64 69 6E 67 2D 72 69 67 68 74 3A 35 70 78 3B 70 6F 73 69 74 69 6F 6E 3A 61 62 73 6F 6C 75 74 65 3B 77 69 64 74 68 3A 31 36 70 78 7D 73 | success or wait | 736484232 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 64 3A 72 67 62 28 32 34 37 2C 32 34 33 2C 31 38 31 29 3B 64 69 73 70 6C 61 79 3A 6E 6F 6E 65 3B 6C 69 6E 65 2D 68 65 69 67 68 74 3A 31 2E 35 65 6D 3B 6F 75 74 6C 69 6E 65 3A 31 70 78 20 73 6F 6C 69 64 20 72 67 62 28 32 35 35 2C 31 38 35 2C 32 33 29 3B 70 61 64 64 69 6E 67 3A 36 70 78 20 34 70 78 20 | success or wait | 736486866 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 69 6E 67 3A 32 70 78 7D 2E 70 70 6C 5F 74 68 75 6D 62 5F 73 72 63 7B 63 6F 6C 6F 72 3A 23 37 36 37 36 37 36 3B 66 6F 6E 74 2D 73 69 7A 65 3A 30 2E 38 65 6D 3B 6C 69 6E 65 2D 68 65 69 67 68 74 3A 31 2E 33 65 6D 3B 6F 76 65 72 66 6C 6F 77 3A 68 69 64 64 65 6E 3B 74 65 78 74 2D 6F 76 65 72 66 6C 6F 77 | success or wait | 736489760 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 805 Value: 6F 72 61 74 69 6F 6E 3A 6E 6F 6E 65 7D 73 70 61 6E 2E 6D 61 6C 62 73 74 6C 7B 62 61 63 6B 67 72 6F 75 6E 64 3A 23 37 38 37 38 37 38 3B 63 6F 6C 6F 72 3A 23 66 66 66 7D 73 70 61 6E 2E 6D 61 6C 62 73 74 6C 3A 68 6F 76 65 72 7B 62 61 63 6B 67 72 6F 75 6E 64 3A 23 30 30 37 45 45 37 7D 73 70 61 6E 2E 6D | success or wait | 736492910 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 7B 68 65 69 67 68 74 3A 30 70 78 3B 6C 65 66 74 3A 30 70 78 3B 74 6F 70 3A 30 70 78 3B 77 69 64 74 68 3A 30 70 78 3B 7D 2E 75 68 5F 68 76 7B 62 61 63 6B 67 72 6F 75 6E 64 3A 23 66 66 66 3B 62 6F 72 64 65 72 3A 31 70 78 20 73 6F 6C 69 64 20 23 63 63 63 3B 6D 61 72 67 69 6E 3A 2D 31 30 70 78 3B 2D 6D | success or wait | 736497303 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 78 74 2D 64 65 63 6F 72 61 74 69 6F 6E 3A 6E 6F 6E 65 7D 61 3A 68 6F 76 65 72 2E 75 68 5F 68 61 6C 20 7B 74 65 78 74 2D 64 65 63 6F 72 61 74 69 6F 6E 3A 75 6E 64 65 72 6C 69 6E 65 7D 2E 73 70 65 61 6B 65 72 2D 69 63 6F 6E 2D 6C 69 73 74 65 6E 2D 6F 66 66 7B 62 61 63 6B 67 72 6F 75 6E 64 3A 75 72 6C | success or wait | 736499433 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 6C 75 74 65 3B 77 69 64 74 68 3A 31 37 70 78 3B 62 61 63 6B 67 72 6F 75 6E 64 2D 70 6F 73 69 74 69 6F 6E 3A 30 20 2D 32 31 32 70 78 3B 72 69 67 68 74 3A 2B 31 39 70 78 3B 74 6F 70 3A 2D 31 31 70 78 7D 2E 63 6F 61 64 6C 62 61 72 7B 68 65 69 67 68 74 3A 31 31 70 78 3B 70 6F 73 69 74 69 6F 6E 3A 61 62 | success or wait | 736501517 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 64 69 76 23 74 61 64 73 74 6F 20 2E 6D 62 6C 69 6E 6B 20 62 2C 64 69 76 23 74 61 64 73 62 20 61 3A 6C 69 6E 6B 2C 64 69 76 23 74 61 64 73 62 20 2E 77 2C 64 69 76 23 74 61 64 73 62 20 2E 71 3A 61 63 74 69 76 65 2C 64 69 76 23 74 61 64 73 62 20 2E 71 3A 76 69 73 69 74 65 64 2C 64 69 76 23 74 61 64 73 | success or wait | 736503660 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 732 Value: 6F 77 3A 20 68 69 64 64 65 6E 3B 74 65 78 74 2D 6F 76 65 72 66 6C 6F 77 3A 20 65 6C 6C 69 70 73 69 73 7D 2E 61 6E 73 77 65 72 5F 70 72 65 64 69 63 61 74 65 2E 6C 6F 6E 67 7B 66 6F 6E 74 2D 73 69 7A 65 3A 31 36 70 78 3B 6C 69 6E 65 2D 68 65 69 67 68 74 3A 32 30 70 78 7D 2E 61 6E 73 77 65 72 5F 73 75 | success or wait | 736507703 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 72 69 67 68 74 3A 31 70 78 3B 62 6F 72 64 65 72 2D 74 6F 70 2D 72 69 67 68 74 2D 72 61 64 69 75 73 3A 31 70 78 3B 6C 65 66 74 3A 30 3B 77 68 69 74 65 2D 73 70 61 63 65 3A 6E 6F 77 72 61 70 3B 7A 2D 69 6E 64 65 78 3A 31 7D 2E 72 67 5F 69 6C 73 20 64 69 76 2E 66 20 61 7B 63 6F 6C 6F 72 3A 23 66 66 66 | success or wait | 736513586 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 61 64 64 69 6E 67 2D 6C 65 66 74 3A 38 70 78 3B 20 70 61 64 64 69 6E 67 2D 72 69 67 68 74 3A 38 70 78 3B 20 77 69 64 74 68 3A 33 33 70 78 3B 20 7D 20 2E 6C 75 7A 61 62 20 7B 20 62 61 63 6B 67 72 6F 75 6E 64 2D 63 6F 6C 6F 72 3A 74 72 61 6E 73 70 61 72 65 6E 74 3B 20 62 6F 72 64 65 72 2D 62 6F 74 74 | success or wait | 736517736 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 2D 6C 65 66 74 3A 37 34 33 70 78 7D 2E 62 69 67 20 23 72 68 73 7B 6D 61 72 67 69 6E 2D 6C 65 66 74 3A 37 39 32 70 78 7D 62 6F 64 79 20 2E 62 69 67 20 23 73 75 62 66 6F 72 6D 5F 63 74 72 6C 7B 6D 61 72 67 69 6E 2D 6C 65 66 74 3A 32 32 39 70 78 7D 2E 72 68 73 63 66 7B 62 6F 72 64 65 72 3A 31 70 78 20 | success or wait | 736523687 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 6C 74 3B 68 65 69 67 68 74 3A 61 75 74 6F 3B 6D 61 72 67 69 6E 3A 30 3B 6D 69 6E 2D 68 65 69 67 68 74 3A 34 30 70 78 3B 70 61 64 64 69 6E 67 2D 6C 65 66 74 3A 39 70 78 3B 70 61 64 64 69 6E 67 2D 72 69 67 68 74 3A 34 70 78 3B 70 6F 73 69 74 69 6F 6E 3A 61 62 73 6F 6C 75 74 65 3B 72 69 67 68 74 3A 2D | success or wait | 736544378 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 743 Value: 70 78 20 73 6F 6C 69 64 20 74 72 61 6E 73 70 61 72 65 6E 74 3B 62 6F 72 64 65 72 2D 72 61 64 69 75 73 3A 32 70 78 3B 62 6F 72 64 65 72 2D 72 69 67 68 74 3A 6E 6F 6E 65 3B 63 75 72 73 6F 72 3A 64 65 66 61 75 6C 74 3B 75 73 65 72 2D 73 65 6C 65 63 74 3A 6E 6F 6E 65 7D 2E 76 73 68 2E 6E 79 63 5F 6F 70 | success or wait | 736551574 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 32 70 78 20 2D 32 39 30 70 78 7D 2E 76 73 74 69 74 6F 70 7B 62 61 63 6B 67 72 6F 75 6E 64 2D 70 6F 73 69 74 69 6F 6E 3A 2D 31 30 70 78 20 2D 32 39 39 70 78 7D 2E 76 73 74 61 20 2E 76 73 74 69 62 74 6D 7B 62 61 63 6B 67 72 6F 75 6E 64 2D 70 6F 73 69 74 69 6F 6E 3A 2D 32 70 78 20 2D 33 30 39 70 78 7D | success or wait | 736558479 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 6F 72 6D 61 6C 7D 6C 69 2E 77 30 20 2E 77 73 2C 74 64 2E 77 30 20 2E 77 73 7B 6F 70 61 63 69 74 79 3A 30 2E 35 7D 6C 69 2E 77 30 3A 68 6F 76 65 72 20 2E 77 73 2C 74 64 2E 77 30 3A 68 6F 76 65 72 20 2E 77 73 7B 6F 70 61 63 69 74 79 3A 31 7D 6F 6C 2C 75 6C 2C 6C 69 7B 62 6F 72 64 65 72 3A 30 3B 6D 61 | success or wait | 736620674 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 70 61 63 65 3A 6E 6F 77 72 61 70 3B 70 61 64 64 69 6E 67 2D 72 69 67 68 74 3A 31 36 70 78 3B 6D 61 72 67 69 6E 2D 74 6F 70 3A 2D 31 70 78 3B 70 61 64 64 69 6E 67 2D 62 6F 74 74 6F 6D 3A 31 70 78 7D 23 74 61 64 73 2C 23 74 61 64 73 62 2C 23 74 61 64 73 74 6F 7B 6D 61 72 67 69 6E 2D 62 6F 74 74 6F 6D | success or wait | 736625143 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 6F 6E 3A 75 6E 64 65 72 6C 69 6E 65 7D 2E 6D 69 74 65 6D 2C 23 73 68 6F 77 6D 6F 64 65 73 7B 62 6F 72 64 65 72 2D 62 6F 74 74 6F 6D 3A 31 70 78 20 73 6F 6C 69 64 20 74 72 61 6E 73 70 61 72 65 6E 74 3B 6C 69 6E 65 2D 68 65 69 67 68 74 3A 32 39 70 78 3B 6F 70 61 63 69 74 79 3A 31 2E 30 7D 2E 6D 69 74 | success or wait | 736629333 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 50 Value: 7B 6D 61 72 67 69 6E 2D 74 6F 70 3A 38 70 78 7D 23 73 65 61 73 6F 6E 5F 7B 6D 61 72 67 69 6E 2D 74 6F 70 3A 38 70 78 7D 23 69 73 7A 6C 74 5F 73 65 6C | success or wait | 736631729 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 2E 74 62 63 6F 6E 74 72 6F 6C 5F 76 69 73 7B 6D 61 72 67 69 6E 2D 6C 65 66 74 3A 30 7D 2E 74 62 70 63 2C 2E 74 62 70 6F 2C 2E 6C 63 73 6F 7B 66 6F 6E 74 2D 73 69 7A 65 3A 31 33 70 78 7D 2E 74 62 70 63 2C 2E 74 62 6F 20 2E 74 62 70 6F 7B 64 69 73 70 6C 61 79 3A 69 6E 6C 69 6E 65 7D 2E 74 62 6F 20 2E | success or wait | 736637898 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 6E 2D 77 69 64 74 68 3A 37 30 70 78 3B 70 61 64 64 69 6E 67 2D 72 69 67 68 74 3A 30 7D 2E 63 64 72 5F 65 72 72 7B 63 6F 6C 6F 72 3A 72 65 64 3B 66 6F 6E 74 2D 73 69 7A 65 3A 38 34 25 3B 66 6F 6E 74 2D 77 65 69 67 68 74 3A 6E 6F 72 6D 61 6C 7D 2E 72 68 73 73 7B 6D 61 72 67 69 6E 3A 30 20 30 20 33 32 | success or wait | 736642463 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 68 6F 76 65 72 7B 62 61 63 6B 67 72 6F 75 6E 64 2D 63 6F 6C 6F 72 3A 23 35 35 38 62 65 33 7D 23 67 75 73 65 72 20 61 2E 67 62 32 3A 68 6F 76 65 72 2C 2E 6D 69 3A 68 6F 76 65 72 2C 2E 6D 69 3A 68 6F 76 65 72 20 2A 7B 63 6F 6C 6F 72 3A 23 66 66 66 21 69 6D 70 6F 72 74 61 6E 74 7D 23 67 75 73 65 72 7B | success or wait | 736649039 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 941 Value: 6C 20 61 7B 6D 61 72 67 69 6E 3A 30 20 32 34 70 78 20 30 20 30 21 69 6D 70 6F 72 74 61 6E 74 7D 23 66 6F 6F 74 20 61 2E 73 6C 69 6E 6B 3A 76 69 73 69 74 65 64 7B 63 6F 6C 6F 72 3A 23 36 30 39 7D 23 62 6C 75 72 62 62 6F 78 5F 62 6F 74 74 6F 6D 7B 63 6F 6C 6F 72 3A 23 37 36 37 36 37 36 7D 2E 73 74 70 | success or wait | 736652331 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 2C 23 6D 62 45 6E 64 20 68 33 7B 66 6F 6E 74 2D 73 69 7A 65 3A 6D 65 64 69 75 6D 7D 2E 6E 72 74 64 20 6C 69 7B 6D 61 72 67 69 6E 3A 37 70 78 20 30 20 30 20 30 7D 2E 6F 73 6C 7B 6D 61 72 67 69 6E 2D 74 6F 70 3A 34 70 78 7D 2E 73 6C 6B 7B 6D 61 72 67 69 6E 2D 74 6F 70 3A 36 70 78 21 69 6D 70 6F 72 74 | success or wait | 736663155 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 6F 6C 6F 72 53 74 72 5C 78 33 64 5C 78 32 37 23 66 35 66 35 66 35 5C 78 32 37 2C 45 6E 64 43 6F 6C 6F 72 53 74 72 5C 78 33 64 5C 78 32 37 23 66 31 66 31 66 31 5C 78 32 37 29 7D 61 2E 6B 73 62 2C 2E 64 69 76 2E 6B 73 62 2C 61 2E 61 62 5F 62 75 74 74 6F 6E 7B 63 6F 6C 6F 72 3A 23 34 34 34 3B 74 65 78 | success or wait | 736667568 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 61 72 2D 67 72 61 64 69 65 6E 74 28 74 6F 70 2C 23 65 65 65 2C 23 65 30 65 30 65 30 29 3B 62 61 63 6B 67 72 6F 75 6E 64 2D 69 6D 61 67 65 3A 6C 69 6E 65 61 72 2D 67 72 61 64 69 65 6E 74 28 74 6F 70 2C 23 65 65 65 2C 23 65 30 65 30 65 30 29 3B 62 6F 72 64 65 72 3A 31 70 78 20 73 6F 6C 69 64 20 23 63 | success or wait | 736670826 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 6D 70 2D 74 6F 6F 6C 2D 62 6C 6F 63 6B 20 2E 6B 73 62 2C 20 23 63 6F 6D 70 2D 74 6F 6F 6C 2D 62 6C 6F 63 6B 20 2E 6B 70 72 62 7B 63 6F 6C 6F 72 3A 23 37 37 37 3B 64 69 73 70 6C 61 79 3A 69 6E 6C 69 6E 65 2D 62 6C 6F 63 6B 3B 66 6F 6E 74 2D 73 69 7A 65 3A 31 30 70 78 3B 68 65 69 67 68 74 3A 31 36 70 | success or wait | 736675311 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 882 Value: 72 64 65 72 2D 72 61 64 69 75 73 3A 31 70 78 3B 62 6F 78 2D 73 69 7A 69 6E 67 3A 62 6F 72 64 65 72 2D 62 6F 78 3B 63 75 72 73 6F 72 3A 64 65 66 61 75 6C 74 3B 64 69 73 70 6C 61 79 3A 69 6E 6C 69 6E 65 2D 62 6C 6F 63 6B 3B 70 6F 73 69 74 69 6F 6E 3A 72 65 6C 61 74 69 76 65 3B 74 65 78 74 2D 69 6E 64 | success or wait | 736678362 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 35 70 78 3B 70 6F 73 69 74 69 6F 6E 3A 61 62 73 6F 6C 75 74 65 3B 74 6F 70 3A 31 37 70 78 7D 23 61 62 5F 6E 61 6D 65 20 61 7B 63 6F 6C 6F 72 3A 23 39 39 39 7D 23 61 62 5F 63 74 6C 73 7B 70 6F 73 69 74 69 6F 6E 3A 72 65 6C 61 74 69 76 65 3B 72 69 67 68 74 3A 31 36 70 78 3B 66 6C 6F 61 74 3A 72 69 67 | success or wait | 736687796 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 69 64 20 23 34 64 39 30 66 65 3B 6F 75 74 6C 69 6E 65 3A 6E 6F 6E 65 7D 2E 61 62 5F 69 63 6F 6E 7B 62 61 63 6B 67 72 6F 75 6E 64 3A 75 72 6C 28 2F 69 6D 61 67 65 73 2F 6E 61 76 5F 6C 6F 67 6F 31 30 37 2E 70 6E 67 29 20 6E 6F 2D 72 65 70 65 61 74 3B 64 69 73 70 6C 61 79 3A 69 6E 6C 69 6E 65 2D 62 6C | success or wait | 736710740 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 70 65 61 74 3A 6E 6F 2D 72 65 70 65 61 74 7D 2E 61 62 5F 64 72 6F 70 64 6F 77 6E 69 74 65 6D 2E 64 69 73 61 62 6C 65 64 7B 63 75 72 73 6F 72 3A 64 65 66 61 75 6C 74 3B 62 6F 72 64 65 72 3A 31 70 78 20 73 6F 6C 69 64 20 23 66 33 66 33 66 33 3B 62 6F 72 64 65 72 3A 31 70 78 20 73 6F 6C 69 64 20 72 67 | success or wait | 736712847 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 70 3A 2D 32 30 70 78 7D 23 74 62 70 69 2E 70 74 7B 6D 61 72 67 69 6E 2D 74 6F 70 3A 38 70 78 7D 23 74 62 70 69 7B 6D 61 72 67 69 6E 2D 74 6F 70 3A 30 7D 23 74 62 72 74 7B 6D 61 72 67 69 6E 2D 74 6F 70 3A 2D 32 30 70 78 7D 2E 6C 6E 73 65 70 7B 62 6F 72 64 65 72 2D 62 6F 74 74 6F 6D 3A 31 70 78 20 73 | success or wait | 736715014 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 526 Value: 7B 6D 61 72 67 69 6E 2D 6C 65 66 74 3A 32 37 70 78 7D 2E 62 69 67 20 23 61 62 5F 6E 61 6D 65 7B 6D 61 72 67 69 6E 2D 6C 65 66 74 3A 34 33 70 78 7D 2E 6D 64 6D 20 23 61 62 5F 63 74 6C 73 7B 72 69 67 68 74 3A 32 38 70 78 3B 7D 2E 62 69 67 20 23 61 62 5F 63 74 6C 73 7B 72 69 67 68 74 3A 34 34 70 78 3B | success or wait | 736716457 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 7B 64 69 73 70 6C 61 79 3A 69 6E 6C 69 6E 65 7D 23 6F 62 73 6D 74 63 20 61 2C 2E 72 73 63 6F 6E 74 61 69 6E 65 72 20 61 7B 74 65 78 74 2D 64 65 63 6F 72 61 74 69 6F 6E 3A 6E 6F 6E 65 7D 23 6F 62 73 6D 74 63 20 61 3A 68 6F 76 65 72 20 2E 75 6C 2C 2E 72 73 63 6F 6E 74 61 69 6E 65 72 20 61 3A 68 6F 76 | success or wait | 736719460 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 65 7D 20 23 73 65 61 72 63 68 66 6F 72 6D 20 2E 6A 73 62 2C 23 67 62 71 66 77 20 2E 6A 73 62 7B 20 64 69 73 70 6C 61 79 3A 6E 6F 6E 65 20 7D 20 23 73 65 61 72 63 68 66 6F 72 6D 20 2E 6E 6F 6A 73 62 2C 23 67 62 71 66 77 20 2E 6E 6F 6A 73 62 7B 20 64 69 73 70 6C 61 79 3A 62 6C 6F 63 6B 20 7D 20 20 2E | success or wait | 736721584 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 69 76 20 69 64 5C 78 33 64 5C 78 32 32 73 66 6F 72 6D 5C 78 32 32 20 73 74 79 6C 65 5C 78 33 64 5C 78 32 32 68 65 69 67 68 74 3A 33 36 70 78 5C 78 32 32 5C 78 33 65 5C 78 33 63 2F 64 69 76 5C 78 33 65 5C 78 33 63 2F 64 69 76 5C 78 33 65 5C 78 33 63 64 69 76 20 69 64 5C 78 33 64 5C 78 32 32 73 72 63 | success or wait | 736723632 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 1024 Value: 65 5C 78 33 64 5C 78 32 32 70 61 64 64 69 6E 67 3A 30 20 38 70 78 5C 78 32 32 5C 78 33 65 5C 78 33 63 64 69 76 5C 78 33 65 20 5C 78 33 63 64 69 76 20 69 64 5C 78 33 64 5C 78 32 32 62 6F 74 73 74 75 66 66 5C 78 32 32 5C 78 33 65 5C 78 33 63 2F 64 69 76 5C 78 33 65 20 5C 78 33 63 2F 64 69 76 5C 78 33 | success or wait | 736726256 | 
| Process information queried | PID: 2724 Info Class: Wow64Information | success or wait | 736791947 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 736797909 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 5450000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 736798941 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 145 Value: 6C 6C 5C 78 32 32 20 73 74 79 6C 65 5C 78 33 64 5C 78 32 32 6D 61 72 67 69 6E 3A 31 39 70 78 20 61 75 74 6F 3B 74 65 78 74 2D 61 6C 69 67 6E 3A 63 65 6E 74 65 72 5C 78 32 32 5C 78 33 65 5C 78 33 63 61 20 68 72 65 66 5C 78 33 64 5C 78 32 32 2F 5C 78 32 32 5C 78 33 65 41 63 63 75 65 69 6C 5C 78 32 36 | success or wait | 736802504 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\b0659096785d29d3[1].js Offset: unknown Length: 924 Value: 6E 74 6C 2F 66 72 2F 61 64 73 2F 5C 78 32 32 5C 78 33 65 53 6F 6C 75 74 69 6F 6E 73 20 70 75 62 6C 69 63 69 74 61 69 72 65 73 5C 78 33 63 2F 61 5C 78 33 65 E2 80 8E 20 5C 78 33 63 61 20 68 72 65 66 5C 78 33 64 5C 78 32 32 2F 73 65 72 76 69 63 65 73 2F 5C 78 32 32 5C 78 33 65 53 6F 6C 75 74 69 6F 6E | success or wait | 736806462 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\j_e6a6aca6[1].png Offset: unknown Length: 6932 Value: 89 50 4E 47 0D 0A 1A 0A 00 00 00 0D 49 48 44 52 00 00 01 7D 00 00 00 2D 08 06 00 00 00 42 80 BB 12 00 00 00 06 62 4B 47 44 00 FF 00 FF 00 FF A0 BD A7 93 00 00 00 09 70 48 59 73 00 00 00 48 00 00 00 48 00 46 C9 6B 3E 00 00 00 09 76 70 41 67 00 00 01 7D 00 00 00 2D 00 24 33 F2 4D 00 00 3A A5 49 44 41 | success or wait | 736824896 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 736843027 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 5450000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 736844056 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\3FZRZ9KZ\tia[1].png Offset: unknown Length: 387 Value: 89 50 4E 47 0D 0A 1A 0A 00 00 00 0D 49 48 44 52 00 00 00 1B 00 00 00 17 08 02 00 00 00 75 74 A3 79 00 00 00 01 73 52 47 42 00 AE CE 1C E9 00 00 00 04 67 41 4D 41 00 00 B1 8F 0B FC 61 05 00 00 00 20 63 48 52 4D 00 00 7A 26 00 00 80 84 00 00 FA 00 00 00 80 E8 00 00 75 30 00 00 EA 60 00 00 3A 98 00 00 | success or wait | 736867232 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\j_e6a6aca6[1].png Offset: unknown Length: 1260 Value: 79 D0 A0 41 23 10 90 FB 21 78 F7 BC 7A F5 6A 2A 82 34 9E B8 12 8F AD 7B 31 FB C0 E9 98 71 EE FA 8E 48 DB 93 33 6D 71 28 A4 54 73 BD 0D 72 06 2F 8E A4 89 46 EA 27 6E DF 64 6C FF 00 37 37 B7 59 A3 47 8F EE 77 F8 F0 E1 6E 4F 9F 3E FD 0D 35 34 53 D1 3B 20 DA 53 F1 14 36 28 E4 AC 60 AC E6 48 B5 44 73 EA | success or wait | 737020275 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\j_e6a6aca6[1].png Offset: unknown Length: 5408 Value: 36 E1 6F A1 55 63 D7 64 F1 0A 45 F8 6B 20 2D A5 39 17 54 D5 41 DD 2E F0 B7 34 DC EB 45 C0 40 6F 89 F6 A4 F5 2D 27 A3 C8 52 E4 06 5C 58 A5 E2 FE A0 41 D5 FF 05 E8 25 96 3D 0E FB 3D 77 68 BB 69 85 DD FD 7F AF 38 CD 0A 2D 28 51 B3 9B 10 4A D6 7D 75 D1 C6 49 00 FD BF 11 F4 FB 20 E8 07 BF 83 FE 85 08 37 | success or wait | 737116732 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\5B7NHQO2\j_e6a6aca6[1].png Offset: unknown Length: 1530 Value: 44 7E 1E 2B E8 CE DF EA DE 47 46 AA BB 6E EC CC B0 9E 16 45 37 1F DB 8E E9 92 75 88 EA 72 17 54 FC 5E 82 46 54 31 B2 FC 8B 40 2B F4 E4 30 11 F0 FF 7F 12 3C D2 25 25 AA 74 42 7C 04 83 F0 DC D5 C8 FB 81 1B 3C 13 52 85 9F D7 13 CD BB D3 A4 08 BF A7 80 C3 DD B2 B2 B2 26 7D 8D C6 01 E7 35 C7 F9 CD 71 12 | success or wait | 737131434 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 737150429 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 5450000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 737151466 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\swxa[1].gif Offset: unknown Length: 2103 Value: 47 49 46 38 39 61 78 00 41 00 A2 00 00 FF FF FF F1 F1 F1 E2 E2 E2 D2 D2 D2 FE 01 02 00 00 00 00 00 00 00 00 00 21 F9 04 04 01 00 FF 00 2C 00 00 00 00 78 00 41 00 00 03 65 08 BA DC FE 30 CA 49 AB BD 38 EB CD BB FF 60 28 8E 64 69 9E 68 AA AE 6C EB BE 70 2C CF 74 6D DF 78 AE EF 7C EF FF C0 A0 70 48 2C | success or wait | 737166859 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\swxa[1].gif Offset: unknown Length: 1977 Value: AC 21 51 13 93 A1 25 0B BD 70 BE A8 A0 8C B9 91 8A 3E 8E 87 87 B5 A9 CC 94 CE A8 6F 90 5F 9D C9 3A 86 B0 14 BD 26 78 76 DF C4 2D A4 5D C7 D8 60 DA D2 E3 79 E1 E0 EA B1 00 03 7B AC E7 C8 A4 A7 D3 CB F6 A6 E8 69 03 A3 F5 94 58 D1 26 6E CB 98 1B FF FA 95 48 38 CF 8D 9F 42 A0 F0 A5 C1 A5 22 92 82 4A 0A | success or wait | 737191169 | 
| Process information queried | PID: 1728 Info Class: BasicInformation | success or wait | 737416586 | 
| Section loaded | Path: \BaseNamedObjects\MSCTF.Shared.SFM.EJL Access: query and write and read Type: reserve Baseaddress: 5840000 Size: 524288 Protection: read write Mapped to pid: own pid | success or wait | 737417830 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 737494029 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 737496680 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 737500816 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 6510000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 737502430 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 737516151 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 6510000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 737518101 | 
| Process information queried | PID: 1728 Info Class: BasicInformation | success or wait | 737540509 | 
| File write | Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\L1ZDGPDD\swxa[1].gif Offset: unknown Length: 1143 Value: 91 00 00 21 F9 04 05 0A 00 04 00 2C 1C 00 13 00 36 00 1E 00 00 03 DA 08 BA DC FE 30 CA D9 82 B8 81 61 CA 3B B0 C3 25 84 41 10 8E 83 A7 3E 66 A6 0D 83 0B 5C 6B FD C5 AC 7C DB 2B DD 91 1E DD 4F 75 09 51 50 B8 8E 69 55 12 08 67 A2 D6 4E 99 E2 80 42 30 E3 0D 0B 54 A0 9E 16 C1 62 79 D4 8E 61 23 99 94 41 | success or wait | 737814046 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 738015318 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 738067342 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 738104033 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 738137032 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 738236857 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 738277565 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739061706 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739120220 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739158695 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739191306 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739232536 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739267504 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739302510 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739347806 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739363715 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739378958 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739393831 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739406892 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739418300 | 
| Process information queried | PID: 2724 Info Class: DeviceMap | success or wait | 739427753 | 
| Section loaded | Path: unknown Access: query and write and read Type: commit Baseaddress: 58D0000 Size: 4096 Protection: read write Mapped to pid: own pid | success or wait | 739428130 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 739435916 | 
| Process information queried | PID: 2724 Info Class: SessionInformation | success or wait | 739489642 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739546171 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739559054 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739570846 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739623828 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739886754 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739904984 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739920863 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739934962 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739946334 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739962495 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739974554 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 739986318 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 740001839 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 740015373 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 740030233 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 740045100 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 740058201 | 
| Section loaded | Path: C:\WINDOWS\system32\mshtml.tlb Access: query and read Type: commit Baseaddress: 6510000 Size: 1642496 Protection: readonly Mapped to pid: own pid | success or wait | 740069482 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 772433714 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 772436395 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 772440668 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 6510000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 772442285 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 772459249 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 6510000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 772461104 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 772476099 | 
| Key value queried | Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer Name: Version | success or wait | 772478716 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 772482780 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 6510000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 772484629 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 772532049 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 6510000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 772533868 | 
| Thread created | PID: 2724 TID: 3796 EIP: 7C8106F9 Imagepath: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 774052094 | 
| Thread resumed | TID: 3796 PID: 2724 Path: C:\Program Files\Internet Explorer\iexplore.exe | success or wait | 774067975 | 
| File opened | Path: \pipe\globpluginspipe Access: read attributes and synchronize and generic read Options: synchronous io non alert and non directory file Attributes: none Content Overwritten: null | success or wait | 774073034 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 4 Value: 59 50 00 00 | success or wait | 774075633 | 
| File read | Path: \globpluginspipe Offset: unknown Length: 20569 Value: 67 6C 6F 62 70 6C 75 67 69 6E 73 00 04 00 00 00 63 63 67 72 61 62 62 65 72 00 00 50 00 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 | success or wait | 774079671 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 798927754 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 6510000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 798928836 | 
| File opened | Path: C:\WINDOWS\system32\wininet.dll Access: synchronize and generic read Options: synchronous io non alert and non directory file and random access Overwritten: false | success or wait | 799240542 | 
| Section loaded | Path: C:\WINDOWS\system32\wininet.dll Access: query and write and read and execute and extend size Type: image Baseaddress: 6510000 Size: 942080 Protection: readonly Mapped to pid: own pid | image not at base | 799241676 |