Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager Name: CWDIllegalInDLLSearch |
object name not found |
614796698 |
System info queried |
Type: BasicInformation |
success or wait |
614798311 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 140000
Length: 12FB14 Allocation Type: unknown Protection: page read and write
|
success or wait |
614798574 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 140000
Length: 12FB18 Allocation Type: unknown Protection: page read and write
|
success or wait |
614798780 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 141000
Length: 12F7F4 Allocation Type: unknown Protection: page read and write
|
success or wait |
614799182 |
System info queried |
Type: BasicInformation |
success or wait |
614799431 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 240000
Length: 12FB14 Allocation Type: unknown Protection: page read and write
|
success or wait |
614799633 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 240000
Length: 12FB18 Allocation Type: unknown Protection: page read and write
|
success or wait |
614799827 |
File opened |
Path: C:\Program Files\AutoIt3 Access: execute or traverse and synchronize Options:
directory file and synchronous io non alert Overwritten: false
|
success or wait |
614800723 |
File control set |
Path: C:\Program Files\AutoIt3 Control Code: 90028 Input Buffer: |
success or wait |
614801565 |
Section loaded |
Path: \KnownDlls\kernel32.dll Access: write and read and execute Type: unknown Baseaddress:
7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid
|
success or wait |
614802521 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C801000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614803756 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C801000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614804990 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
614806018 |
System info queried |
Type: RangeStartInformation |
success or wait |
614806265 |
System info queried |
Type: BasicInformation |
success or wait |
614806447 |
Section loaded |
Path: unknown Access: query and write and read and execute and extend size Type: reserve
Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid
|
success or wait |
614806694 |
System info queried |
Type: BasicInformation |
success or wait |
614807655 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 250000
Length: 12F340 Allocation Type: unknown Protection: page read and write
|
success or wait |
614808116 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server Name: TSAppCompat |
success or wait |
614810438 |
Section loaded |
Path: \NLS\NlsSectionUnicode Access: read Type: unknown Baseaddress: 260000 Size:
90112 Protection: readonly Mapped to pid: own pid
|
success or wait |
614811459 |
Section loaded |
Path: \NLS\NlsSectionLocale Access: read Type: unknown Baseaddress: 280000 Size: 266240
Protection: readonly Mapped to pid: own pid
|
success or wait |
614812817 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 143000
Length: 12F21C Allocation Type: unknown Protection: page read and write
|
success or wait |
614813827 |
Section loaded |
Path: \NLS\NlsSectionSortkey Access: query and read Type: unknown Baseaddress: 2D0000
Size: 266240 Protection: readonly Mapped to pid: own pid
|
success or wait |
614814143 |
Section loaded |
Path: \NLS\NlsSectionSortTbls Access: read Type: unknown Baseaddress: 320000 Size:
24576 Protection: readonly Mapped to pid: own pid
|
success or wait |
614814837 |
Section loaded |
Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: unknown
Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
614816353 |
Section loaded |
Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: unknown
Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
614816596 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 251000
Length: 12F168 Allocation Type: unknown Protection: page read and write
|
success or wait |
614816815 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE.2.Manifest Access: read
data or list directory and read ea and execute or traverse and read attributes and
read control and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
object name not found |
614819032 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE.2.Config Access: read
data or list directory and read ea and execute or traverse and read attributes and
read control and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
object name not found |
614820975 |
Section loaded |
Path: \KnownDlls\ADVAPI32.dll Access: write and read and execute Type: unknown Baseaddress:
77DD0000 Size: 634880 Protection: read write Mapped to pid: own pid
|
success or wait |
614851330 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77DD1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614852826 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77DD1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614853432 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77DD1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614853733 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77DD1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614854180 |
Section loaded |
Path: \KnownDlls\RPCRT4.dll Access: write and read and execute Type: unknown Baseaddress:
77E70000 Size: 602112 Protection: read write Mapped to pid: own pid
|
success or wait |
614854466 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77E71000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614855761 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77E71000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614856435 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77E71000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614856694 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77E71000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614857052 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77E71000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614857310 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77E71000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614857580 |
Section loaded |
Path: \KnownDlls\Secur32.dll Access: write and read and execute Type: unknown Baseaddress:
77FE0000 Size: 69632 Protection: read write Mapped to pid: own pid
|
success or wait |
614857873 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77FE1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614859148 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77FE1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614859495 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77FE1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614859857 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77FE1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614860140 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77FE1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614860410 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77FE1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614860754 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77E71000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614861004 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77E71000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614861254 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77DD1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614861495 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77DD1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614861999 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614862226 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614862606 |
Section loaded |
Path: \KnownDlls\GDI32.dll Access: write and read and execute Type: unknown Baseaddress:
77F10000 Size: 299008 Protection: read write Mapped to pid: own pid
|
success or wait |
614862801 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F11000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614864017 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F11000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614864432 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F11000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614864678 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F11000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614864928 |
Section loaded |
Path: \KnownDlls\USER32.dll Access: write and read and execute Type: unknown Baseaddress:
7E410000 Size: 593920 Protection: read write Mapped to pid: own pid
|
success or wait |
614865207 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7E411000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614866472 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7E411000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614867274 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7E411000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614867534 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7E411000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614867836 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7E411000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614868091 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7E411000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614868456 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F11000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614868696 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F11000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614869316 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614869580 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614869882 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614870114 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614870529 |
Section loaded |
Path: \KnownDlls\ole32.dll Access: write and read and execute Type: unknown Baseaddress:
774E0000 Size: 1302528 Protection: read write Mapped to pid: own pid
|
success or wait |
614870793 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614872068 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614872465 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614872709 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614872959 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614873201 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614873614 |
Section loaded |
Path: \KnownDlls\msvcrt.dll Access: write and read and execute Type: unknown Baseaddress:
77C10000 Size: 360448 Protection: read write Mapped to pid: own pid
|
success or wait |
614874415 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77C11000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614875652 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77C11000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614876103 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77C11000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614876363 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77C11000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614876613 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614876852 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614877350 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614877591 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614877837 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614878079 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614878422 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614878663 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 774E1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614879017 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614879244 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614879760 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614879990 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614880359 |
Section loaded |
Path: \KnownDlls\VERSION.dll Access: write and read and execute Type: unknown Baseaddress:
77C00000 Size: 32768 Protection: read write Mapped to pid: own pid
|
success or wait |
614880673 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77C01000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614881832 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77C01000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614882235 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77C01000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614882481 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77C01000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614882733 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614882963 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614883190 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614883421 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30001000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614883677 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 144000
Length: 12F894 Allocation Type: unknown Protection: page read and write
|
success or wait |
614884335 |
Process information queried |
PID: 1160 Info Class: ImageInformation |
success or wait |
614886561 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server Name: TSAppCompat |
success or wait |
614887165 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server Name: TSAppCompat |
success or wait |
614890012 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server Name: TSUserEnabled |
success or wait |
614890595 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Name:
LeakTrack
|
object name not found |
614891492 |
System info queried |
Type: BasicInformation |
success or wait |
614892393 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager Name: SafeDllSearchMode |
object name not found |
614893527 |
File opened |
Path: C:\WINDOWS\system32\IMM32.DLL Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
614894394 |
Section loaded |
Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit
Baseaddress: 410000 Size: 110592 Protection: execute Mapped to pid: own pid
|
success or wait |
614895155 |
File opened |
Path: C:\WINDOWS\system32\IMM32.DLL Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
614897012 |
Section loaded |
Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit
Baseaddress: 410000 Size: 110592 Protection: execute Mapped to pid: own pid
|
success or wait |
614897760 |
File opened |
Path: C:\WINDOWS\system32\IMM32.DLL Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
614899352 |
Section loaded |
Path: C:\WINDOWS\system32\imm32.dll Access: query and write and read and execute Type:
image Baseaddress: 76390000 Size: 118784 Protection: read write Mapped to pid: own
pid
|
success or wait |
614900320 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Name: TransparentEnabled
|
success or wait |
614900831 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76391000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614902895 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76391000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614903289 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76391000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614903548 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76391000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614903868 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76391000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614904128 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76391000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614904412 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76391000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614904669 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76391000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614904933 |
System info queried |
Type: BasicInformation |
success or wait |
614905477 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
Name: DisableMetaFiles
|
object name not found |
614906623 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Name:
AppInit_DLLs
|
success or wait |
614909746 |
System info queried |
Type: BasicInformation |
success or wait |
614911456 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 840000
Length: 12F91C Allocation Type: unknown Protection: page read and write
|
success or wait |
614911672 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 840000
Length: 12F920 Allocation Type: unknown Protection: page read and write
|
success or wait |
614911881 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 841000
Length: 12F5FC Allocation Type: unknown Protection: page read and write
|
success or wait |
614912155 |
Section loaded |
Path: \NLS\NlsSectionCType Access: read Type: unknown Baseaddress: 850000 Size: 12288
Protection: readonly Mapped to pid: own pid
|
success or wait |
614913061 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 843000
Length: 12F6B8 Allocation Type: unknown Protection: page read and write
|
success or wait |
614914799 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
614915997 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
614916200 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 166000
Length: 12F5BC Allocation Type: unknown Protection: page read and write
|
success or wait |
614916699 |
File opened |
Path: \Device\KsecDD Access: read data or list directory and synchronize Options:
synchronous io alert Overwritten: false
|
success or wait |
614917598 |
System info queried |
Type: BasicInformation |
success or wait |
614920534 |
System info queried |
Type: ProcessorInformation |
success or wait |
614920738 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager Name: CriticalSectionTimeout |
success or wait |
614921119 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole Name: RWLockResourceTimeOut |
object name not found |
614921735 |
System info queried |
Type: BasicInformation |
success or wait |
614922225 |
System info queried |
Type: ProcessorInformation |
success or wait |
614922430 |
System info queried |
Type: BasicInformation |
success or wait |
614922620 |
System info queried |
Type: ProcessorInformation |
success or wait |
614922825 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface Name: InterfaceHelperDisableAll |
object name not found |
614923116 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface Name: InterfaceHelperDisableAllForOle32 |
object name not found |
614923334 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface Name: InterfaceHelperDisableTypeLib |
object name not found |
614923548 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00020400-0000-0000-C000-000000000046}
Name: InterfaceHelperDisableAll
|
object name not found |
614924060 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00020400-0000-0000-C000-000000000046}
Name: InterfaceHelperDisableAllForOle32
|
object name not found |
614924273 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30B81000
Length: 1000 New Protection: page readonly New Protection: page read and write
|
success or wait |
614924961 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion Name: CommonFilesDir |
success or wait |
614925676 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll Access: execute
or traverse and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
success or wait |
614926371 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Access: write
and read and execute Type: commit Baseaddress: 860000 Size: 12259328 Protection: execute
Mapped to pid: own pid
|
success or wait |
614927266 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll Access: execute
or traverse and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
success or wait |
614929120 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Access: query
and write and read and execute Type: image Baseaddress: 30C90000 Size: 12304384 Protection:
read write Mapped to pid: own pid
|
success or wait |
614929938 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll.2.Manifest
Access: read data or list directory and read ea and execute or traverse and read attributes
and read control and synchronize Options: synchronous io non alert and non directory
file Overwritten: false
|
object name not found |
614932084 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll.2.Config Access:
read data or list directory and read ea and execute or traverse and read attributes
and read control and synchronize Options: synchronous io non alert and non directory
file Overwritten: false
|
object name not found |
614932992 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614963166 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614963625 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614963991 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614964405 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614964700 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614965259 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614965500 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614965834 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614966074 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614966471 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614966708 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614966952 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
614967186 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 30C91000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
614967449 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\mso.dll Name: CheckAppHelp
|
success or wait |
614968119 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\AppCompatibility
Name: DisableAppCompat
|
object name not found |
614969402 |
Section loaded |
Path: \BaseNamedObjects\ShimSharedMemory Access: write Type: unknown Baseaddress:
870000 Size: 57344 Protection: read write Mapped to pid: own pid
|
success or wait |
614969924 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 167000
Length: 12ED44 Allocation Type: unknown Protection: page read and write
|
success or wait |
615117357 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 3165E000
Length: 1000 New Protection: page readonly New Protection: page read and write
|
success or wait |
615118065 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
615118930 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
615119375 |
File opened |
Path: C:\Program Files\ Access: read data or list directory and synchronize Options:
directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
615120694 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
615121995 |
Mutant created |
Name: \BaseNamedObjects\Local\Mutex_MSOSharedMem |
success or wait |
615123264 |
System info queried |
Type: BasicInformation |
success or wait |
615125093 |
System info queried |
Type: ProcessorInformation |
success or wait |
615125286 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
615129148 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
615129327 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 880000
Length: 12F8B8 Allocation Type: unknown Protection: page no access
|
success or wait |
615132172 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 880000
Length: 12F8B8 Allocation Type: unknown Protection: page read and write
|
success or wait |
615132379 |
Key created |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency |
success or wait |
615135776 |
Key created |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems |
success or wait |
615139106 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems Name:
y
|
object name not found |
615139868 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems Name:
y Type: binary Data: 79 13 02 00 88 04 00 00 01 00 00 00 00 00 00 00 00 00 00 00
Old data:
|
success or wait |
615140327 |
Foreground Window Got |
HWND: 1008C |
success |
615140927 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
615141179 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
615141371 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\General Name: InstalledOnWin2k |
success or wait |
615142969 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: UserData |
success or wait |
615143410 |
Process information queried |
PID: 1160 Info Class: Times |
success or wait |
615143708 |
Process information queried |
PID: 1160 Info Class: Times |
success or wait |
615143894 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common Name: QMStrMax |
object name not found |
615144252 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 890000
Length: 12F8CC Allocation Type: unknown Protection: page no access
|
success or wait |
615144624 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 890000
Length: 12F8CC Allocation Type: unknown Protection: page read and write
|
success or wait |
615144822 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: QMStudyID |
object name not found |
615145249 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 891000
Length: 12F85C Allocation Type: unknown Protection: page read and write
|
success or wait |
615145558 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8A0000
Length: 12F888 Allocation Type: unknown Protection: page no access
|
success or wait |
615145807 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8A0000
Length: 12F888 Allocation Type: unknown Protection: page read and write
|
success or wait |
615146000 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B0000
Length: 12F810 Allocation Type: unknown Protection: page no access
|
success or wait |
615146214 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B0000
Length: 12F810 Allocation Type: unknown Protection: page read and write
|
success or wait |
615146407 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: UserData |
success or wait |
615147145 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\LanguageResources Name:
SKULanguage
|
success or wait |
615147686 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: InstallLanguage |
success or wait |
615148355 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: UILanguage |
success or wait |
615148678 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: HelpLanguage |
success or wait |
615149011 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: ExeMode |
object name not found |
615149328 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: WinXPLanguagePatch |
success or wait |
615149652 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: PreviousInstallLanguage |
success or wait |
615151384 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: WebLocale |
success or wait |
615151705 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: LangTuneUp |
success or wait |
615152098 |
Key value replaced with new |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: 2055
Type: unicode Data: On Old data: Off
|
success or wait |
615154284 |
Key value replaced with new |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: 2055
Type: unicode Data: Off Old data: On
|
success or wait |
615157921 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Name: OfficeUILanguage |
success or wait |
615158597 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Name: OfficeUILanguage |
success or wait |
615158959 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: InstallFonts |
object name not found |
615159294 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\1033\wwintl.dll Access: execute
or traverse and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
success or wait |
615160069 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\1033\WWINTL.DLL Access: write and
read and execute Type: commit Baseaddress: 8C0000 Size: 778240 Protection: execute
Mapped to pid: own pid
|
success or wait |
615160921 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\1033\wwintl.dll Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file Attributes: none Content Overwritten: null
|
success or wait |
615162670 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\1033\WWINTL.DLL Access: query and
read Type: commit Baseaddress: 8C0000 Size: 778240 Protection: readonly Mapped to
pid: own pid
|
success or wait |
615163496 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\LanguageResources Name: UILanguage |
success or wait |
615169219 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale Name: 00000401 |
success or wait |
615170752 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale Name: 0000040D |
success or wait |
615171275 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale Name: 0000041E |
success or wait |
615171851 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale Name: 0000042A |
success or wait |
615172376 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 168000
Length: 12F074 Allocation Type: unknown Protection: page read and write
|
success or wait |
615172904 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale Name: 00000439 |
success or wait |
615173182 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale Name: 00000420 |
success or wait |
615173812 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale Name: 00000429 |
success or wait |
615174334 |
Key created |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Migration\Word |
success or wait |
615176672 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 980000
Length: 12F45C Allocation Type: unknown Protection: page read and write
|
success or wait |
615180049 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 980000
Length: 12F458 Allocation Type: unknown Protection: page read and write
|
success or wait |
615180268 |
System info queried |
Type: PerformanceInformation |
success or wait |
615180520 |
Process information queried |
PID: 1160 Info Class: QuotaLimits |
success or wait |
615180950 |
Process information queried |
PID: 1160 Info Class: VmCounters |
success or wait |
615181155 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9A0000
Length: 12F164 Allocation Type: unknown Protection: page no access
|
success or wait |
615181490 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9A0000
Length: 12F164 Allocation Type: unknown Protection: page read and write
|
success or wait |
615181681 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: ASKFORPRINTERPICTURE |
object name not found |
615188169 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B1000
Length: 12F114 Allocation Type: unknown Protection: page read and write
|
success or wait |
615188641 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B2000
Length: 12F0DC Allocation Type: unknown Protection: page read and write
|
success or wait |
615188990 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B3000
Length: 12F084 Allocation Type: unknown Protection: page read and write
|
success or wait |
615189439 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B4000
Length: 12F0C4 Allocation Type: unknown Protection: page read and write
|
success or wait |
615189835 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9B0000
Length: 12F110 Allocation Type: unknown Protection: page no access
|
success or wait |
615190228 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9B0000
Length: 12F110 Allocation Type: unknown Protection: page read and write
|
success or wait |
615190425 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9C0000
Length: 12F114 Allocation Type: unknown Protection: page no access
|
success or wait |
615190893 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9C0000
Length: 12F114 Allocation Type: unknown Protection: page read and write
|
success or wait |
615191087 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: CACHESIZE |
object name not found |
615191425 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9D0000
Length: 12F258 Allocation Type: unknown Protection: page no access
|
success or wait |
615191725 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9D0000
Length: 12F258 Allocation Type: unknown Protection: page read and write
|
success or wait |
615191919 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9C1000
Length: 12F0F8 Allocation Type: unknown Protection: page read and write
|
success or wait |
615192169 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9F0000
Length: 12F258 Allocation Type: unknown Protection: page no access
|
success or wait |
615192416 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9F0000
Length: 12F258 Allocation Type: unknown Protection: page read and write
|
success or wait |
615192607 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9C2000
Length: 12F208 Allocation Type: unknown Protection: page read and write
|
success or wait |
615193137 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 9C3000
Length: 12EC38 Allocation Type: unknown Protection: page read and write
|
success or wait |
615193852 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B5000
Length: 12EC98 Allocation Type: unknown Protection: page read and write
|
success or wait |
615194140 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: UserTemplates |
object name not found |
615195972 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Name: AppData
|
success or wait |
615196842 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: Templates |
success or wait |
615197451 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
615198585 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: A00000
Length: 12B1A0 Allocation Type: unknown Protection: page no access
|
success or wait |
615198982 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: A00000
Length: 12B1A0 Allocation Type: unknown Protection: page read and write
|
success or wait |
615199180 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 8B6000
Length: 127988 Allocation Type: unknown Protection: page read and write
|
success or wait |
615201574 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 881000
Length: 12C8D8 Allocation Type: unknown Protection: page read and write
|
success or wait |
615202069 |
Memory allocated |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: A00000
Length: 12C870 Allocation Type: unknown Protection: page no access
|
success or wait |
615202434 |
System info queried |
Type: BasicInformation |
success or wait |
615219388 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc Name: MaxRpcSize |
object name not found |
615219888 |
System time queried |
Time: 129876420050625000 |
success or wait |
615220604 |
System info queried |
Type: PerformanceInformation |
success or wait |
615221023 |
Process information queried |
PID: 1160 Info Class: QuotaLimits |
success or wait |
615221478 |
Process information queried |
PID: 1160 Info Class: VmCounters |
success or wait |
615221691 |
Section loaded |
Path: \BaseNamedObjects\Local\Mso97SharedDg19211108172 Access: query and write and
read and execute and extend size Type: unknown Baseaddress: unknown Size: unknown
Protection: unknown Mapped to pid: unknown
|
object name not found |
615222769 |
Section loaded |
Path: \BaseNamedObjects\Local\Mso97SharedDg19211108172 Access: query and write and
read Type: reserve Baseaddress: A10000 Size: 126976 Protection: read write Mapped
to pid: own pid
|
success or wait |
615223004 |
Mutant created |
Name: \BaseNamedObjects\Local\Mso97SharedDg19211108172Mutex |
success or wait |
615223775 |
Section loaded |
Path: \KnownDlls\uxtheme.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
615225083 |
File opened |
Path: C:\WINDOWS\system32\uxtheme.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
615225757 |
Section loaded |
Path: C:\WINDOWS\system32\uxtheme.dll Access: query and write and read and execute
Type: image Baseaddress: 5AD70000 Size: 229376 Protection: read write Mapped to pid:
own pid
|
success or wait |
615226535 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5AD71000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615228343 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5AD71000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615228752 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5AD71000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615229065 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5AD71000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615229403 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5AD71000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615229663 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5AD71000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615229970 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5AD71000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615230277 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5AD71000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615230535 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5AD71000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615230792 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5AD71000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615231050 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\ThemeManager Name: Compositing |
object name not found |
615232328 |
Key value queried |
Path: HKEY_USERS\Control Panel\Desktop Name: LameButtonText |
object name not found |
615233605 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Internet Explorer\Settings Name: Anchor Color |
success or wait |
615236365 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Internet Explorer\Settings Name: Anchor Color
Visited
|
success or wait |
615236693 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoClearTypeNW |
object name not found |
615237171 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: FontInfoCache |
object name not found |
615238043 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: UseOfficeUIFont |
object name not found |
615238578 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: FontInfoCache |
object name not found |
615241912 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: FontInfoCache Type: binary
Data: 60 00 00 00 60 00 00 00 F5 FF FF FF 00 00 00 00 00 00 00 00 00 00 00 00 BC 02
00 00 00 00 00 00 00 40 00 22 54 00 61 00 68 00 6F 00 6D 00 61 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 54 00 61 00 68 00 6F 00 6D 00
61 00 00 00 12 00 20 E9 90 7C 10 00 00 00 00 F1 12 00 08 F1 12 00 00 00 00 00 E4 F0
12 00 D6 20 91 7C 54 F2 12 00 0E 00 00 00 F0 F0 12 00 24 F1 12 00 1C 00 00 00 54 F2
12 00 9C 00 00 00 00 00 00 00 00 00 00 00 30 F2 12 00 3A 2C 81 7C 08 F1 12 00 0E 00
00 00 00 00 00 00 D4 F2 12 00 4D 2C 81 7C 1C 00 1E 00 24 F1 12 00 0E 00 80 00 54 F2
12 00 1C 01 00 00 05 00 00 00 01 00 00 00 28 0A 00 00 02 00 00 00 53 00 65 00 72 00
76 00 69 00 63 00 65 00 20 00 50 00 61 00 63 00 6B 00 20 00 33 00 00 00 12 00 5C F6
90 7C 61 F6 90 7C B4 F1 12 00 6E D9 90 7C 74 F2 12 00 4C F1 12 00 7A D9 90 7C 08 50
41 7E 32 F2 12 00 00 39 41 7E D0 00 00 00 C0 F1 12 00 3B 7D 91 7C 32 F2 12 00 DC 02
00 00 00 00 41 7E 98 44 41 7E 08 50 41 7E 00 00 00 00 01 00 00 00 30 F2 12 00 00 00
00 00 01 00 00 00 00 00 41 7E D8 00 41 7E 98 F1 12 00 01 00 00 00 D0 F1 12 00 85 03
91 7C 00 00 41 7E 00 00 00 00 8C F2 12 00 02 7C 91 7C 00 00 41 7E 32 F2 12 00 2C F2
12 00 2C F2 12 00 32 F2 12 00 A7 7C 91 7C 74 E1 97 7C 51 7C 91 7C 74 DD 00 30 40 AE
80 7C FF FF 00 00 00 F0 FD 7F 7A CF 90 7C 42 9B 80 7C FF FF FF FF 50 F2 12 00 00 00
00 00 54 F2 12 00 00 10 00 00 59 9B 80 7C 04 00 00 00 00 20 00 00 00 10 00 00 00 00
00 00 E8 22 24 00 18 F2 12 00 00 00 45 6E B0 FF 12 00 D8 9A 83 7C 60 9B 80 7C FF FF
FF FF 59 9B 80 7C 09 9B 80 7C FF FF FF FF 00 10 9A 00 00 10 00 00 00 10 00 00 04 00
00 00 00 00 9A 00 D2 B9 CB 30 00 10 9A 00 00 10 00 00 F4 B9 CB 30 28 2F 62 31 40 02
00 00 00 00 9A 00 03 20 00 00 00 10 00 00 CE B8 CB 30 03 00 00 00 FD 3F 00 00 0D 00
00 00 0B 00 00 00 02 00 00 00 02 00 00 00 00 00 00 00 06 00 00 00 1A 00 00 00 BC 02
00 00 00 00 00 00 60 00 00 00 60 00 00 00 1E FF 1F 20 00 00 00 27 00 00 01 01 87 7A
00 61 00 00 00 80 08 00 00 00 00 00 00 00 01 00 00 00 00 00 28 20 07 00 00 00 F5 FF
FF FF 00 00 00 00 00 00 00 00 00 00 00 00 90 01 00 00 00 00 00 00 00 40 00 22 54 00
61 00 68 00 6F 00 6D 00 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 54 00 61 00 68 00 6F 00 6D 00 61 00 00 00 12 00 20 E9 90 7C 10 00
00 00 00 F1 12 00 08 F1 12 00 00 00 00 00 E4 F0 12 00 D6 20 91 7C 54 F2 12 00 0E 00
00 00 F0 F0 12 00 24 F1 12 00 1C 00 00 00 54 F2 12 00 9C 00 00 00 00 00 00 00 00 00
00 00 30 F2 12 00 3A 2C 81 7C 08 F1 12 00 0E 00 00 00 00 00 00 00 D4 F2 12 00 4D 2C
81 7C 1C 00 1E 00 24 F1 12 00 0E 00 80 00 54 F2 12 00 1C 01 00 00 05 00 00 00 01 00
00 00 28 0A 00 00 02 00 00 00 53 00 65 00 72 00 76 00 69 00 63 00 65 00 20 00 50 00
61 00 63 00 6B 00 20 00 33 00 00 00 12 00 5C F6 90 7C 61 F6 90 7C B4 F1 12 00 6E D9
90 7C 74 F2 12 00 4C F1 12 00 7A D9 90 7C 08 50 41 7E 32 F2 12 00 00 39 41 7E D0 00
00 00 C0 F1 12 00 3B 7D 91 7C 32 F2 12 00 DC 02 00 00 00 00 41 7E 98 44 41 7E 08 50
41 7E 00 00 00 00 01 00 00 00 30 F2 12 00 00 00 00 00 01 00 00 00 00 00 41 7E D8 00
41 7E 98 F1 12 00 01 00 00 00 D0 F1 12 00 85 03 91 7C 00 00 41 7E 00 00 00 00 8C F2
12 00 02 7C 91 7C 00 00 41 7E 32 F2 12 00 2C F2 12 00 2C F2 12 00 32 F2 12 00 A7 7C
91 7C 74 E1 97 7C 51 7C 91 7C 74 DD 00 30 40 AE 80 7C FF FF 00 00 00 F0 FD 7F 7A CF
90 7C 42 9B 80 7C FF FF FF FF 50 F2 12 00 00 00 00 00 54 F2 12 00 00 10 00 00 59 9B
80 7C 04 00 00 00 00 20 00 00 00 10 00 00 00 00 00 00 E8 22 24 00 18 F2 12 00 00 00
45 6E B0 FF 12 00 D8 9A 83 7C 60 9B 80 7C FF FF FF FF 59 9B 80 7C 09 9B 80 7C FF FF
FF FF 00 10 9A 00 00 10 00 00 00 10 00 00 04 00 00 00 00 00 9A 00 D2 B9 CB 30 00 10
9A 00 00 10 00 00 F4 B9 CB 30 28 2F 62 31 40 02 00 00 00 00 9A 00 03 20 00 00 00 10
00 00 CE B8 CB 30 03 00 00 00 FD 3F 00 00 0D 00 00 00 0B 00 00 00 02 00 00 00 02 00
00 00 00 00 00 00 05 00 00 00 15 00 00 00 90 01 00 00 00 00 00 00 60 00 00 00 60 00
00 00 1E FF 1F 20 00 00 00 27 00 00 01 01 87 7A 00 61 00 00 00 80 08 00 00 00 00 00
00 00 01 00 00 00 00 00 28 20 06 00 00 00 F7 FF FF FF 00 00 00 00 00 00 00 00 00 00
00 00 90 01 00 00 00 00 00 00 00 40 00 22 54 00 61 00 68 00 6F 00 6D 00 61 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 54 00 61 00 68 00
6F 00 6D 00 61 00 00 00 12 00 20 E9 90 7C 10 00 00 00 00 F1 12 00 08 F1 12 00 00 00
00 00 E4 F0 12 00 D6 20 91 7C 54 F2 12 00 0E 00 00 00 F0 F0 12 00 24 F1 12 00 1C 00
00 00 54 F2 12 00 9C 00 00 00 00 00 00 00 00 00 00 00 30 F2 12 00 3A 2C 81 7C 08 F1
12 00 0E 00 00 00 00 00 00 00 D4 F2 12 00 4D 2C 81 7C 1C 00 1E 00 24 F1 12 00 0E 00
80 00 54 F2 12 00 1C 01 00 00 05 00 00 00 01 00 00 00 28 0A 00 00 02 00 00 00 53 00
65 00 72 00 76 00 69 00 63 00 65 00 20 00 50 00 61 00 63 00 6B 00 20 00 33 00 00 00
12 00 5C F6 90 7C 61 F6 90 7C B4 F1 12 00 6E D9 90 7C 74 F2 12 00 4C F1 12 00 7A D9
90 7C 08 50 41 7E 32 F2 12 00 00 39 41 7E D0 00 00 00 C0 F1 12 00 3B 7D 91 7C 32 F2
12 00 DC 02 00 00 00 00 41 7E 98 44 41 7E 08 50 41 7E 00 00 00 00 01 00 00 00 30 F2
12 00 00 00 00 00 01 00 00 00 00 00 41 7E D8 00 41 7E 98 F1 12 00 01 00 00 00 D0 F1
12 00 85 03 91 7C 00 00 41 7E 00 00 00 00 8C F2 12 00 02 7C 91 7C 00 00 41 7E 32 F2
12 00 2C F2 12 00 2C F2 12 00 32 F2 12 00 A7 7C 91 7C 74 E1 97 7C 51 7C 91 7C 74 DD
00 30 40 AE 80 7C FF FF 00 00 00 F0 FD 7F 7A CF 90 7C 42 9B 80 7C FF FF FF FF 50 F2
12 00 00 00 00 00 54 F2 12 00 00 10 00 00 59 9B 80 7C 04 00 00 00 00 20 00 00 00 10
00 00 00 00 00 00 E8 22 24 00 18 F2 12 00 00 00 45 6E B0 FF 12 00 D8 9A 83 7C 60 9B
80 7C FF FF FF FF 59 9B 80 7C 09 9B 80 7C FF FF FF FF 00 10 9A 00 00 10 00 00 00 10
00 00 04 00 00 00 00 00 9A 00 D2 B9 CB 30 00 10 9A 00 00 10 00 00 F4 B9 CB 30 28 2F
62 31 40 02 00 00 00 00 9A 00 03 20 00 00 00 10 00 00 CE B8 CB 30 03 00 00 00 FD 3F
00 00 0B 00 00 00 09 00 00 00 02 00 00 00 02 00 00 00 00 00 00 00 04 00 00 00 11 00
00 00 90 01 00 00 00 00 00 00 60 00 00 00 60 00 00 00 1E FF 1F 20 00 00 00 27 00 00
01 01 87 7A 00 61 00 00 00 80 08 00 00 00 00 00 00 00 01 00 00 00 00 00 28 20 05 00
00 00 F5 FF FF FF 00 00 00 00 00 00 00 00 00 00 00 00 BC 02 00 00 00 00 00 00 00 40
00 22 54 00 61 00 68 00 6F 00 6D 00 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 54 00 61 00 68 00 6F 00 6D 00 61 00 00 00 12 00 20 E9
90 7C 10 00 00 00 00 F1 12 00 08 F1 12 00 00 00 00 00 E4 F0 12 00 D6 20 91 7C 54 F2
12 00 0E 00 00 00 F0 F0 12 00 24 F1 12 00 1C 00 00 00 54 F2 12 00 9C 00 00 00 00 00
00 00 00 00 00 00 30 F2 12 00 3A 2C 81 7C 08 F1 12 00 0E 00 00 00 00 00 00 00 D4 F2
12 00 4D 2C 81 7C 1C 00 1E 00 24 F1 12 00 0E 00 80 00 54 F2 12 00 1C 01 00 00 05 00
00 00 01 00 00 00 28 0A 00 00 02 00 00 00 53 00 65 00 72 00 76 00 69 00 63 00 65 00
20 00 50 00 61 00 63 00 6B 00 20 00 33 00 00 00 12 00 5C F6 90 7C 61 F6 90 7C B4 F1
12 00 6E D9 90 7C 74 F2 12 00 4C F1 12 00 7A D9 90 7C 08 50 41 7E 32 F2 12 00 00 39
41 7E D0 00 00 00 C0 F1 12 00 3B 7D 91 7C 32 F2 12 00 DC 02 00 00 00 00 41 7E 98 44
41 7E 08 50 41 7E 00 00 00 00 01 00 00 00 30 F2 12 00 00 00 00 00 01 00 00 00 00 00
41 7E D8 00 41 7E 98 F1 12 00 01 00 00 00 D0 F1 12 00 85 03 91 7C 00 00 41 7E 00 00
00 00 8C F2 12 00 02 7C 91 7C 00 00 41 7E 32 F2 12 00 2C F2 12 00 2C F2 12 00 32 F2
12 00 A7 7C 91 7C 74 E1 97 7C 51 7C 91 7C 74 DD 00 30 40 AE 80 7C FF FF 00 00 00 F0
FD 7F 7A CF 90 7C 42 9B 80 7C FF FF FF FF 50 F2 12 00 00 00 00 00 54 F2 12 00 00 10
00 00 59 9B 80 7C 04 00 00 00 00 20 00 00 00 10 00 00 00 00 00 00 E8 22 24 00 18 F2
12 00 00 00 45 6E B0 FF 12 00 D8 9A 83 7C 60 9B 80 7C FF FF FF FF 59 9B 80 7C 09 9B
80 7C FF FF FF FF 00 10 9A 00 00 10 00 00 00 10 00 00 04 00 00 00 00 00 9A 00 D2 B9
CB 30 00 10 9A 00 00 10 00 00 F4 B9 CB 30 28 2F 62 31 40 02 00 00 00 00 9A 00 03 20
00 00 00 10 00 00 CE B8 CB 30 03 00 00 00 FD 3F 00 00 0D 00 00 00 0B 00 00 00 02 00
00 00 02 00 00 00 00 00 00 00 06 00 00 00 1A 00 00 00 BC 02 00 00 00 00 00 00 60 00
00 00 60 00 00 00 1E FF 1F 20 00 00 00 27 00 00 01 01 87 7A 00 61 00 00 00 80 08 00
00 00 00 00 00 00 01 00 00 00 00 00 28 20 07 00 00 00 Old data:
|
success or wait |
615244013 |
Key value queried |
Path: HKEY_USERS\Control Panel\International Name: iCountry |
success or wait |
615250816 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: UseNTWordDefPgSzBehavior |
object name not found |
615251145 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: UseAlternateTOCDelimiter |
object name not found |
615251465 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: UpdateAllNumpages |
object name not found |
615251780 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: AlternateReplaceAllMethodBehaviour |
object name not found |
615252099 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: WordPartialProtectDocTableResize |
object name not found |
615252469 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: FieldCalcSecurityLevel |
object name not found |
615252785 |
Key created |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Wizards |
success or wait |
615253154 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Wizards Name: PageSize Type:
unicode Data: Letter Old data:
|
success or wait |
615253722 |
Key value queried |
Path: HKEY_USERS\Control Panel\International Name: iMeasure |
success or wait |
615254085 |
Key value queried |
Path: HKEY_USERS\Control Panel\International Name: iTimePrefix |
success or wait |
615254512 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: DOC-EXTENSION |
object name not found |
615255386 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: DOT-EXTENSION |
object name not found |
615255962 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: BAK-EXTENSION |
object name not found |
615256563 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: BitmapMemory |
object name not found |
615257119 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: MessageBeeps |
object name not found |
615257618 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: EnableSubDocPutSaved |
object name not found |
615258105 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: FavorWord97ListIndents |
object name not found |
615258423 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: DoNotConfirmConverterSecurity |
object name not found |
615258737 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: WordRTFOutPathPref |
object name not found |
615259047 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: CalcDataFieldOnOpen |
object name not found |
615259360 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: SlowShading |
object name not found |
615259756 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: HideFileNotSavedDlg |
object name not found |
615260240 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NumberingGapUL |
object name not found |
615261098 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: AlternateRevisionStepThrough |
object name not found |
615261468 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: BlockDocCloseDuringCmdExec |
object name not found |
615261783 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: EnsurePrintLongVertCell |
object name not found |
615262097 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: AlternativeLongTablesLayout |
object name not found |
615262409 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: BulletProofOnCorruption |
object name not found |
615262720 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: UpdateHeaderFooter |
object name not found |
615263031 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: EnsureFlagsOfProtectedDocForVbaSel |
object name not found |
615263346 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: RestoreXmlEvents |
object name not found |
615263656 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: UseLocalBiDiStyle |
object name not found |
615263967 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: AlternateBreakThroughTab |
object name not found |
615264280 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: UpdateWwdVBAUponToggleXML |
object name not found |
615264643 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: SpecialFieldsProtHandling |
object name not found |
615264956 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: WriteUrlWithSubitemAsBinary |
object name not found |
615265269 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: ForceGrayscalePrint |
object name not found |
615265630 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoSmartTagRecognition |
object name not found |
615266251 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoSmartTagActions |
object name not found |
615266565 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: DefaultFormat |
object name not found |
615266873 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: BackgroundSave |
object name not found |
615267183 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: BackgroundOpen |
object name not found |
615267495 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: BackgroundPrint |
object name not found |
615267858 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: PlainTextAutoFormat |
object name not found |
615268169 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Outlook\Options\Calendar Name: Text
Direction
|
success or wait |
615268760 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Outlook\Options\Calendar Name: Text
Direction
|
success or wait |
615269078 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: NoTrack |
object name not found |
615269493 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: Bidi Spelling |
object name not found |
615269808 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: AutoSpell |
object name not found |
615270118 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: AutoGrammar |
object name not found |
615270426 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoLiveScrolling |
object name not found |
615270732 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoFontMRUList |
object name not found |
615271137 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: InsertFloating |
object name not found |
615271496 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoRecentDocsHistory
|
object name not found |
615271962 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: DisableScalingUpForHighDPI |
object name not found |
615272503 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: WordName |
success or wait |
615273348 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
Access: execute or traverse and synchronize Options: directory file and synchronous
io non alert Overwritten: false
|
success or wait |
615274364 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\Comctl32.dll
Access: execute or traverse and synchronize Options: synchronous io non alert and
non directory file Overwritten: false
|
success or wait |
615275384 |
Section loaded |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
Access: write and read and execute Type: commit Baseaddress: A30000 Size: 1056768
Protection: execute Mapped to pid: own pid
|
success or wait |
615276389 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\Comctl32.dll
Access: execute or traverse and synchronize Options: synchronous io non alert and
non directory file Overwritten: false
|
success or wait |
615279101 |
Section loaded |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
Access: query and write and read and execute Type: image Baseaddress: 773D0000 Size:
1060864 Protection: read write Mapped to pid: own pid
|
success or wait |
615280109 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615281610 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615281941 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615282201 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615282452 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615282760 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615283082 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615283400 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615283671 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615283925 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615284250 |
Section loaded |
Path: \KnownDlls\SHLWAPI.dll Access: write and read and execute Type: unknown Baseaddress:
77F60000 Size: 483328 Protection: read write Mapped to pid: own pid
|
success or wait |
615284542 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F61000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615285921 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F61000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615286340 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F61000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615286611 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F61000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615286887 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F61000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615287154 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F61000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615287545 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F61000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615287812 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F61000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615288076 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F61000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615288342 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77F61000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615288720 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615288970 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615289366 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615289618 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 773D1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615289916 |
File opened |
Path: C:\WINDOWS\WindowsShell.Manifest Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
615292328 |
Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: write and read and execute Type: commit
Baseaddress: A30000 Size: 4096 Protection: execute Mapped to pid: own pid
|
success or wait |
615293274 |
File opened |
Path: C:\WINDOWS\WindowsShell.Manifest Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: null
|
success or wait |
615295260 |
Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: query and read Type: commit Baseaddress:
A30000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
615296119 |
File opened |
Path: C:\WINDOWS\WindowsShell.Manifest Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
615297572 |
Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: read Type: commit Baseaddress: A30000
Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
615298353 |
File opened |
Path: C:\WINDOWS\WindowsShell.Config Access: read data or list directory and read
ea and execute or traverse and read attributes and read control and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
object name not found |
615299149 |
Key value queried |
Path: HKEY_USERS\Control Panel\Desktop Name: SmoothScroll |
object name not found |
615330097 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
EnableBalloonTips
|
object name not found |
615331024 |
Window created |
Window Name: OpusApp Class Name: OpusApp HWND: 5012E |
success |
615334574 |
File opened |
Path: C:\WINDOWS\system32\MSCTF.dll Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
615335085 |
Section loaded |
Path: C:\WINDOWS\system32\msctf.dll Access: write and read and execute Type: commit
Baseaddress: A50000 Size: 299008 Protection: execute Mapped to pid: own pid
|
success or wait |
615335849 |
File opened |
Path: C:\WINDOWS\system32\MSCTF.dll Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
615337612 |
Section loaded |
Path: C:\WINDOWS\system32\msctf.dll Access: query and write and read and execute Type:
image Baseaddress: 74720000 Size: 311296 Protection: read write Mapped to pid: own
pid
|
success or wait |
615338361 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 74721000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615339856 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 74721000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615340270 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 74721000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615340536 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 74721000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615340799 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 74721000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615341064 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 74721000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615341434 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 74721000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615341695 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 74721000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615342005 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 74721000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615342266 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 74721000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615342521 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
615343415 |
Section loaded |
Path: \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read Type: commit Baseaddress: unknown Size: unknown Protection:
unknown Mapped to pid: unknown
|
object name exists |
615344928 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\SystemShared Name: CUAS |
success or wait |
615345726 |
Mutant created |
Name: \BaseNamedObjects\CTF.LBES.MutexDefaultS-1-5-21-507921405-1960408961-839522115-500 |
object name exists |
615347407 |
Mutant created |
Name: \BaseNamedObjects\CTF.Compart.MutexDefaultS-1-5-21-507921405-1960408961-839522115-500 |
object name exists |
615347693 |
Mutant created |
Name: \BaseNamedObjects\CTF.Asm.MutexDefaultS-1-5-21-507921405-1960408961-839522115-500 |
object name exists |
615347975 |
Mutant created |
Name: \BaseNamedObjects\CTF.Layouts.MutexDefaultS-1-5-21-507921405-1960408961-839522115-500 |
object name exists |
615348252 |
Mutant created |
Name: \BaseNamedObjects\CTF.TMD.MutexDefaultS-1-5-21-507921405-1960408961-839522115-500 |
object name exists |
615348525 |
Key value queried |
Path: HKEY_USERS\Keyboard Layout\Toggle Name: Language Hotkey |
success or wait |
615348939 |
Key value queried |
Path: HKEY_USERS\Keyboard Layout\Toggle Name: Language Hotkey |
success or wait |
615349309 |
Key value queried |
Path: HKEY_USERS\Keyboard Layout\Toggle Name: Layout Hotkey |
success or wait |
615349671 |
Key value queried |
Path: HKEY_USERS\Keyboard Layout\Toggle Name: Layout Hotkey |
success or wait |
615350031 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF Name: EnableAnchorContext |
object name not found |
615351970 |
Mutant created |
Name: \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-507921405-1960408961-839522115-500MUTEX.DefaultS-1-5-21-507921405-1960408961-839522115-500 |
object name exists |
615352895 |
Section loaded |
Path: \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-507921405-1960408961-839522115-500SFM.DefaultS-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read and execute and extend size Type: unknown Baseaddress:
A50000 Size: 262144 Protection: read write Mapped to pid: own pid
|
success or wait |
615353216 |
Windows hook set |
Module: C:\WINDOWS\system32\MSCTF.dll TID: 1768 Hook ID: keyboard |
success |
615354256 |
Windows hook set |
Module: C:\WINDOWS\system32\MSCTF.dll TID: 1768 Hook ID: mouse |
success |
615354481 |
Message sent |
HWND: 5012E Message: NCCREATE WParam: 0 LParam: 1239824 |
success |
615354948 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IMM Name: Ime
File
|
success or wait |
615355684 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
615356251 |
File opened |
Path: C:\WINDOWS\system32\msctfime.ime Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
615356803 |
Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: write and read and execute Type: commit
Baseaddress: A90000 Size: 180224 Protection: execute Mapped to pid: own pid
|
success or wait |
615357602 |
File opened |
Path: C:\WINDOWS\system32\msctfime.ime Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: null
|
success or wait |
615359508 |
Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: query and read Type: commit Baseaddress:
A90000 Size: 180224 Protection: readonly Mapped to pid: own pid
|
success or wait |
615360352 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
615361713 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
615363329 |
File opened |
Path: C:\WINDOWS\system32\msctfime.ime Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
615363801 |
Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: write and read and execute Type: commit
Baseaddress: A90000 Size: 180224 Protection: execute Mapped to pid: own pid
|
success or wait |
615364594 |
File opened |
Path: C:\WINDOWS\system32\msctfime.ime Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: null
|
success or wait |
615366248 |
Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: query and read Type: commit Baseaddress:
A90000 Size: 180224 Protection: readonly Mapped to pid: own pid
|
success or wait |
615367034 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
615368395 |
File opened |
Path: C:\WINDOWS\system32\msctfime.ime Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
615370016 |
Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: write and read and execute Type: commit
Baseaddress: A90000 Size: 180224 Protection: execute Mapped to pid: own pid
|
success or wait |
615370846 |
File opened |
Path: C:\WINDOWS\system32\msctfime.ime Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
615372398 |
Section loaded |
Path: C:\WINDOWS\system32\msctfime.ime Access: query and write and read and execute
Type: image Baseaddress: 755C0000 Size: 188416 Protection: read write Mapped to pid:
own pid
|
success or wait |
615373179 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615375838 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615377228 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615377525 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615377836 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615378126 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615378420 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615378712 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615379027 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615379316 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615379611 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615379902 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 755C1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615380191 |
Message sent |
HWND: 40132 Message: NCCREATE WParam: 0 LParam: 1239796 |
success |
615382145 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\CTF Name: Disable Thread Input Manager |
object name not found |
615382760 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\SystemShared Name: CUAS |
success or wait |
615384643 |
Message sent |
HWND: 5012E Message: NCCALCSIZE WParam: 0 LParam: 1239864 |
error |
615386572 |
Message sent |
HWND: 5012E Message: WINDOWPOSCHANGING WParam: 0 LParam: 1239844 |
error |
615386929 |
Message sent |
HWND: 5012E Message: NCCALCSIZE WParam: 1 LParam: 1239800 |
error |
615387174 |
Section loaded |
Path: \BaseNamedObjects\PrimaryWord11SharedMemoryArea Access: read Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
615387927 |
Section loaded |
Path: \BaseNamedObjects\PrimaryWord11SharedMemoryArea Access: query and write and
read Type: commit Baseaddress: A90000 Size: 4096 Protection: read write Mapped to
pid: own pid
|
success or wait |
615388162 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\office11\1033\msointl.dll Access:
execute or traverse and synchronize Options: synchronous io non alert and non directory
file Overwritten: false
|
success or wait |
615390190 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\1033\MSOINTL.DLL Access:
write and read and execute Type: commit Baseaddress: AA0000 Size: 1757184 Protection:
execute Mapped to pid: own pid
|
success or wait |
615391044 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\office11\1033\msointl.dll Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file Attributes: none Content Overwritten: null
|
success or wait |
615392866 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\1033\MSOINTL.DLL Access:
query and read Type: commit Baseaddress: AA0000 Size: 1757184 Protection: readonly
Mapped to pid: own pid
|
success or wait |
615393705 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: ScreenReaderPresent |
object name not found |
615394925 |
Section loaded |
Path: \BaseNamedObjects\Local\Mso97SharedDg20321108172 Access: query and write and
read and execute and extend size Type: unknown Baseaddress: unknown Size: unknown
Protection: unknown Mapped to pid: unknown
|
object name not found |
615395289 |
Section loaded |
Path: \BaseNamedObjects\Local\Mso97SharedDg20321108172 Access: query and write and
read Type: reserve Baseaddress: C50000 Size: 126976 Protection: read write Mapped
to pid: own pid
|
success or wait |
615395526 |
Mutant created |
Name: \BaseNamedObjects\Local\Mso97SharedDg20321108172Mutex |
success or wait |
615396415 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: UseAlternateShowUIMethodForFtpSession |
object name not found |
615397418 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: MaxCachedStreamSize |
object name not found |
615397748 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: ShowOtherTablesInDataSrc |
object name not found |
615398140 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: HypAlternateResolveToRel |
object name not found |
615398466 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: RepairSmartTags |
object name not found |
615398786 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: AddressBookNameMax4096 |
object name not found |
615399111 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: ShowDispNameInToolTip |
object name not found |
615399432 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: AllowConsecutiveSlashesInUrlPathComponent |
object name not found |
615399759 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: UseCaseInsensitivePathForHyperlink |
object name not found |
615400133 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: LastUILang |
object name not found |
615400486 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: LastUILang |
object name not found |
615400800 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Name: OfficeUILanguage |
success or wait |
615401115 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Name: OfficeUILanguage |
success or wait |
615401429 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: AcbControl |
object name not found |
615401888 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: AcbOn |
object name not found |
615402514 |
System info queried |
Type: PerformanceInformation |
success or wait |
615402948 |
Process information queried |
PID: 1160 Info Class: QuotaLimits |
success or wait |
615403324 |
Process information queried |
PID: 1160 Info Class: VmCounters |
success or wait |
615403527 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Research\Translation Name:
CurrentProvider
|
success or wait |
615405175 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Research\Translation Name:
MaxWords
|
object name not found |
615405508 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Research\Translation Name:
MaxWordsJapan
|
object name not found |
615405828 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Research\Translation Name:
UseOnline
|
object name not found |
615406147 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Research\Translation Name:
PreferOffline
|
object name not found |
615406466 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Research\Translation Name:
PreferOffline
|
object name not found |
615406777 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Research\Translation Name:
UseMT
|
object name not found |
615407112 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
Access: execute or traverse and synchronize Options: directory file and synchronous
io non alert Overwritten: false
|
success or wait |
615408105 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
RestrictRun
|
object name not found |
615409348 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Word11.pip
Access: read attributes and synchronize and generic read Options: sequential only
and synchronous io non alert and non directory file and open no recall Attributes:
none Content Overwritten: null
|
success or wait |
615409885 |
File read |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Word11.pip
Offset: unknown Length: 12 Value: 19 00 04 00 19 00 19 00 8C 06 00 00
|
success or wait |
615410792 |
File read |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Word11.pip
Offset: unknown Length: 1676 Value: 68 00 00 00 88 05 00 00 80 06 00 00 88 06 00 00
E7 69 CD 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
|
success or wait |
615412096 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 30154 |
success |
615437502 |
Message sent |
HWND: 30154 Message: NCCREATE WParam: 0 LParam: 1239976 |
success |
615437761 |
Message sent |
HWND: 30154 Message: NCCALCSIZE WParam: 0 LParam: 1240016 |
error |
615438004 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: Sound |
object name not found |
615439024 |
Process information queried |
PID: 1160 Info Class: Times |
success or wait |
615440153 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: MTTT |
object name not found |
615440375 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: MTTT |
object name not found |
615440700 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: MTTT |
object name not found |
615441014 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word Name: MTTT Type: binary Data:
88 04 00 00 8C 88 76 79 EA 69 CD 01 00 00 00 00 Old data:
|
success or wait |
615441361 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\BaseSuite Name: 1EBDE4BC9A514630B5412561FA45CCC5 |
object name not found |
615442265 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\InstallRoot Name: InstallCount |
success or wait |
615442851 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Licensing Name: 1EBDE4BC9A514630B5412561FA45CCC5 |
object name not found |
615443327 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\ProductVersion Name:
ProInfo
|
success or wait |
615444019 |
Key value queried |
Path: HKEY_USERS\Control Panel\International Name: NumShape |
success or wait |
615444344 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 40136 |
success |
615479174 |
Window shown |
HWND: 40136 CMD: show no activate |
error |
615479600 |
Key value queried |
Path: HKEY_USERS\Control Panel\International Name: NumShape |
success or wait |
615489544 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: DisableFontLinking |
object name not found |
615489956 |
Key created |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\UserInfo |
success or wait |
615501270 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\UserInfo Name: UserInfo Type:
binary Data: 09 04 68 06 FF 80 40 60 50 38 24 16 0D 06 5F C1 E0 0F 98 33 E9 FE FD
81 BF A0 8C 78 03 7D 7E FC 1F AE 59 87 C3 9A 61 F2 CB 80 3D DF C3 F8 0C 25 FE 3A 7F
44 20 51 28 1A EE 02 BD 7D B7 C6 CB 75 FA B4 DE 79 67 C0 1E CF D6 FC 02 55 27 87 BB
E5 70 43 F8 C5 74 98 46 3D 8D EB 69 A4 D8 F4 AB 15 18 C6 07 B7 CA 85 9A 4C 59 87 DF
CD A7 A3 10 C8 7A 4C 33 47 63 88 21 F9 AC D6 2B 2D 5E AE F5 C3 38 FE 6D 36 3E 95 4E
55 73 59 F6 F6 4B 2D 1E B3 6A DB C9 6A AD 7C 9A D6 96 7B 2D 9D AD 6A 77 AF 96 EA 67
69 BC F6 6A 76 AD AE CF 65 B2 D5 8B 36 7E 02 9E CB 55 73 EC 1A 85 6B 05 A0 8B AC 32
D6 95 8A 5E E3 71 EE DD 23 F5 AD 95 BF 9B 5F AE AC DA BC F6 7E 5E B5 9E D3 D8 13 1C
62 EE 6C 2D A6 21 98 D8 CD 30 FB 75 8B 8C 63 73 F0 E5 62 CD 63 2C F6 5B 46 2A D0 F6
88 62 BB C3 1B C8 13 DD DF 12 8C 42 A4 30 57 BF 8A 42 DF 86 79 BC 70 49 CF AB DD EF
F8 7C 7E 5F 3F A7 D7 ED F7 FC 7E 7F 5F BF E7 F7 FD FF 80 20 18 0A 03 81 20 58 1A 07
82 20 98 2A 0B 83 20 D8 3A 0F 84 21 18 49 EE Old data:
|
success or wait |
615502113 |
Windows hook set |
Module: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE TID: 1768 Hook ID:
FFFFFFFF
|
success |
615503530 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows NT\CurrentVersion\Windows Name: Device |
success or wait |
615503933 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows NT\CurrentVersion\Devices Name: Microsoft
XPS Document Writer
|
success or wait |
615504447 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: ScreenReaderPresent |
object name not found |
615505036 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Messaging Subsystem Name: MAPIX |
object name not found |
615505918 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Messaging Subsystem Name: MAPIX |
object name not found |
615506245 |
File opened |
Path: C:\WINDOWS\system32\rpcss.dll Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
615507231 |
Section loaded |
Path: C:\WINDOWS\system32\rpcss.dll Access: write and read and execute Type: commit
Baseaddress: CF0000 Size: 401408 Protection: execute Mapped to pid: own pid
|
success or wait |
615507999 |
System info queried |
Type: BasicInformation |
success or wait |
615509833 |
System info queried |
Type: BasicInformation |
success or wait |
615510033 |
System info queried |
Type: BasicInformation |
success or wait |
615510249 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 4014A |
success |
615534680 |
Message sent |
HWND: 4014A Message: NCCREATE WParam: 0 LParam: 1239144 |
success |
615534937 |
Message sent |
HWND: 4014A Message: NCCALCSIZE WParam: 0 LParam: 1239184 |
error |
615535165 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoRereg |
object name not found |
615535472 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020906-0000-0000-C000-000000000046}\LocalServer32
Name: NULL
|
success or wait |
615536792 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
615537186 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
615538046 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
615538242 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
615538628 |
File opened |
Path: C:\Program Files\ Access: read data or list directory and synchronize Options:
directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
615539833 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
615540998 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Word.Document\CurVer Name: NULL |
success or wait |
615541699 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: GlobalDotName |
object name not found |
615542175 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
615543724 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates\
Access: read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
615545985 |
Section loaded |
Path: \KnownDlls\SHELL32.dll Access: write and read and execute Type: unknown Baseaddress:
7C9C0000 Size: 8482816 Protection: read write Mapped to pid: own pid
|
success or wait |
615550751 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615552098 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615552590 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615552842 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615553120 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615553372 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615553794 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615554043 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615554302 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615554603 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615554860 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615555112 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615555362 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615555611 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615555988 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615556237 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 7C9C1000
Length: 2000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615556768 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\Setup Name: SystemSetupInProgress |
success or wait |
615558745 |
File opened |
Path: C:\WINDOWS\system32\SHELL32.dll Access: read data or list directory and read
ea and execute or traverse and read attributes and read control and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
615560115 |
Section loaded |
Path: C:\WINDOWS\system32\shell32.dll Access: read Type: commit Baseaddress: CF0000
Size: 8462336 Protection: readonly Mapped to pid: own pid
|
success or wait |
615561446 |
File opened |
Path: C:\WINDOWS\system32\SHELL32.dll.124.Manifest Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
615562197 |
File opened |
Path: C:\WINDOWS\system32\SHELL32.dll.124.Config Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
615563283 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
Access: execute or traverse and synchronize Options: directory file and synchronous
io non alert Overwritten: false
|
success or wait |
615603005 |
Section loaded |
Path: \KnownDlls\comctl32.dll Access: write and read and execute Type: unknown Baseaddress:
5D090000 Size: 630784 Protection: read write Mapped to pid: own pid
|
success or wait |
615604650 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5D091000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615606017 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5D091000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615606453 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5D091000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615606797 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5D091000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615607112 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5D091000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615607401 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5D091000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615607730 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5D091000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615608066 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5D091000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615608347 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5D091000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
615608632 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 5D091000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
615609023 |
System info queried |
Type: BasicInformation |
success or wait |
615609935 |
File opened |
Path: C:\WINDOWS\system32\comctl32.dll Access: read data or list directory and read
ea and execute or traverse and read attributes and read control and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
615612719 |
Section loaded |
Path: C:\WINDOWS\system32\comctl32.dll Access: read Type: commit Baseaddress: CF0000
Size: 618496 Protection: readonly Mapped to pid: own pid
|
success or wait |
615613545 |
File opened |
Path: C:\WINDOWS\system32\comctl32.dll.124.Manifest Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
615614394 |
File opened |
Path: C:\WINDOWS\system32\comctl32.dll.124.Config Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
615615411 |
Process information queried |
PID: 1160 Info Class: SessionInformation |
success or wait |
615621175 |
Key value queried |
Path: HKEY_USERS\Control Panel\Desktop Name: SmoothScroll |
object name not found |
615622364 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: ScriptAnchorVis |
object name not found |
615633776 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Proofing Tools Name: FormatConsistencyWavyUnderlineColor |
object name not found |
615634806 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: GlobalDotName |
object name not found |
615666016 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
615667385 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates\
Access: read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
615669263 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems Name:
|
object name not found |
615675711 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems Name:
Type: binary Data: 05 14 02 00 88 04 00 00 04 00 00 00 00 00 00 00 BE 00 00 00 01
00 00 00 B6 00 00 00 57 00 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E
00 74 00 73 00 20 00 61 00 6E 00 64 00 20 00 53 00 65 00 74 00 74 00 69 00 6E 00 67
00 73 00 5C 00 41 00 64 00 6D 00 69 00 6E 00 69 00 73 00 74 00 72 00 61 00 74 00 6F
00 72 00 5C 00 41 00 70 00 70 00 6C 00 69 00 63 00 61 00 74 00 69 00 6F 00 6E 00 20
00 44 00 61 00 74 00 61 00 5C 00 4D 00 69 00 63 00 72 00 6F 00 73 00 6F 00 66 00 74
00 5C 00 54 00 65 00 6D 00 70 00 6C 00 61 00 74 00 65 00 73 00 5C 00 4E 00 6F 00 72
00 6D 00 61 00 6C 00 2E 00 64 00 6F 00 74 00 00 00 00 00 00 00 Old data:
|
success or wait |
615676216 |
Section loaded |
Path: \BaseNamedObjects\DfSharedHeap35EFC Access: query and write and read Type: reserve
Baseaddress: DA0000 Size: 4194304 Protection: read write Mapped to pid: own pid
|
success or wait |
615679239 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates\Normal.dot
Access: read attributes and synchronize and generic read and generic write Options:
synchronous io non alert and non directory file Attributes: normal Content Overwritten:
null
|
success or wait |
615680778 |
System info queried |
Type: PerformanceInformation |
success or wait |
615681738 |
Process information queried |
PID: 1160 Info Class: QuotaLimits |
success or wait |
615682534 |
Process information queried |
PID: 1160 Info Class: VmCounters |
success or wait |
615682754 |
Section loaded |
Path: \BaseNamedObjects\DFMap0-220928 Access: query and write and read Type: commit
Baseaddress: D10000 Size: 524288 Protection: read write Mapped to pid: own pid
|
success or wait |
615683012 |
Section loaded |
Path: \BaseNamedObjects\DfRoot000035EFC Access: query and write and read Type: commit
Baseaddress: 11A0000 Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
615688234 |
File created |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF5F05.tmp Access: read attributes and delete
and synchronize and generic read and generic write Options: synchronous io non alert
and non directory file and delete on close Attributes: temporary Content Overwritten:
null
|
success or wait |
615690610 |
File other op |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF5F05.tmp New path: Disposition: PositionInformation
Data : Offset: 512
|
success or wait |
615699064 |
File other op |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF5F05.tmp New path: Disposition: EndOfFileInformation
Data : unknown
|
success or wait |
615699288 |
File other op |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF5F05.tmp New path: Disposition: AllocationInformation
Data : unknown
|
success or wait |
615702945 |
File other op |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF5F05.tmp New path: Disposition: PositionInformation
Data : Offset: 0
|
success or wait |
615703737 |
System info queried |
Type: PerformanceInformation |
success or wait |
615703929 |
Process information queried |
PID: 1160 Info Class: QuotaLimits |
success or wait |
615704360 |
Process information queried |
PID: 1160 Info Class: VmCounters |
success or wait |
615704571 |
Section loaded |
Path: \BaseNamedObjects\DFMap0-220944 Access: query and write and read Type: commit
Baseaddress: 11B0000 Size: 524288 Protection: read write Mapped to pid: own pid
|
success or wait |
615704906 |
File created |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates\~$Normal.dot
Access: read attributes and synchronize and generic write Options: synchronous io
non alert and non directory file and open no recall Attributes: hidden Content Overwritten:
null
|
success or wait |
615711576 |
File write |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates\~$Normal.dot
Offset: unknown Length: 54 Value: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00
|
success or wait |
615715203 |
File write |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates\~$Normal.dot
Offset: unknown Length: 108 Value: 00 00 00 00 04 00 00 00 00 00 00 00 04 00 00 00
00 00 00 00 48 00 00 00 00 00 3E 00 02 02 00 00 06 00 09 00 34 00 00 00 00 00 90 00
90 00 00 00 00 00 0F 00 00 00 FF FF FF 00 00 00 00 00 00 00 14 00 14 00 00 00 00 00
00 00 02 63 78 00 C8 00 00 00 00 00 14 00 00 00 00 00 90 00 90 00 80 00 16 00 00 00
|
success or wait |
615716383 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Name: Cache
|
success or wait |
615738846 |
Key value replaced with same |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Name: Cache Type: unicode Data: C:\Documents and Settings\Administrator\Local Settings\Temporary
Internet Files Old data:
|
success or wait |
615740969 |
File opened |
Path: C:\Program Files\AutoIt3\:\Documents and Settings\Administrator\Local Settings\Temporary
Internet Files\Content.Word Access: read attributes and delete Options: non directory
file and open for backup ident and open reparse point Overwritten: false
|
object name invalid |
615744056 |
File created |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.Word
Access: read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Attributes: normal Content Overwritten: null
|
success or wait |
615744728 |
File opened |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.Word
Access: write attributes and synchronize Options: synchronous io non alert and open
for backup ident and open reparse point Overwritten: false
|
success or wait |
615747908 |
File other op |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.Word
New path: Disposition: BasicInformation Data : Creation Time: 01:00 01-01-1601
Last Access Time: 01:00 01-01-1601 Last Write Time: 01:00 01-01-1601 Change Time:
01:00 01-01-1601 File Attributes: hidden and archive and temporary and sparse file
|
success or wait |
615748785 |
File created |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.Word\~WRS0000.tmp
Access: read attributes and synchronize and generic read and generic write Options:
synchronous io non alert and non directory file and open no recall Attributes: normal
Content Overwritten: null
|
success or wait |
615751599 |
Key value deleted |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems Keyname:
|
success or wait |
615757640 |
Window created |
Window Name: _WwC Class Name: _WwC HWND: 40134 |
success |
615761522 |
Message sent |
HWND: 40134 Message: NCCREATE WParam: 0 LParam: 1238664 |
success |
615761779 |
Window shown |
HWND: 40134 CMD: show normal |
error |
615762195 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\CTF Name: Disable Thread Input Manager |
object name not found |
615762905 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\LanguageProfile\0x00000409\{09EA4E4B-46CE-4469-B450-0DE76A435BBB}
Name: Enable
|
success or wait |
615763654 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\LanguageProfile\0x00000807\{09EA4E4B-46CE-4469-B450-0DE76A435BBB}
Name: Enable
|
success or wait |
615764560 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\LanguageProfile\0x0000ffff\{09EA4E4B-46CE-4469-B450-0DE76A435BBB}
Name: Enable
|
success or wait |
615765801 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 40138 |
success |
615791342 |
Message sent |
HWND: 40138 Message: NCCREATE WParam: 0 LParam: 1238952 |
success |
615791608 |
Message sent |
HWND: 40138 Message: NCCALCSIZE WParam: 0 LParam: 1238992 |
error |
615791846 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 3011C |
success |
615816462 |
Message sent |
HWND: 40138 Message: NCCREATE WParam: 0 LParam: 1238952 |
success |
615816715 |
Message sent |
HWND: 40138 Message: NCCALCSIZE WParam: 0 LParam: 1238992 |
error |
615816949 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 800F4 |
success |
615841139 |
Message sent |
HWND: 40138 Message: NCCREATE WParam: 0 LParam: 1238952 |
success |
615841336 |
Message sent |
HWND: 40138 Message: NCCALCSIZE WParam: 0 LParam: 1238992 |
error |
615841569 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 5010A |
success |
615865728 |
Message sent |
HWND: 40138 Message: NCCREATE WParam: 0 LParam: 1238952 |
success |
615865925 |
Message sent |
HWND: 40138 Message: NCCALCSIZE WParam: 0 LParam: 1238992 |
error |
615866302 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 50108 |
success |
615890024 |
Message sent |
HWND: 50108 Message: NCCREATE WParam: 0 LParam: 1237660 |
success |
615890290 |
Message sent |
HWND: 50108 Message: NCCALCSIZE WParam: 0 LParam: 1237700 |
error |
615890661 |
Message sent |
HWND: 50108 Message: SETTEXT WParam: 0 LParam: 8912904 |
success |
615896987 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 400E0 |
success |
615922751 |
Message sent |
HWND: 50108 Message: NCCREATE WParam: 0 LParam: 1237660 |
success |
615923213 |
Message sent |
HWND: 50108 Message: NCCALCSIZE WParam: 0 LParam: 1237700 |
error |
615923443 |
Message sent |
HWND: 50108 Message: SETTEXT WParam: 0 LParam: 8912904 |
success |
615923743 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale Name: 00000409 |
success or wait |
615929343 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups Name: 1 |
success or wait |
615930805 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 400E8 |
success |
615956173 |
Message sent |
HWND: 50108 Message: NCCREATE WParam: 0 LParam: 1237660 |
success |
615956404 |
Message sent |
HWND: 50108 Message: NCCALCSIZE WParam: 0 LParam: 1237700 |
error |
615956771 |
Message sent |
HWND: 50108 Message: SETTEXT WParam: 0 LParam: 8912904 |
success |
615957077 |
Message sent |
HWND: 5010A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1240492 |
error |
615958825 |
Message sent |
HWND: 5010A Message: NCCALCSIZE WParam: 1 LParam: 1240448 |
error |
615959098 |
Message sent |
HWND: 5010A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1240492 |
error |
615959317 |
Message sent |
HWND: 5010A Message: NCCALCSIZE WParam: 1 LParam: 1240448 |
error |
615959532 |
Message sent |
HWND: 5010A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1240492 |
error |
615959744 |
Message sent |
HWND: 5010A Message: NCCALCSIZE WParam: 1 LParam: 1240448 |
error |
615959955 |
Message sent |
HWND: 5010A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1240492 |
error |
615960170 |
Message sent |
HWND: 5010A Message: NCCALCSIZE WParam: 1 LParam: 1240448 |
error |
615960383 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\BaseSuite Name: 1EBDE4BC9A514630B5412561FA45CCC5 |
object name not found |
616024400 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\InstallRoot Name: InstallCount |
success or wait |
616024908 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Licensing Name: 1EBDE4BC9A514630B5412561FA45CCC5 |
object name not found |
616056867 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\ProductVersion Name:
ProInfo
|
success or wait |
616057368 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail Name: NULL |
success or wait |
616063298 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail\Outlook Express\Envelope\CLSID Name:
NULL
|
success or wait |
616063772 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\BaseSuite Name: 1EBDE4BC9A514630B5412561FA45CCC5 |
object name not found |
616087610 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\InstallRoot Name: InstallCount |
success or wait |
616157424 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Licensing Name: 1EBDE4BC9A514630B5412561FA45CCC5 |
object name not found |
616157973 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\ProductVersion Name:
ProInfo
|
success or wait |
616161023 |
Message sent |
HWND: 400E8 Message: NCCALCSIZE WParam: 1 LParam: 1240312 |
error |
616161943 |
Message sent |
HWND: 50108 Message: NCCALCSIZE WParam: 1 LParam: 1240368 |
error |
616165173 |
Message sent |
HWND: 50108 Message: NCCALCSIZE WParam: 1 LParam: 1240368 |
error |
616165404 |
Message sent |
HWND: 40134 Message: WINDOWPOSCHANGING WParam: 0 LParam: 1240240 |
error |
616166064 |
Message sent |
HWND: 5010A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1240328 |
error |
616169590 |
Message sent |
HWND: 5010A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1240328 |
error |
616169818 |
Message sent |
HWND: 3011C Message: NCCALCSIZE WParam: 1 LParam: 1240284 |
error |
616170041 |
Message sent |
HWND: 5010A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1240328 |
error |
616171359 |
Message sent |
HWND: 3011C Message: NCCALCSIZE WParam: 1 LParam: 1240284 |
error |
616171582 |
Message sent |
HWND: 5010A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1240328 |
error |
616171806 |
Message sent |
HWND: 3011C Message: NCCALCSIZE WParam: 1 LParam: 1240284 |
error |
616173826 |
Window shown |
HWND: 3011C CMD: show no activate |
error |
616174333 |
Window shown |
HWND: 3011C CMD: show no activate |
success |
616174508 |
Window created |
Window Name: _WwF Class Name: _WwF HWND: 90058 |
success |
616180241 |
Message sent |
HWND: 90058 Message: NCCREATE WParam: 0 LParam: 1238704 |
success |
616180531 |
Message sent |
HWND: 90058 Message: NCCALCSIZE WParam: 0 LParam: 1238756 |
error |
616180757 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: UseAlternateForegroundWindowDetectionMethod |
object name not found |
616182598 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: UseSpaceAsTextDelimiter |
object name not found |
616182934 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: AlternateTableHeightLayout |
object name not found |
616183310 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: AdjustSdtCaSmart |
object name not found |
616185006 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: MMDataSrcHeuristic |
object name not found |
616188014 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: DontJumpForegroundInDDEExec |
object name not found |
616188345 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: DisableODSOUIInDataSrc |
object name not found |
616188668 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: UseTempCopyForNonLocDoc |
object name not found |
616190366 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: KeepUISpecModeAtVbaEnd |
object name not found |
616190744 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: UseAlternatePageNumberFormat |
object name not found |
616191142 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: DontUpdateSmartDocAtInsert |
object name not found |
616192778 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: ShowFileNameOnlyInIconCaption |
object name not found |
616193569 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: AlternateStyleCopyPasteNoOverwrite |
object name not found |
616193890 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: DontShowDocActionsPaneAtOpen |
object name not found |
616195129 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: FastTableRenderOnIMETS |
object name not found |
616195460 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: MntrSynchronize1stTabCell |
object name not found |
616195782 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoLinkBltinCharStyles |
object name not found |
616196264 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoDocChangeEventOnStoryRange |
object name not found |
616196586 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: TreatLocationReferenceAsLocal |
object name not found |
616196958 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: ForceSetCopyCount |
object name not found |
616198053 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: ListDefaultDictForAllLanFirst |
object name not found |
616198378 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: MailMergeFastSetPrintOrient |
object name not found |
616198693 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: SuppressPrinterIconEnum |
object name not found |
616199749 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoActivateOleLinkObjAtOpen |
object name not found |
616200072 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: CheckDupAddin4ShellLoad |
object name not found |
616200389 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: CleanupOldHyphBeforeHyphenate |
object name not found |
616201543 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: KeepDocActPaneWhileInReviewPane |
object name not found |
616201868 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: FireSelChangeEventInTableCell |
object name not found |
616202284 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: UpdateHdrFtrOnVBAFldUpdate |
object name not found |
616202669 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: ForceUpdateToolbarAtInit |
object name not found |
616202988 |
Window shown |
HWND: 5012E CMD: show maximized |
error |
616203283 |
Message sent |
HWND: 5012E Message: WINDOWPOSCHANGING WParam: 0 LParam: 1240708 |
error |
616203496 |
Message sent |
HWND: 5012E Message: NCCALCSIZE WParam: 1 LParam: 1240664 |
error |
616213035 |
Foreground Window Got |
HWND: 0 |
error |
616239855 |
Message posted |
HWND: 5012E Message: D00 WParam: 37 LParam: 0 |
success |
616241903 |
Foreground Window Got |
HWND: 5012E |
success |
616242077 |
Windows found |
Window Name: NULL Class Name: MSOBALLOON HWND: 0 |
error |
616242285 |
Windows found |
Window Name: NULL Class Name: MsoHelp10 HWND: 0 |
error |
616242498 |
Windows found |
Window Name: NULL Class Name: AgentAnim HWND: 0 |
error |
616242706 |
Message sent |
HWND: 5012E Message: NCACTIVATE WParam: 1 LParam: 0 |
success |
616242945 |
Message posted |
HWND: 5012E Message: D00 WParam: 37 LParam: 0 |
success |
616244005 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\office11\riched20.dll Access:
execute or traverse and synchronize Options: synchronous io non alert and non directory
file Overwritten: false
|
success or wait |
616255091 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\RICHED20.DLL Access:
write and read and execute Type: commit Baseaddress: 1240000 Size: 1105920 Protection:
execute Mapped to pid: own pid
|
success or wait |
616255960 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\office11\riched20.dll Access:
execute or traverse and synchronize Options: synchronous io non alert and non directory
file Overwritten: false
|
success or wait |
616257851 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\RICHED20.DLL Access:
query and write and read and execute Type: image Baseaddress: 39700000 Size: 1097728
Protection: read write Mapped to pid: own pid
|
success or wait |
616258692 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 397EE000
Length: 1000 New Protection: page read and write New Protection: page readonly
|
success or wait |
616260852 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 397EE000
Length: 1000 New Protection: page readonly New Protection: page read and write
|
success or wait |
616261355 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 397EE000
Length: 1000 New Protection: page read and write New Protection: page readonly
|
success or wait |
616261609 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 397EE000
Length: 1000 New Protection: page readonly New Protection: page read and write
|
success or wait |
616261915 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 397EE000
Length: 1000 New Protection: page read and write New Protection: page readonly
|
success or wait |
616262169 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 397EE000
Length: 1000 New Protection: page readonly New Protection: page read and write
|
success or wait |
616262510 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 397EE000
Length: 1000 New Protection: page read and write New Protection: page readonly
|
success or wait |
616262763 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 397EE000
Length: 1000 New Protection: page readonly New Protection: page read and write
|
success or wait |
616263225 |
System info queried |
Type: BasicInformation |
success or wait |
616263877 |
Section loaded |
Path: \KnownDlls\OLEAUT32.dll Access: write and read and execute Type: unknown Baseaddress:
77120000 Size: 569344 Protection: read write Mapped to pid: own pid
|
success or wait |
616265195 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
616266375 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
616282640 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
616282897 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
616283202 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
616283451 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
616283814 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
616284058 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
616284322 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
616284564 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
616284817 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
616286131 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77121000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
616286563 |
Message posted |
TID: 6E8 Message: C087 WParam: 17 LParam: 327982 |
success |
616287700 |
Window created |
Window Name: MSCTFIME UI Class Name: MSCTFIME UI HWND: 400FA |
success |
616289003 |
Message sent |
HWND: 400FA Message: NCCREATE WParam: 0 LParam: 1234616 |
success |
616290408 |
Message sent |
HWND: 400FA Message: NCCALCSIZE WParam: 0 LParam: 1234656 |
error |
616291247 |
File opened |
Path: C:\WINDOWS\system32\Msimtf.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
616291981 |
Section loaded |
Path: C:\WINDOWS\system32\msimtf.dll Access: write and read and execute Type: commit
Baseaddress: 1300000 Size: 159744 Protection: execute Mapped to pid: own pid
|
success or wait |
616306050 |
Foreground Window Got |
HWND: 5012E |
success |
616308358 |
File opened |
Path: C:\WINDOWS\system32\Msimtf.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
616309199 |
Section loaded |
Path: C:\WINDOWS\system32\msimtf.dll Access: write and read and execute Type: commit
Baseaddress: 1300000 Size: 159744 Protection: execute Mapped to pid: own pid
|
success or wait |
616310071 |
File opened |
Path: C:\WINDOWS\system32\Msimtf.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
616315914 |
Section loaded |
Path: C:\WINDOWS\system32\msimtf.dll Access: write and read and execute Type: commit
Baseaddress: 1300000 Size: 159744 Protection: execute Mapped to pid: own pid
|
success or wait |
616316854 |
File opened |
Path: C:\WINDOWS\system32\Msimtf.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
616319381 |
Section loaded |
Path: C:\WINDOWS\system32\msimtf.dll Access: write and read and execute Type: commit
Baseaddress: 1300000 Size: 159744 Protection: execute Mapped to pid: own pid
|
success or wait |
616320290 |
Foreground Window Got |
HWND: 5012E |
success |
616325024 |
Windows found |
Window Name: NULL Class Name: Shell_TrayWnd HWND: 1005E |
success |
616325488 |
Windows enumerated |
Desktop: 0 Parent: 1005E Enum Children: true TID: 0 HWNDs: 10064, 10066, 10068, 1006A,
1006C, 1006E, 10078, 10084, 10088, 1, 88000000, 88000000, 88000000, 88000000, 88000000
|
success or wait |
616325703 |
Message posted |
TID: 61C Message: C087 WParam: 1 LParam: 0 |
success |
616326189 |
Message posted |
TID: 6E8 Message: C087 WParam: 0 LParam: 0 |
success |
616326569 |
Section loaded |
Path: \BaseNamedObjects\CTF.AsmListCache.FMPDefaultS-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read and execute and extend size Type: unknown Baseaddress:
1300000 Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
616327354 |
Window created |
Window Name: CicMarshalWndClass Class Name: CicMarshalWndClass HWND: A0118 |
success |
616340296 |
Message sent |
HWND: A0118 Message: NCCREATE WParam: 0 LParam: 1238464 |
success |
616340577 |
Message sent |
HWND: A0118 Message: NCCALCSIZE WParam: 0 LParam: 1238528 |
error |
616340824 |
Message posted |
TID: 7DC Message: C088 WParam: 0 LParam: 0 |
success |
616341211 |
Message sent |
HWND: 5012E Message: NCPAINT WParam: 1 LParam: 0 |
error |
616342348 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
616343552 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
616349609 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
616350145 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
616350382 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
616350727 |
Foreground Window Got |
HWND: 5012E |
success |
616351306 |
System info queried |
Type: BasicInformation |
success or wait |
616351773 |
System info queried |
Type: ProcessorInformation |
success or wait |
616352019 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: AddIns |
success or wait |
616358148 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Word\Addins\WebPage.Connect Name: LoadBehavior |
success or wait |
616359281 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: Com+Enabled |
success or wait |
616359896 |
Section loaded |
Path: \KnownDlls\CLBCATQ.DLL Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
616360465 |
File opened |
Path: C:\WINDOWS\system32\CLBCATQ.DLL Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
616362318 |
Section loaded |
Path: C:\WINDOWS\system32\clbcatq.dll Access: query and write and read and execute
Type: image Baseaddress: 76FD0000 Size: 520192 Protection: read write Mapped to pid:
own pid
|
success or wait |
616363103 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
616364896 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
616365403 |
Section loaded |
Path: \KnownDlls\COMRes.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
616365709 |
File opened |
Path: C:\WINDOWS\system32\COMRes.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
616366469 |
Section loaded |
Path: C:\WINDOWS\system32\comres.dll Access: query and write and read and execute
Type: image Baseaddress: 77050000 Size: 806912 Protection: read write Mapped to pid:
own pid
|
success or wait |
616367381 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77051000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
616369137 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 77051000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
616369490 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
616369761 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
616370188 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
616370454 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
616389046 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
616389325 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
616389589 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
616389853 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
616390121 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page read and write New Protection: page execute read
|
success or wait |
616390390 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 76FD1000
Length: 1000 New Protection: page execute read New Protection: page read and write
|
success or wait |
616390702 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole Name: MinimumFreeMemPercentageToCreateProcess |
object name not found |
616392684 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole Name: MinimumFreeMemPercentageToCreateObject |
object name not found |
616393057 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
616394889 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: Com+Enabled |
success or wait |
616395247 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
616398146 |
System info queried |
Type: BasicInformation |
success or wait |
616399075 |
System info queried |
Type: ProcessorInformation |
success or wait |
616399293 |
File opened |
Path: C:\WINDOWS\Registration\R000000000007.clb Access: read attributes and synchronize
and generic read Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: null
|
success or wait |
616409692 |
File other op |
Path: C:\WINDOWS\Registration\R000000000007.clb New path: Disposition: PositionInformation
Data : Offset: 22512
|
success or wait |
616410524 |
File other op |
Path: C:\WINDOWS\Registration\R000000000007.clb New path: Disposition: PositionInformation
Data : Offset: 0
|
success or wait |
616411175 |
File read |
Path: C:\WINDOWS\Registration\R000000000007.clb Offset: unknown Length: 22512 Value:
43 4F 4D 2B 01 00 00 00 01 00 12 00 24 00 00 00 00 01 01 00 63 00 00 00 00 00 00 01
01 00 00 00 00 01 10 00 00 00 00 00 C0 00 00 00 00 00 00 46 0E 00 00 00 30 01 00 00
A0 03 00 00 33 5F 30 00 D0 04 00 00 0C 00 00 00 33 5F 31 00 DC 04 00 00 88 02 00 00
33 5F 32 00 64 07 00 00 3C 00 00 00 33 5F 33 00
|
success or wait |
616411386 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Word\Addins\WebPage.Connect Name: FileName |
object name not found |
616428783 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Word\Addins\WordEEFonts.Connect Name: LoadBehavior |
success or wait |
616429720 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
616430205 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Word\Addins\WordEEFonts.Connect Name: FileName |
object name not found |
616430803 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\CTF Name: Disable Thread Input Manager |
object name not found |
616431770 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{1188450c-fdab-47ae-80d8-c9633f71be64}\LanguageProfile\0x00000000\{63800dac-e7ca-4df9-9a5c-20765055488d}
Name: Enable
|
success or wait |
616433570 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\LanguageProfile\0x00000409\{09EA4E4B-46CE-4469-B450-0DE76A435BBB}
Name: Enable
|
success or wait |
616434822 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\LanguageProfile\0x00000807\{09EA4E4B-46CE-4469-B450-0DE76A435BBB}
Name: Enable
|
success or wait |
616435711 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\LanguageProfile\0x0000ffff\{09EA4E4B-46CE-4469-B450-0DE76A435BBB}
Name: Enable
|
success or wait |
616437433 |
Window destroyed |
HWND: 40136 |
success |
616439628 |
Windows enumerated |
Desktop: 0 Parent: 0 Enum Children: false TID: 6E8 HWNDs: 40136, 5012E, 30154, 400FA,
40132, 1, 10078, 10084, 10088, 1, 88000000, 88000000, 88000000, 88000000, 88000000
|
success or wait |
616439797 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
616440249 |
Window shown |
HWND: 40134 CMD: show normal |
success |
616446590 |
Message sent |
HWND: 5012E Message: SETICON WParam: 1 LParam: 197243 |
error |
616451498 |
Message sent |
HWND: 5012E Message: SETICON WParam: 0 LParam: 197151 |
error |
616454393 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: QuickPreview |
object name not found |
616455491 |
Window shown |
HWND: 40134 CMD: show normal |
success |
616455795 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Name: Local AppData
|
success or wait |
616458408 |
Key value replaced with same |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Name: Local AppData Type: unicode Data: C:\Documents and Settings\Administrator\Local
Settings\Application Data Old data:
|
success or wait |
616460268 |
File opened |
Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Schemas\MS
Word_restart.xml Access: read attributes and delete Options: non directory file and
open for backup ident and open reparse point Overwritten: false
|
object path not found |
616461003 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: STARTUP-PATH |
object name not found |
616461960 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: Startup |
success or wait |
616463240 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Word\STARTUP\
Access: read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
616470135 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\STARTUP\ Access: read data or list
directory and synchronize Options: directory file and synchronous io non alert and
open for backup ident Overwritten: false
|
success or wait |
616471769 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: VolumePref |
object name not found |
616474285 |
Process information queried |
PID: 1160 Info Class: Times |
success or wait |
616474604 |
Key value deleted |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems Keyname:
y
|
success or wait |
616475025 |
Key deleted |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems |
success or wait |
616476084 |
Key deleted |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency |
success or wait |
616479118 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: FirstRun |
object name not found |
616479844 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: FirstRun |
success or wait |
616481561 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: FirstRun |
object name not found |
616481950 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: FirstRun Type:
dword Data: 0 Old data:
|
success or wait |
616482275 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\UserInfo Name: UserName |
success or wait |
616484820 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\UserInfo Name: UserInitials |
success or wait |
616485142 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\UserInfo Name: Company |
success or wait |
616485475 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Wizards Name: Assistant Time
Stamp
|
object name not found |
616489049 |
Mutant created |
Name: \BaseNamedObjects\OfficeAssistantStateMutex |
success or wait |
616489428 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common\Assistant Name: AsstState |
object name not found |
616490261 |
System info queried |
Type: PerformanceInformation |
success or wait |
616490698 |
Process information queried |
PID: 1160 Info Class: QuotaLimits |
success or wait |
616491092 |
Process information queried |
PID: 1160 Info Class: VmCounters |
success or wait |
616491291 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Office\Common\Assistant Name: CurrAsstState Type:
dword Data: 38 Old data:
|
success or wait |
616491530 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: ScreenReaderPresent |
object name not found |
616493869 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
616501058 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
616501745 |
System info queried |
Type: BasicInformation |
success or wait |
616502372 |
System info queried |
Type: ProcessorInformation |
success or wait |
616504688 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A1F4E726-8CF1-11D1-BF92-0060081ED811}\LocalServer32
Name: LocalServer32
|
object name not found |
616508589 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A1F4E726-8CF1-11D1-BF92-0060081ED811}\LocalServer32
Name: NULL
|
success or wait |
616511109 |
Process information queried |
PID: 1160 Info Class: SessionInformation |
success or wait |
616512668 |
System info queried |
Type: BasicInformation |
success or wait |
616514924 |
File opened |
Path: C:\WINDOWS\system32\winlogon.exe Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
616515914 |
Section loaded |
Path: C:\WINDOWS\system32\winlogon.exe Access: write and read and execute Type: commit
Baseaddress: 1330000 Size: 507904 Protection: execute Mapped to pid: own pid
|
success or wait |
616518917 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole Name: MaximumAllowedAllocationSize |
object name not found |
616524523 |
Section loaded |
Path: \KnownDlls\xpsp2res.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
616525430 |
File opened |
Path: C:\WINDOWS\system32\xpsp2res.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
616526172 |
Section loaded |
Path: C:\WINDOWS\system32\xpsp2res.dll Access: query and write and read and execute
Type: image Baseaddress: 1330000 Size: 2904064 Protection: read write Mapped to pid:
own pid
|
conflicting addresses |
616526974 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole Name: DefaultAccessPermission |
object name not found |
616529503 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName
Name: ComputerName
|
success or wait |
616530602 |
File opened |
Path: \pipe\lsarpc Access: read attributes and synchronize and generic read and generic
write Options: non directory file Attributes: none Content Overwritten: null
|
success or wait |
616531765 |
File other op |
Path: \lsarpc New path: Disposition: PipeInformation Data : unknown |
success or wait |
616532642 |
File other op |
Path: \lsarpc New path: Disposition: CompletionInformation Data : unknown |
success or wait |
616532978 |
File write |
Path: \lsarpc Offset: 0 Length: 72 Value: 05 00 0B 03 10 00 00 00 48 00 00 00 01 00
00 00 B8 10 B8 10 00 00 00 00 01 00 00 00 00 00 01 00 78 57 34 12 34 12 CD AB EF 00
01 23 45 67 89 AB 00 00 00 00 04 5D 88 8A EB 1C C9 11 9F E8 08 00 2B 10 48 60 02 00
00 00
|
success or wait |
616533367 |
File read |
Path: \lsarpc Offset: 0 Length: 1024 Value: 05 00 0C 03 10 00 00 00 44 00 00 00 01
00 00 00 B8 10 B8 10 21 16 00 00 0C 00 5C 50 49 50 45 5C 6C 73 61 73 73 00 00 00 01
00 00 00 00 00 00 00 04 5D 88 8A EB 1C C9 11 9F E8 08 00 2B 10 48 60 02 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00
|
success or wait |
616534090 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........@.......(.....,......................................... |
pending |
616535155 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........t.......\.....9............B..$...d..................................CF..w.tC..2............................ |
pending |
616536718 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........,..........................B..$...d. |
pending |
616537976 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName
Name: ComputerName
|
success or wait |
616541192 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 16FE000
Length: 1000 New Protection: page read and write and page guard New Protection: page
read and write
|
success or wait |
616542761 |
Thread created |
PID: 1160 TID: 1824 EIP: 7C8106F9 EAX: 77E76C7D Imagepath: C:\Program Files\Microsoft
Office\OFFICE11\WINWORD.EXE
|
success or wait |
616543757 |
Thread resumed |
TID: 1824 PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE |
success or wait |
616544573 |
Memory attributes changed |
PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Base: 17FE000
Length: 1000 New Protection: page read and write and page guard New Protection: page
read and write
|
success or wait |
616550397 |
Thread created |
PID: 1160 TID: 1876 EIP: 7C8106F9 EAX: 774FE4DF Imagepath: C:\Program Files\Microsoft
Office\OFFICE11\WINWORD.EXE
|
success or wait |
616551382 |
Thread resumed |
TID: 1876 PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE |
success or wait |
616552192 |
Thread delayed |
Time: -60 TID: 1876 |
user apc |
616557048 |
Message sent |
HWND: 5012E Message: GETICON WParam: 2 LParam: 0 |
success |
616569363 |
Message sent |
HWND: 5012E Message: GETICON WParam: 0 LParam: 0 |
success |
616572792 |
Message sent |
HWND: 5012E Message: GETICON WParam: 1 LParam: 0 |
success |
616573368 |
Message sent |
HWND: 5012E Message: GETICON WParam: 2 LParam: 0 |
success |
616849432 |
Thread created |
PID: 1160 TID: 1788 EIP: 7C8106F9 EAX: 77E76C7D Imagepath: C:\Program Files\Microsoft
Office\OFFICE11\WINWORD.EXE
|
success or wait |
618879093 |
Thread resumed |
TID: 1788 PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE |
success or wait |
618879879 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5EB2502A-8CF1-11D1-BF92-0060081ED811}\ProxyStubClsid32
Name: NULL
|
success or wait |
618881460 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
618882473 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
618883299 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4DB1AD10-3391-11D2-9A33-00C04FA36145}\InProcServer32
Name: InprocServer32
|
object name not found |
618885514 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4DB1AD10-3391-11D2-9A33-00C04FA36145}\InProcServer32
Name: NULL
|
success or wait |
618893990 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4DB1AD10-3391-11D2-9A33-00C04FA36145}
Name: AppID
|
object name not found |
618896350 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
618897996 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
618902532 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4DB1AD10-3391-11D2-9A33-00C04FA36145}\InProcServer32
Name: InprocServer32
|
object name not found |
618904768 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4DB1AD10-3391-11D2-9A33-00C04FA36145}\InProcServer32
Name: NULL
|
success or wait |
618906877 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4DB1AD10-3391-11D2-9A33-00C04FA36145}
Name: AppID
|
object name not found |
618912839 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4DB1AD10-3391-11D2-9A33-00C04FA36145}\InProcServer32
Name: ThreadingModel
|
success or wait |
618915610 |
File opened |
Path: C:\WINDOWS\system32\sti.dll Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
618916774 |
Section loaded |
Path: C:\WINDOWS\system32\sti.dll Access: write and read and execute Type: commit
Baseaddress: 1900000 Size: 69632 Protection: execute Mapped to pid: own pid
|
success or wait |
618917643 |
File opened |
Path: C:\WINDOWS\system32\sti.dll Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
618919662 |
Section loaded |
Path: C:\WINDOWS\system32\sti.dll Access: query and write and read and execute Type:
image Baseaddress: 73BA0000 Size: 77824 Protection: read write Mapped to pid: own
pid
|
success or wait |
618922665 |
Section loaded |
Path: \KnownDlls\CFGMGR32.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
618925381 |
File opened |
Path: C:\WINDOWS\system32\CFGMGR32.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
619003541 |
Section loaded |
Path: C:\WINDOWS\system32\cfgmgr32.dll Access: query and write and read and execute
Type: image Baseaddress: 74AE0000 Size: 28672 Protection: read write Mapped to pid:
own pid
|
success or wait |
619004414 |
Section loaded |
Path: \KnownDlls\setupapi.DLL Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
619006463 |
File opened |
Path: C:\WINDOWS\system32\setupapi.DLL Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
619007007 |
Section loaded |
Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute
Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid:
own pid
|
success or wait |
619007934 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
619018561 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\Setup Name: SystemSetupInProgress |
success or wait |
619018988 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\WPA\PnP Name: seed |
success or wait |
619019831 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\Setup Name: OsLoaderPath |
success or wait |
619020680 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\Setup Name: OsLoaderPath |
success or wait |
619021168 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\Setup Name: SystemPartition |
success or wait |
619022014 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\Setup Name: SystemPartition |
success or wait |
619022461 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: SourcePath |
success or wait |
619023297 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: SourcePath |
success or wait |
619023746 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: ServicePackSourcePath |
success or wait |
619024552 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: ServicePackSourcePath |
success or wait |
619025000 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: ServicePackCachePath |
success or wait |
619025885 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: ServicePackCachePath |
success or wait |
619026384 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: DriverCachePath |
success or wait |
619027250 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: DriverCachePath |
success or wait |
619027692 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion Name: DevicePath |
success or wait |
619028505 |
Mutant created |
Name: unknown |
success or wait |
619029239 |
Mutant created |
Name: unknown |
success or wait |
619029594 |
Mutant created |
Name: unknown |
success or wait |
619029914 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: LogLevel |
success or wait |
619030332 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: LogLevel |
success or wait |
619030777 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: LogPath |
object name not found |
619031276 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName
Name: ComputerName
|
success or wait |
619032334 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters Name: Hostname |
success or wait |
619033208 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters Name: Domain |
success or wait |
619034080 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\StillImage\Logging Name: MaxSize |
object name not found |
619035490 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\StillImage\Logging Name: Level |
object name not found |
619035935 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\StillImage\Logging Name: Mode |
object name not found |
619036365 |
File opened |
Path: C:\WINDOWS\Sti_Trace.log Access: read attributes and synchronize and generic
write Options: synchronous io non alert and non directory file Attributes: normal
Content Overwritten: null
|
success or wait |
619036827 |
File other op |
Path: C:\WINDOWS\Sti_Trace.log New path: Disposition: PositionInformation Data
: Offset: 0
|
success or wait |
619037563 |
Mutant created |
Name: \BaseNamedObjects\StiTraceMutexSti_Trace.log |
access denied |
619038119 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A1F4E726-8CF1-11D1-BF92-0060081ED811}
Name: InsecureQI
|
object name not found |
619422801 |
File opened |
Path: \pipe\lsarpc Access: read attributes and synchronize and generic read and generic
write Options: non directory file Attributes: none Content Overwritten: null
|
success or wait |
619423826 |
File other op |
Path: \lsarpc New path: Disposition: PipeInformation Data : unknown |
success or wait |
619424778 |
File other op |
Path: \lsarpc New path: Disposition: CompletionInformation Data : unknown |
success or wait |
619425164 |
File write |
Path: \lsarpc Offset: 0 Length: 72 Value: 05 00 0B 03 10 00 00 00 48 00 00 00 01 00
00 00 B8 10 B8 10 00 00 00 00 01 00 00 00 00 00 01 00 78 57 34 12 34 12 CD AB EF 00
01 23 45 67 89 AB 00 00 00 00 04 5D 88 8A EB 1C C9 11 9F E8 08 00 2B 10 48 60 02 00
00 00
|
success or wait |
619425605 |
File read |
Path: \lsarpc Offset: 0 Length: 1024 Value: 05 00 0C 03 10 00 00 00 44 00 00 00 01
00 00 00 B8 10 B8 10 24 16 00 00 0C 00 5C 50 49 50 45 5C 6C 73 61 73 73 00 00 00 01
00 00 00 00 00 00 00 04 5D 88 8A EB 1C C9 11 9F E8 08 00 2B 10 48 60 02 00 00 00 48
00 41 00 4E 00 55 00 45 00 4C 00 45 00 2D 00 42 00 43 00 36 00 30 00 37 00 32 00 30
00 52 00
|
success or wait |
619427453 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........@.......(.....,......................................... |
pending |
619428468 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ................p.....D..........."M...#............&.(.................N.T.
.A.U.T.H.O.R.I.T.Y.\.S.Y.S.T.E.M...........................
|
pending |
619430273 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........,........................."M...#.... |
pending |
619431275 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........@.......(.....,......................................... |
pending |
619435776 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ................p.....D.........u..C..-f.F..........&.(.................N.T.
.A.U.T.H.O.R.I.T.Y.\.S.Y.S.T.E.M...........................
|
pending |
619437330 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........,.......................u..C..-f.F.. |
pending |
619438311 |
Process information queried |
PID: 1160 Info Class: Times |
success or wait |
619554026 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common Name: QMEnable |
success or wait |
619554352 |
Message posted |
HWND: 5012E Message: 45F WParam: 0 LParam: 0 |
success |
619554796 |
Foreground Window Got |
HWND: 5012E |
success |
619555353 |
Message posted |
TID: 7DC Message: C088 WParam: 0 LParam: 0 |
success |
619555740 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
HideFileExt
|
success or wait |
619562345 |
Window created |
Window Name: _WwB Class Name: _WwB HWND: 80040 |
success |
619573385 |
Message sent |
HWND: 80040 Message: NCCREATE WParam: 0 LParam: 1237124 |
success |
619573674 |
Message sent |
HWND: 80040 Message: NCCALCSIZE WParam: 0 LParam: 1237164 |
error |
619573959 |
Message sent |
HWND: 50136 Message: DDE_ACK WParam: 524352 LParam: 3221864481 |
success |
619574288 |
Key value queried |
Path: HKEY_USERS\Keyboard Layout\Toggle Name: Language Hotkey |
success or wait |
619578793 |
Key value queried |
Path: HKEY_USERS\Keyboard Layout\Toggle Name: Language Hotkey |
success or wait |
619579151 |
Key value queried |
Path: HKEY_USERS\Keyboard Layout\Toggle Name: Layout Hotkey |
success or wait |
619579500 |
Key value queried |
Path: HKEY_USERS\Keyboard Layout\Toggle Name: Layout Hotkey |
success or wait |
619580997 |
Message posted |
TID: 7DC Message: C0C3 WParam: 0 LParam: 1768 |
success |
619581993 |
Message posted |
TID: 7DC Message: C0C3 WParam: 0 LParam: 1768 |
success |
619583345 |
Message posted |
TID: 7DC Message: C0C3 WParam: 0 LParam: 1768 |
success |
619585401 |
Message posted |
TID: 7DC Message: C0C3 WParam: 0 LParam: 1768 |
success |
619588442 |
Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IOG..LMIJC Access: query and
write and read Type: commit Baseaddress: 1900000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
619589414 |
Message sent |
HWND: 5012E Message: 88 WParam: 4 LParam: 0 |
error |
619592198 |
Message sent |
HWND: 5012E Message: NCPAINT WParam: 1 LParam: 0 |
error |
619592384 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
619593543 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
619600004 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
619600312 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
619601132 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
619601412 |
Mutant created |
Name: \BaseNamedObjects\MSCTF.Shared.MUTEX.MNH |
object name exists |
619606754 |
Section loaded |
Path: \BaseNamedObjects\MSCTF.Shared.SFM.MNH Access: query and write and read and
execute and extend size Type: unknown Baseaddress: 1910000 Size: 524288 Protection:
read write Mapped to pid: own pid
|
success or wait |
619607200 |
Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IOG.B.LNIJC Access: query and
write and read Type: commit Baseaddress: 1900000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
619608760 |
Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IOG.C.LNIJC Access: query and
write and read Type: commit Baseaddress: 1990000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
619609466 |
Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IOG.D.LNIJC Access: query and
write and read Type: commit Baseaddress: 19A0000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
619610187 |
Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IOG.E.LNIJC Access: query and
write and read Type: commit Baseaddress: 1900000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
619615802 |
Message sent |
HWND: 5012E Message: PAINT WParam: 0 LParam: 0 |
error |
619619975 |
Message sent |
HWND: 90058 Message: PAINT WParam: 0 LParam: 0 |
error |
619622208 |
Message sent |
HWND: 90058 Message: PAINT WParam: 0 LParam: 0 |
error |
619622486 |
Section loaded |
Path: \BaseNamedObjects\Local\Mso97SharedDg19521108172 Access: query and write and
read and execute and extend size Type: unknown Baseaddress: unknown Size: unknown
Protection: unknown Mapped to pid: unknown
|
object name not found |
619632632 |
Section loaded |
Path: \BaseNamedObjects\Local\Mso97SharedDg19521108172 Access: query and write and
read Type: reserve Baseaddress: 19B0000 Size: 126976 Protection: read write Mapped
to pid: own pid
|
success or wait |
619632878 |
Mutant created |
Name: \BaseNamedObjects\Local\Mso97SharedDg19521108172Mutex |
success or wait |
619633670 |
Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IOG.F.KOIJC Access: query and
write and read Type: commit Baseaddress: 1900000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
619688086 |
Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IOG.G.KOIJC Access: query and
write and read Type: commit Baseaddress: 1900000 Size: 4096 Protection: read write
Mapped to pid: own pid
|
success or wait |
619691693 |
Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MNH.CB.KPIJC Access: query
and write and read and execute and extend size Type: unknown Baseaddress: 1900000
Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
619719769 |
Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MNH.DB.KPIJC Access: query
and write and read and execute and extend size Type: unknown Baseaddress: 1900000
Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
619720827 |
Section loaded |
Path: \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MNH.EB.KPIJC Access: query
and write and read and execute and extend size Type: unknown Baseaddress: 1900000
Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
619722526 |
Section loaded |
Path: \BaseNamedObjects\Local\Mso97SharedDg19521108172 Access: query and write and
read and execute and extend size Type: unknown Baseaddress: 1990000 Size: 126976 Protection:
read write Mapped to pid: own pid
|
success or wait |
619740946 |
Section loaded |
Path: \BaseNamedObjects\Local\Mso97SharedDg19531108172 Access: query and write and
read and execute and extend size Type: unknown Baseaddress: unknown Size: unknown
Protection: unknown Mapped to pid: unknown
|
object name not found |
619742602 |
Section loaded |
Path: \BaseNamedObjects\Local\Mso97SharedDg19531108172 Access: query and write and
read Type: reserve Baseaddress: 1990000 Size: 126976 Protection: read write Mapped
to pid: own pid
|
success or wait |
619742897 |
Mutant created |
Name: \BaseNamedObjects\Local\Mso97SharedDg19531108172Mutex |
success or wait |
619744645 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
619767341 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
619767536 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\BaseSuite Name: 1EBDE4BC9A514630B5412561FA45CCC5 |
object name not found |
619771775 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\InstallRoot Name: InstallCount |
success or wait |
619775486 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Licensing Name: 1EBDE4BC9A514630B5412561FA45CCC5 |
object name not found |
619775913 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\ProductVersion Name:
ProInfo
|
success or wait |
619776394 |
Foreground Window Got |
HWND: 5012E |
success |
619793558 |
Foreground Window Got |
HWND: 5012E |
success |
619793750 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
619802998 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: NoTrack |
object name not found |
619804187 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: NoNetHood
|
object name not found |
619805670 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoNetHood
|
object name not found |
619806383 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: NoPropertiesMyComputer
|
object name not found |
619807058 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoPropertiesMyComputer
|
object name not found |
619808497 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: NoInternetIcon
|
object name not found |
619809169 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoInternetIcon
|
object name not found |
619809798 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: NoCommonGroups
|
object name not found |
619810962 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoCommonGroups
|
object name not found |
619813077 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Name: Desktop
|
success or wait |
619814906 |
Key value replaced with same |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Name: Desktop Type: unicode Data: C:\Documents and Settings\Administrator\Desktop
Old data:
|
success or wait |
619817084 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: NoControlPanel
|
object name not found |
619818893 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoControlPanel
|
object name not found |
619819705 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: NoSetFolders
|
object name not found |
619820552 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoSetFolders
|
object name not found |
619823770 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32
Name: NULL
|
success or wait |
619825009 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
619825911 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........@.......(.....,......................................... |
pending |
619826807 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........j.......R............{....}K.>\.....*.,.................S.e.L.o.a.d.D.r.i.v.e.r.P.r.i.v.i.l.e.g.e. |
pending |
619828377 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........,....................{....}K.>\..... |
pending |
619829394 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........@.......(.....,......................................... |
pending |
619830382 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........b.......J...........!..:."fO........".$.................S.e.U.n.d.o.c.k.P.r.i.v.i.l.e.g.e. |
pending |
619831771 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........,...................!..:."fO........ |
pending |
619832688 |
Privilege adjusted |
Privilege: Load Driver On or off: on |
success or wait |
619833537 |
Privilege adjusted |
Privilege: Load Driver On or off: on |
success or wait |
619840933 |
File opened |
Path: IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#42562d3231303037333036372020202020202020#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Access: read attributes and synchronize Options: synchronous io non alert and non
directory file Overwritten: false
|
success or wait |
619848177 |
File opened |
Path: IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#42562d3231303037333036372020202020202020#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Access: read attributes and synchronize Options: synchronous io non alert and non
directory file Overwritten: false
|
success or wait |
619850742 |
File opened |
Path: MountPointManager Access: read attributes and synchronize Options: synchronous
io non alert and non directory file Attributes: normal Content Overwritten: true
|
success or wait |
619853818 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{811e0202-1746-11df-8a4d-806d6172696f}
Name: Data
|
buffer overflow |
619859989 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{811e0202-1746-11df-8a4d-806d6172696f}
Name: Data
|
success or wait |
619861869 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{811e0202-1746-11df-8a4d-806d6172696f}
Name: Generation
|
success or wait |
619863439 |
File opened |
Path: STORAGE#Volume#1&30a96598&0&SignatureF4ACF4ACOffset7E00Length3BFEFCE00#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Access: read attributes and synchronize Options: synchronous io non alert and non
directory file Overwritten: false
|
success or wait |
619864161 |
File opened |
Path: STORAGE#Volume#1&30a96598&0&SignatureF4ACF4ACOffset7E00Length3BFEFCE00#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Access: read attributes and synchronize Options: synchronous io non alert and non
directory file Overwritten: false
|
success or wait |
619865858 |
File opened |
Path: MountPointManager Access: read attributes and synchronize Options: synchronous
io non alert and non directory file Attributes: normal Content Overwritten: true
|
success or wait |
619868066 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{0d6ab97b-ade6-11de-bdcc-806d6172696f}
Name: Data
|
buffer overflow |
619872258 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{0d6ab97b-ade6-11de-bdcc-806d6172696f}
Name: Data
|
success or wait |
619872723 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{0d6ab97b-ade6-11de-bdcc-806d6172696f}
Name: Generation
|
success or wait |
619874298 |
File opened |
Path: MountPointManager Access: read attributes and synchronize Options: synchronous
io non alert and non directory file Attributes: normal Content Overwritten: true
|
success or wait |
619874994 |
File opened |
Path: MountPointManager Access: read attributes and synchronize Options: synchronous
io non alert and non directory file Attributes: normal Content Overwritten: true
|
success or wait |
619879691 |
Key value replaced with same |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0d6ab97b-ade6-11de-bdcc-806d6172696f}
Name: BaseClass Type: unicode Data: Drive Old data:
|
success or wait |
619884674 |
File opened |
Path: MountPointManager Access: read attributes and synchronize Options: synchronous
io non alert and non directory file Attributes: normal Content Overwritten: true
|
success or wait |
619885231 |
File opened |
Path: MountPointManager Access: read attributes and synchronize Options: synchronous
io non alert and non directory file Attributes: normal Content Overwritten: true
|
success or wait |
619889776 |
Key value replaced with same |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{811e0202-1746-11df-8a4d-806d6172696f}
Name: BaseClass Type: unicode Data: Drive Old data:
|
success or wait |
619894947 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
619895438 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
619895742 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
619896030 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{0d6ab97b-ade6-11de-bdcc-806d6172696f}
Name: Generation
|
success or wait |
619896858 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
619897529 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: DontShowSuperHidden
|
object name not found |
619900785 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
DontShowSuperHidden
|
object name not found |
619902100 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer Name: ShellState |
success or wait |
619903061 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer Name: ShellState |
success or wait |
619903494 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: ForceActiveDesktopOn
|
object name not found |
619904316 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
ForceActiveDesktopOn
|
object name not found |
619905121 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: NoActiveDesktop
|
object name not found |
619906015 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoActiveDesktop
|
object name not found |
619906819 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: NoWebView
|
object name not found |
619907737 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoWebView
|
object name not found |
619908547 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: ClassicShell
|
object name not found |
619909387 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
ClassicShell
|
object name not found |
619910193 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: SeparateProcess
|
object name not found |
619911067 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
SeparateProcess
|
object name not found |
619911872 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: NoNetCrawling
|
object name not found |
619912761 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoNetCrawling
|
object name not found |
619913566 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: NoSimpleStartMenu
|
object name not found |
619914406 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoSimpleStartMenu
|
object name not found |
619915210 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
Hidden
|
success or wait |
619916068 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
ShowCompColor
|
success or wait |
619916491 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
HideFileExt
|
success or wait |
619916909 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
DontPrettyPath
|
success or wait |
619917350 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
ShowInfoTip
|
success or wait |
619917770 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
HideIcons
|
success or wait |
619918240 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
MapNetDrvBtn
|
success or wait |
619918660 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
WebView
|
success or wait |
619919113 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
Filter
|
success or wait |
619919531 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
ShowSuperHidden
|
success or wait |
619919949 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
SeparateProcess
|
success or wait |
619920440 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
NoNetCrawling
|
success or wait |
619920863 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory Name: DocObject |
object name not found |
619922370 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory Name: BrowseInPlace |
object name not found |
619923172 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory Name: IsShortcut |
object name not found |
619924844 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory Name: AlwaysShowExt |
success or wait |
619925642 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory Name: NeverShowExt |
object name not found |
619926441 |
File opened |
Path: C:\Documents and Settings\ Access: read data or list directory and synchronize
Options: directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
619927468 |
File opened |
Path: C:\Documents and Settings\Administrator\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
619928901 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
619930427 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
619930678 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
619930923 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
619931165 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
619931688 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
619931892 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
619932088 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
619938898 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
619939162 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{0d6ab97b-ade6-11de-bdcc-806d6172696f}
Name: Generation
|
success or wait |
619939981 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
Name: DriveMask
|
success or wait |
619941269 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
619941829 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
619942344 |
File opened |
Path: C:\Documents and Settings\ Access: read data or list directory and synchronize
Options: directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
619943631 |
File opened |
Path: C:\Documents and Settings\Administrator\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
619945509 |
File opened |
Path: C:\Documents and Settings\Administrator\Desktop\ Access: read data or list
directory and synchronize Options: directory file and synchronous io non alert and
open for backup ident Overwritten: false
|
success or wait |
619946882 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: AllowFileCLSIDJunctions
|
object name not found |
619948406 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
AllowFileCLSIDJunctions
|
object name not found |
619949105 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
619949756 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
619950011 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{0d6ab97b-ade6-11de-bdcc-806d6172696f}
Name: Generation
|
success or wait |
619950750 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
Name: DriveMask
|
success or wait |
619952016 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
619952524 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
619953028 |
File opened |
Path: C:\Documents and Settings\ Access: read data or list directory and synchronize
Options: directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
619954387 |
File opened |
Path: C:\Documents and Settings\Administrator\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
619955714 |
File opened |
Path: C:\Documents and Settings\Administrator\Desktop\ Access: read data or list
directory and synchronize Options: directory file and synchronous io non alert and
open for backup ident Overwritten: false
|
success or wait |
619957848 |
Key created |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency |
success or wait |
619967795 |
Key created |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems |
success or wait |
619968829 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems Name:
9
|
object name not found |
619969814 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems Name:
9 Type: binary Data: 39 19 02 00 88 04 00 00 06 00 00 00 01 00 00 00 9A 00 00 00
02 00 00 00 8A 00 00 00 04 00 00 00 63 00 3A 00 5C 00 64 00 6F 00 63 00 75 00 6D 00
65 00 6E 00 74 00 73 00 20 00 61 00 6E 00 64 00 20 00 73 00 65 00 74 00 74 00 69 00
6E 00 67 00 73 00 5C 00 61 00 64 00 6D 00 69 00 6E 00 69 00 73 00 74 00 72 00 61 00
74 00 6F 00 72 00 5C 00 64 00 65 00 73 00 6B 00 74 00 6F 00 70 00 5C 00 69 00 70 00
68 00 6F 00 6E 00 65 00 20 00 35 00 20 00 62 00 61 00 74 00 74 00 65 00 72 00 79 00
2E 00 64 00 6F 00 63 00 00 00 00 00 00 00 Old data:
|
success or wait |
619970272 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
HideFileExt
|
success or wait |
619971211 |
Section loaded |
Path: \BaseNamedObjects\DfSharedHeap37B58 Access: query and write and read Type: reserve
Baseaddress: 19D0000 Size: 4194304 Protection: read write Mapped to pid: own pid
|
success or wait |
619972088 |
File opened |
Path: C:\Documents and Settings\Administrator\Desktop\iPhone 5 Battery.doc Access:
read attributes and synchronize and generic read and generic write Options: synchronous
io non alert and non directory file Attributes: normal Content Overwritten: true
|
success or wait |
619973334 |
System info queried |
Type: PerformanceInformation |
success or wait |
619974220 |
Process information queried |
PID: 1160 Info Class: QuotaLimits |
success or wait |
619974629 |
Process information queried |
PID: 1160 Info Class: VmCounters |
success or wait |
619974841 |
Section loaded |
Path: \BaseNamedObjects\DFMap0-228188 Access: query and write and read Type: commit
Baseaddress: 1DD0000 Size: 598016 Protection: read write Mapped to pid: own pid
|
success or wait |
619975102 |
Section loaded |
Path: \BaseNamedObjects\DfRoot000037B58 Access: query and write and read Type: commit
Baseaddress: 1E70000 Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
619976566 |
File created |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF7B61.tmp Access: read attributes and delete
and synchronize and generic read and generic write Options: synchronous io non alert
and non directory file and delete on close Attributes: temporary Content Overwritten:
true
|
success or wait |
619978138 |
File other op |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF7B61.tmp New path: Disposition: PositionInformation
Data : Offset: 512
|
success or wait |
619984792 |
File other op |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF7B61.tmp New path: Disposition: EndOfFileInformation
Data : unknown
|
success or wait |
619985018 |
File other op |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF7B61.tmp New path: Disposition: AllocationInformation
Data : unknown
|
success or wait |
619989517 |
File other op |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF7B61.tmp New path: Disposition: PositionInformation
Data : Offset: 0
|
success or wait |
619990167 |
System info queried |
Type: PerformanceInformation |
success or wait |
619990362 |
Process information queried |
PID: 1160 Info Class: QuotaLimits |
success or wait |
619990816 |
Process information queried |
PID: 1160 Info Class: VmCounters |
success or wait |
619991028 |
Section loaded |
Path: \BaseNamedObjects\DFMap0-228204 Access: query and write and read Type: commit
Baseaddress: 1E80000 Size: 524288 Protection: read write Mapped to pid: own pid
|
success or wait |
619991315 |
File created |
Path: C:\Documents and Settings\Administrator\Desktop\~$hone 5 Battery.doc Access:
read attributes and synchronize and generic write Options: synchronous io non alert
and non directory file and open no recall Attributes: hidden Content Overwritten:
true
|
success or wait |
619994472 |
File write |
Path: C:\Documents and Settings\Administrator\Desktop\~$hone 5 Battery.doc Offset:
unknown Length: 54 Value: 0D 48 61 6E 75 65 6C 65 20 42 61 73 65 72 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00
|
success or wait |
619999738 |
File write |
Path: C:\Documents and Settings\Administrator\Desktop\~$hone 5 Battery.doc Offset:
unknown Length: 108 Value: 0D 00 48 00 61 00 6E 00 75 00 65 00 6C 00 65 00 20 00 42
00 61 00 73 00 65 00 72 00 00 00 00 00 1E 00 00 00 0D 00 48 00 61 00 6E 00 75 00 65
00 6C 00 65 00 20 00 42 00 61 00 73 00 65 00 72 00 00 00 00 00 16 00 00 00 40 00 08
00 36 01 05 00 A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1A 00 00 00
|
success or wait |
620000901 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows NT\CurrentVersion\Windows Name: Device |
success or wait |
620003646 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows NT\CurrentVersion\Devices Name: Microsoft
XPS Document Writer
|
success or wait |
620004090 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows NT\CurrentVersion\Windows Name: Device |
success or wait |
620004583 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows NT\CurrentVersion\Devices Name: Microsoft
XPS Document Writer
|
success or wait |
620004992 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: PrinterHangTimeOut |
object name not found |
620005689 |
Thread created |
PID: 1160 TID: 1980 EIP: 7C8106F9 EAX: 30D5382C Imagepath: C:\Program Files\Microsoft
Office\OFFICE11\WINWORD.EXE
|
success or wait |
620006879 |
Thread resumed |
TID: 1980 PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE |
success or wait |
620007684 |
Section loaded |
Path: \KnownDlls\winspool.drv Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
620011349 |
File opened |
Path: C:\WINDOWS\system32\winspool.drv Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
620012073 |
Section loaded |
Path: C:\WINDOWS\system32\winspool.drv Access: query and write and read and execute
Type: image Baseaddress: 73000000 Size: 155648 Protection: read write Mapped to pid:
own pid
|
success or wait |
620012873 |
System info queried |
Type: BasicInformation |
success or wait |
620018608 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620025033 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620026055 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620026941 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620027129 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\unidrvui.dll Access: execute or
traverse and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
success or wait |
620070031 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\unidrvui.dll Access: write and read
and execute Type: commit Baseaddress: 2020000 Size: 745472 Protection: execute Mapped
to pid: own pid
|
success or wait |
620070893 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\unidrvui.dll Access: execute or
traverse and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
success or wait |
620074615 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\unidrvui.dll Access: query and write
and read and execute Type: image Baseaddress: 7E5A0000 Size: 761856 Protection: read
write Mapped to pid: own pid
|
success or wait |
620075441 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620091180 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620092763 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620094027 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2020000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
620096175 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620099761 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620101554 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620109913 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2030000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
620111037 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
620112689 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620114301 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2030000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
620115129 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620118936 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
620119817 |
System info queried |
Type: BasicInformation |
success or wait |
620132301 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620133452 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620133747 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620133972 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620134196 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620134420 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620134696 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620134921 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620135154 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620135919 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620136161 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620136395 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620136627 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620136860 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620137092 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620137322 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620137553 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620137785 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620138855 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620139097 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620139332 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620139564 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620139795 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620140018 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620140307 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620141222 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620141993 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620142215 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620142432 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620142650 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620142867 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620143085 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620143302 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620143519 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620143737 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620145585 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620145817 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620146338 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620146555 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620146781 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620147850 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620148335 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620149820 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620150009 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620151805 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620152280 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620155129 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2020000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
620156939 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620157913 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620159666 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620163420 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2030000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
620164267 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
620166426 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620166883 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2030000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
620167703 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620169936 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
620170757 |
System info queried |
Type: BasicInformation |
success or wait |
620179431 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620180581 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620180875 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620181101 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620181325 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620182359 |
Process information queried |
PID: 1160 Info Class: Cookie |
success or wait |
620182591 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620191982 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620192888 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620193339 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620194311 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2020000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
620195188 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620196245 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620197471 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620201213 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2030000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
620202607 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
620203867 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620204314 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2030000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
620205182 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620206781 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
620207597 |
System info queried |
Type: BasicInformation |
success or wait |
620214355 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620229601 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620230512 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620231471 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620231915 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620232860 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2020000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
620233730 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620234731 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620236040 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620239795 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2030000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
620240691 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
620241946 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620242393 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2030000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
620243207 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620245310 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
620246120 |
System info queried |
Type: BasicInformation |
success or wait |
620252380 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620339431 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620673192 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620674682 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620675155 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620676135 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2020000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
620677270 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620678234 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620679463 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620683247 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2030000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
620684089 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
620685342 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620685790 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2030000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
620686606 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620688255 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
620689111 |
System info queried |
Type: BasicInformation |
success or wait |
620695359 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620708523 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620709437 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620710325 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620710796 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620711832 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2020000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
620712699 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620713650 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620714924 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620719603 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2030000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
620720451 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
620721702 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620722148 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2030000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
620722957 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620724570 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
620725382 |
System info queried |
Type: BasicInformation |
success or wait |
620731786 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\unires.dll Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620745881 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\unires.dll Access: write and read
and execute Type: commit Baseaddress: 2040000 Size: 761856 Protection: execute Mapped
to pid: own pid
|
success or wait |
620746736 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\unires.dll Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620750863 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\unires.dll Access: query and write
and read and execute Type: image Baseaddress: 2040000 Size: 765952 Protection: read
write Mapped to pid: own pid
|
conflicting addresses |
620751705 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620757901 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620758808 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620760207 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620760718 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620761661 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2020000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
620762533 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620763493 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620764768 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620768515 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2030000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
620769406 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
620770647 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620771090 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2030000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
620772232 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620773831 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
620774705 |
System info queried |
Type: BasicInformation |
success or wait |
620780919 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\unires.dll Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620792851 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\unires.dll Access: write and read
and execute Type: commit Baseaddress: 2040000 Size: 761856 Protection: execute Mapped
to pid: own pid
|
success or wait |
620793698 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\unires.dll Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620795469 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\unires.dll Access: query and write
and read and execute Type: image Baseaddress: 2040000 Size: 765952 Protection: read
write Mapped to pid: own pid
|
conflicting addresses |
620796308 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620801745 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdrv.dll Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620803475 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdrv.dll Access: write and read
and execute Type: commit Baseaddress: 2020000 Size: 765952 Protection: execute Mapped
to pid: own pid
|
success or wait |
620804301 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdrv.dll Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620806204 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdrv.dll Access: query and write
and read and execute Type: image Baseaddress: 3F500000 Size: 786432 Protection: read
write Mapped to pid: own pid
|
success or wait |
620807110 |
System info queried |
Type: BasicInformation |
success or wait |
620814419 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620835509 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620835702 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620836675 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620837146 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620838104 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2030000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
620838994 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620839984 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620841228 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620845004 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2040000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
620846386 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
620847694 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620848154 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2040000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
620848981 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620850629 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
620851455 |
System info queried |
Type: BasicInformation |
success or wait |
620857981 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620870352 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620870550 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620871472 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620871931 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620872898 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2030000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
620873782 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620874818 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620876085 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620879851 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2040000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
620880701 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
620882057 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620882519 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2040000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
620883266 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620885341 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
620886170 |
System info queried |
Type: BasicInformation |
success or wait |
620893208 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620910495 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620910712 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620911630 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620912113 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620913062 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2430000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
620914014 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620915184 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620916463 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620920318 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2440000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
620921187 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
620922549 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620923023 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2440000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
620923862 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620925571 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
620926413 |
System info queried |
Type: BasicInformation |
success or wait |
620934493 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620948304 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620948514 |
Process information queried |
PID: 1160 Info Class: Wow64Information |
success or wait |
620949447 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620950908 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2430000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
620951807 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620952876 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620954143 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620957731 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2440000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
620958598 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
620959973 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620960446 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2440000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
620961336 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620963033 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
620963869 |
System info queried |
Type: BasicInformation |
success or wait |
620970624 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620986577 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2430000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
620987477 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620988596 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620989952 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
620993834 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2440000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
620994702 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
620996465 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620996943 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2440000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
620997788 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
620999490 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621000510 |
System info queried |
Type: BasicInformation |
success or wait |
621007358 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621026731 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2430000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
621027663 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621028745 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621030019 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621033865 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2440000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
621034740 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
621036089 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621036556 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2440000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
621037394 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621039146 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621039986 |
System info queried |
Type: BasicInformation |
success or wait |
621046754 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621063726 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2430000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
621064628 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621065700 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621066968 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621070822 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2440000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
621071693 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
621073040 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621073514 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2440000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
621074351 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621076101 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621076968 |
System info queried |
Type: BasicInformation |
success or wait |
621083808 |
File opened |
Path: C:\WINDOWS\system32\FontSub.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
621111067 |
Section loaded |
Path: C:\WINDOWS\system32\fontsub.dll Access: write and read and execute Type: commit
Baseaddress: 2430000 Size: 81920 Protection: execute Mapped to pid: own pid
|
success or wait |
621111858 |
File opened |
Path: C:\WINDOWS\system32\FontSub.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
621116960 |
Section loaded |
Path: C:\WINDOWS\system32\fontsub.dll Access: query and write and read and execute
Type: image Baseaddress: 69310000 Size: 94208 Protection: read write Mapped to pid:
own pid
|
success or wait |
621117777 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621138328 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2430000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
621139303 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621140339 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621141582 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621145418 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2440000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
621146824 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
621148128 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621148590 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2440000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
621149415 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621151064 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621151890 |
System info queried |
Type: BasicInformation |
success or wait |
621158417 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621173932 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2430000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
621174841 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621175868 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621177111 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621180903 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2440000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
621181761 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
621183065 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621183524 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2440000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
621184348 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621185990 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621186812 |
System info queried |
Type: BasicInformation |
success or wait |
621193847 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621211096 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 2430000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
621211982 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621213013 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621214257 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621218068 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 2440000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
621218848 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
621222474 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621222942 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 2440000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
621223773 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621226451 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621227385 |
System info queried |
Type: BasicInformation |
success or wait |
621237849 |
Message posted |
TID: 7DC Message: C08C WParam: 0 LParam: 1980 |
success |
621258851 |
Thread terminated |
TID: 1980 PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE |
unknown |
621260366 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621273635 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
621275880 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621276857 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621278131 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621281950 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
621282801 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
621284306 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621284761 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
621285580 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621287193 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621288009 |
System info queried |
Type: BasicInformation |
success or wait |
621294435 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621311409 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
621312282 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621313292 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621314623 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621318927 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
621319780 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
621321107 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621321560 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
621322381 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621324002 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621324819 |
System info queried |
Type: BasicInformation |
success or wait |
621331230 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621350889 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
621351829 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621352793 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621354545 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621358336 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
621359182 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
621360995 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621361448 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
621362781 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621364407 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621365225 |
System info queried |
Type: BasicInformation |
success or wait |
621372590 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621391663 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
621392532 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621393577 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621394796 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621398546 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
621399391 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
621400637 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621401079 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
621401939 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621404050 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621404863 |
System info queried |
Type: BasicInformation |
success or wait |
621411007 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621427181 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
621428045 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621429068 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621430290 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621434076 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
621434986 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
621436234 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621436679 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
621437491 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621439073 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621439880 |
System info queried |
Type: BasicInformation |
success or wait |
621447058 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoWideTextPrinting |
object name not found |
621460232 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoWideTextPrinting |
object name not found |
621460863 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621464789 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
621465748 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621466698 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621467960 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621471721 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
621472554 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
621473841 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621474288 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
621475139 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621476729 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621477539 |
System info queried |
Type: BasicInformation |
success or wait |
621483717 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\unires.dll Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621497426 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\unires.dll Access: write and read
and execute Type: commit Baseaddress: 1F20000 Size: 761856 Protection: execute Mapped
to pid: own pid
|
success or wait |
621498273 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\unires.dll Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621500201 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\unires.dll Access: query and write
and read and execute Type: image Baseaddress: 1F20000 Size: 765952 Protection: read
write Mapped to pid: own pid
|
conflicting addresses |
621501088 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621511851 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
621512722 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621514462 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621515686 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621519456 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
621520298 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
621521976 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621522421 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
621523229 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621524868 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621525678 |
System info queried |
Type: BasicInformation |
success or wait |
621533879 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\unires.dll Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621547175 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\unires.dll Access: write and read
and execute Type: commit Baseaddress: 1F20000 Size: 761856 Protection: execute Mapped
to pid: own pid
|
success or wait |
621548021 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\unires.dll Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621549827 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\unires.dll Access: query and write
and read and execute Type: image Baseaddress: 1F20000 Size: 765952 Protection: read
write Mapped to pid: own pid
|
conflicting addresses |
621550659 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621561498 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
621562369 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621563316 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621564776 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621568540 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
621569380 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
621570623 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621571811 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
621572619 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621574201 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621575540 |
System info queried |
Type: BasicInformation |
success or wait |
621583209 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\unires.dll Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621596543 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\unires.dll Access: write and read
and execute Type: commit Baseaddress: 1F20000 Size: 761856 Protection: execute Mapped
to pid: own pid
|
success or wait |
621597395 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\unires.dll Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
621599232 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\unires.dll Access: query and write
and read and execute Type: image Baseaddress: 1F20000 Size: 765952 Protection: read
write Mapped to pid: own pid
|
conflicting addresses |
621600067 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621607922 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
621608875 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621609910 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621611803 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621617011 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
621618408 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
621619783 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
621621103 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621625406 |
System info queried |
Type: BasicInformation |
success or wait |
621633328 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621650213 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
621651113 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621652144 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621653420 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621657280 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
621658156 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
621659517 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
621661415 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621663966 |
System info queried |
Type: BasicInformation |
success or wait |
621671146 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621692009 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
621693038 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621694157 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621695455 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621699298 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
621700176 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
621701568 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
621702904 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621706044 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621730075 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
621730984 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621732068 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621733401 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621737234 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
621738111 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
621739505 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
621740837 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621743528 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621768602 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
621769525 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621770637 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621772013 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621775905 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
621776803 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
621778512 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
621779890 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621782764 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621807896 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
621808820 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621809933 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621811255 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621815172 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
621816110 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
621817570 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
621818979 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621821666 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621846977 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
621847902 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621849018 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621850345 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621854200 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
621855148 |
Process information queried |
PID: 1160 Info Class: DefaultHardErrorMode |
success or wait |
621856613 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
621857994 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621860682 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621888872 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
621889795 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621891363 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621892694 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
621896551 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
621897447 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
621900492 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
621903229 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622312474 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
622313430 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622314595 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622315929 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622319864 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
622320764 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
622323665 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
622326341 |
File opened |
Path: C:\WINDOWS\system32\FontSub.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
622352459 |
Section loaded |
Path: C:\WINDOWS\system32\fontsub.dll Access: write and read and execute Type: commit
Baseaddress: 1F00000 Size: 81920 Protection: execute Mapped to pid: own pid
|
success or wait |
622353269 |
File opened |
Path: C:\WINDOWS\system32\FontSub.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
622354909 |
Section loaded |
Path: C:\WINDOWS\system32\fontsub.dll Access: query and write and read and execute
Type: image Baseaddress: 69310000 Size: 94208 Protection: read write Mapped to pid:
own pid
|
success or wait |
622355758 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622364540 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
622365445 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622366608 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622367897 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622371730 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
622372818 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
622375611 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
622378250 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622402326 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
622403325 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622404433 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622405772 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622409604 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
622410479 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
622413205 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
622415793 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622439224 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
622440129 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622441281 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622442574 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622446451 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
622447328 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
622450069 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
622452906 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622480311 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
622481179 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622482124 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622483336 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622487248 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
622488092 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
622490588 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
622493006 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622515850 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
622516716 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622517662 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622518929 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622523262 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
622524102 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
622526594 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
622529015 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoWideTextPrinting |
object name not found |
622917390 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoWideTextPrinting |
object name not found |
622917975 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622924387 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
622925271 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622926320 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622927543 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622931328 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
622932171 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
622934699 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
622937091 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622961016 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
622961972 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622962915 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622964172 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
622967929 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
622968766 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
622971250 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
622973629 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoWideTextPrinting |
object name not found |
622993401 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoWideTextPrinting |
object name not found |
622993984 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows NT\CurrentVersion\Windows Name: Device |
success or wait |
622997204 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows NT\CurrentVersion\Devices Name: Microsoft
XPS Document Writer
|
success or wait |
622997645 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623002312 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
623003183 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623004135 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623005354 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623012171 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
623013029 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
623015810 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
623018216 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623040129 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
623041002 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623041961 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623043183 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623046951 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
623047792 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
623050297 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
623052739 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623073127 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
623074000 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623074951 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623076226 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623080512 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
623081361 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
623083865 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
623086263 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623111691 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
623112568 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623113551 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623114792 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623118558 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
623119408 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
623122184 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
623125339 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623146463 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
623147342 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623148319 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623149556 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623153367 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
623154226 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
623156786 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
623159239 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623182672 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
623183568 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623184587 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623185847 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623189681 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
623190542 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
623193181 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
623195742 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623218335 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
623219231 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623220253 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623221588 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623225451 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
623226322 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
623229002 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
623231520 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623254552 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
623255449 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623256469 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623257833 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623261672 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
623262536 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
623265188 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
623267760 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.BUD Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623293791 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
623295281 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623297108 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\StdNames.gpd Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623298388 |
File opened |
Path: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mxdwdui.ini Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
623302204 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
623303070 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
623307457 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
623310722 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
623335677 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
623343329 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
623346392 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
623350155 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
623384122 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
623391129 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
623393696 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
623396193 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
623424489 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
623431378 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
623433939 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
623436385 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
623458322 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
623465400 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
623468493 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
623470947 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows NT\CurrentVersion\Windows Name: Device |
success or wait |
623502089 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows NT\CurrentVersion\Devices Name: Microsoft
XPS Document Writer
|
success or wait |
623502535 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
623508073 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
623516229 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
623518982 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
623521443 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
623543588 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
623550415 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
623553462 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
623555874 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
623588375 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
623595785 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
623598307 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
623600709 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
623793555 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
623800629 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
623806946 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
623809956 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
624173021 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
624181095 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
624198815 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
624201309 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
624279438 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
624286998 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
624291244 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
624293771 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
624324136 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
624331702 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
624334432 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
624336959 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
624360345 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
624367341 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
624370609 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
624373136 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
624399438 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
624406399 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
624409257 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
624412508 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
624435254 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
624442287 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
624444940 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
624447541 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
624477616 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
624484497 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
624487069 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
624489516 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
624511897 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
624630026 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
624633007 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
624635474 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
624657284 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
624664196 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
624666818 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
624669803 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
624701396 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
624708217 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
624710788 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
624713764 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
624739007 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
624746486 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
624749356 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
624751876 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
624774279 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
624781138 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
624783760 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
624786230 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
624823539 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
624830606 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
624833317 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
624835882 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
624861245 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
624868277 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
624871017 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
624873576 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
624897713 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
624904847 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
624907550 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
624910123 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
624945100 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
624952196 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
624954889 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
624957497 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
625376993 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
625384320 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
625388194 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
625414986 |
File opened |
Path: C:\WINDOWS\system32\prntvpt.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
625473530 |
Section loaded |
Path: C:\WINDOWS\system32\prntvpt.dll Access: write and read and execute Type: commit
Baseaddress: 1F00000 Size: 118784 Protection: execute Mapped to pid: own pid
|
success or wait |
625474334 |
File opened |
Path: C:\WINDOWS\system32\prntvpt.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
625477265 |
Section loaded |
Path: C:\WINDOWS\system32\prntvpt.dll Access: query and write and read and execute
Type: image Baseaddress: 3FB50000 Size: 131072 Protection: read write Mapped to pid:
own pid
|
success or wait |
625478058 |
Section loaded |
Path: \BaseNamedObjects\AtlDebugAllocator_FileMappingNameStatic3_488 Access: query
and write and read Type: reserve Baseaddress: 2430000 Size: 4194304 Protection: read
write Mapped to pid: own pid
|
success or wait |
625493512 |
System info queried |
Type: ProcessorInformation |
success or wait |
625494398 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
625501802 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
625509658 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
625513152 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
625515691 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
625558566 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
625567868 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
625571019 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
625573515 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
625596541 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
625603622 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
625606225 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
625608744 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
625636089 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
625643428 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
625645921 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
625648306 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
625672047 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
625678745 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
625681284 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
625683697 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoWideTextPrinting |
object name not found |
625703897 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoWideTextPrinting |
object name not found |
625704475 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Font Mapping Name: SimSun |
object name not found |
625708758 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
625714825 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
625721718 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
625724298 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
625726767 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
625752313 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
625759292 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
625761916 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
625764426 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
625787394 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
625794391 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
625797071 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
625799616 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
625827294 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
625835058 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
625837802 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
625840405 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
625865010 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
625872640 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
625875391 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
625878000 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
625902076 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
625909189 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
625911935 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
625915074 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
625943254 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
625950434 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
625953234 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
625955850 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
625980647 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
625987791 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
625990539 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
625993148 |
File opened |
Path: C:\WINDOWS\system32\prntvpt.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
626022501 |
Section loaded |
Path: C:\WINDOWS\system32\prntvpt.dll Access: write and read and execute Type: commit
Baseaddress: 1F00000 Size: 118784 Protection: execute Mapped to pid: own pid
|
success or wait |
626023305 |
File opened |
Path: C:\WINDOWS\system32\prntvpt.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
626024940 |
Section loaded |
Path: C:\WINDOWS\system32\prntvpt.dll Access: query and write and read and execute
Type: image Baseaddress: 3FB50000 Size: 131072 Protection: read write Mapped to pid:
own pid
|
success or wait |
626025722 |
Section loaded |
Path: \BaseNamedObjects\AtlDebugAllocator_FileMappingNameStatic3_488 Access: query
and write and read Type: reserve Baseaddress: 2430000 Size: 4194304 Protection: read
write Mapped to pid: own pid
|
success or wait |
626034671 |
System info queried |
Type: ProcessorInformation |
success or wait |
626035552 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
626040429 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
626047993 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
626050649 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
626053182 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
626076244 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
626083185 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
626087155 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
626089942 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
626112894 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
626119883 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
626122532 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
626125059 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
626153005 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
626159905 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
626162391 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
626164778 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.BUD Access: query and read
Type: commit Baseaddress: 1F00000 Size: 61440 Protection: readonly Mapped to pid:
own pid
|
success or wait |
626188616 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.ini Access: query and read
Type: commit Baseaddress: 1F10000 Size: 4096 Protection: readonly Mapped to pid: own
pid
|
success or wait |
626195342 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: write and read
and execute Type: commit Baseaddress: 1F10000 Size: 200704 Protection: execute Mapped
to pid: own pid
|
success or wait |
626198053 |
Section loaded |
Path: C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll Access: query and write
and read and execute Type: image Baseaddress: 3F960000 Size: 212992 Protection: read
write Mapped to pid: own pid
|
success or wait |
626202174 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoWideTextPrinting |
object name not found |
626222634 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: NoWideTextPrinting |
object name not found |
626223208 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Font Mapping Name: ?? |
object name not found |
626223854 |
Key created |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose |
success or wait |
626225136 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: SimSun |
object name not found |
626225726 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Times New Roman |
object name not found |
626229246 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Times New Roman Type:
binary Data: 02 02 06 03 05 04 05 02 03 04 Old data:
|
success or wait |
626237613 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Arial |
object name not found |
626238669 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Arial Type: binary Data:
02 0B 06 04 02 02 02 02 02 04 Old data:
|
success or wait |
626240791 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Courier New |
object name not found |
626242856 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Courier New Type: binary
Data: 02 07 03 09 02 02 05 02 04 04 Old data:
|
success or wait |
626249452 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Symbol |
object name not found |
626250416 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Symbol Type: binary
Data: 05 05 01 02 01 07 06 02 05 07 Old data:
|
success or wait |
626255905 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Wingdings |
object name not found |
626258683 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Wingdings Type: binary
Data: 05 00 00 00 00 00 00 00 00 00 Old data:
|
success or wait |
626264044 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Mangal |
object name not found |
626265003 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Latha |
object name not found |
626265888 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Sylfaen |
object name not found |
626266814 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Sylfaen Type: binary
Data: 01 0A 05 02 05 03 06 03 03 03 Old data:
|
success or wait |
626272379 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Vrinda |
object name not found |
626273380 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Vrinda Type: binary
Data: 01 01 06 00 01 01 01 01 01 01 Old data:
|
success or wait |
626278733 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Raavi |
object name not found |
626279681 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Shruti |
object name not found |
626280605 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Gautami |
object name not found |
626281510 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Tunga |
object name not found |
626282414 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Estrangelo Edessa |
object name not found |
626283325 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Kartika |
object name not found |
626284234 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Kartika Type: binary
Data: 02 02 05 03 03 04 04 06 02 03 Old data:
|
success or wait |
626290385 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Tahoma |
object name not found |
626291373 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Tahoma Type: binary
Data: 02 0B 06 04 03 05 04 04 02 04 Old data:
|
success or wait |
626294510 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Marlett |
object name not found |
626295463 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Marlett Type: binary
Data: 00 00 00 00 00 00 00 00 00 00 Old data:
|
success or wait |
626296767 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Lucida Console |
object name not found |
626297742 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Lucida Console Type:
binary Data: 02 0B 06 09 04 05 04 02 02 04 Old data:
|
success or wait |
626302296 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Lucida Sans Unicode |
object name not found |
626303245 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Lucida Sans Unicode
Type: binary Data: 02 0B 06 02 03 05 04 02 02 04 Old data:
|
success or wait |
626312410 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Verdana |
object name not found |
626313428 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Verdana Type: binary
Data: 02 0B 06 04 03 05 04 04 02 04 Old data:
|
success or wait |
626319716 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Arial Black |
object name not found |
626320679 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Arial Black Type: binary
Data: 02 0B 0A 04 02 01 02 02 02 04 Old data:
|
success or wait |
626328881 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Comic Sans MS |
object name not found |
626329951 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Comic Sans MS Type:
binary Data: 03 0F 07 02 03 03 02 02 02 04 Old data:
|
success or wait |
626335214 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Impact |
object name not found |
626336207 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Impact Type: binary
Data: 02 0B 08 06 03 09 02 05 02 04 Old data:
|
success or wait |
626341638 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Georgia |
object name not found |
626342642 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Georgia Type: binary
Data: 02 04 05 02 05 04 05 02 03 03 Old data:
|
success or wait |
626348459 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Franklin Gothic Medium |
object name not found |
626349445 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Franklin Gothic Medium
Type: binary Data: 02 0B 06 03 02 01 02 02 02 04 Old data:
|
success or wait |
626355892 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Palatino Linotype |
object name not found |
626356905 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Palatino Linotype Type:
binary Data: 02 04 05 02 05 05 05 03 03 04 Old data:
|
success or wait |
626365132 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Trebuchet MS |
object name not found |
626366142 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Trebuchet MS Type: binary
Data: 02 0B 06 03 02 02 02 02 02 04 Old data:
|
success or wait |
626370933 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Webdings |
object name not found |
626372011 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Webdings Type: binary
Data: 05 03 01 02 01 05 09 06 07 03 Old data:
|
success or wait |
626377034 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: MV Boli |
object name not found |
626378016 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Microsoft Sans Serif |
object name not found |
626378973 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Microsoft Sans Serif
Type: binary Data: 02 0B 06 04 02 02 02 02 02 04 Old data:
|
success or wait |
626388831 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Book Antiqua |
object name not found |
626389895 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Book Antiqua Type: binary
Data: 02 04 06 02 05 03 05 03 03 04 Old data:
|
success or wait |
626396609 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Bookman Old Style |
object name not found |
626397603 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Bookman Old Style Type:
binary Data: 02 05 06 04 05 05 05 02 02 04 Old data:
|
success or wait |
626404453 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Century Gothic |
object name not found |
626405480 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Century Gothic Type:
binary Data: 02 0B 05 02 02 02 02 02 02 04 Old data:
|
success or wait |
626412543 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Garamond |
object name not found |
626413532 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Garamond Type: binary
Data: 02 02 04 04 03 03 01 01 08 03 Old data:
|
success or wait |
626420300 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Monotype Corsiva |
object name not found |
626421694 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Monotype Corsiva Type:
binary Data: 03 01 01 01 01 02 01 01 01 01 Old data:
|
success or wait |
626428374 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Wingdings 2 |
object name not found |
626429922 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Wingdings 2 Type: binary
Data: 05 02 01 02 01 05 07 07 07 07 Old data:
|
success or wait |
626435141 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Wingdings 3 |
object name not found |
626438706 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Wingdings 3 Type: binary
Data: 05 04 01 02 01 08 07 07 07 07 Old data:
|
success or wait |
626443809 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Bookshelf Symbol 7 |
object name not found |
626444804 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Bookshelf Symbol 7 Type:
binary Data: 05 01 01 01 01 01 01 01 01 01 Old data:
|
success or wait |
626450473 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: MS Reference Sans Serif |
object name not found |
626451500 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: MS Reference Sans Serif
Type: binary Data: 02 0B 06 04 03 05 04 04 02 04 Old data:
|
success or wait |
626459046 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: MS Reference Specialty |
object name not found |
626460049 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: MS Reference Specialty
Type: binary Data: 05 00 05 00 00 00 00 00 00 00 Old data:
|
success or wait |
626465816 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Arial Narrow |
object name not found |
626466847 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Panose Name: Arial Narrow Type: binary
Data: 02 0B 06 06 02 02 02 03 02 04 Old data:
|
success or wait |
626473141 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Proofing Tools Name: SpellingWavyUnderlineColor |
object name not found |
626486997 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Shared Tools\Proofing Tools Name: GrammarWavyUnderlineColor |
object name not found |
626487334 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: NoTrack |
object name not found |
626488199 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: MaxPropsStreamSize |
object name not found |
626489658 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
Name: DriveMask
|
success or wait |
626495300 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
626495834 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Name: Recent
|
object name not found |
626497115 |
Section loaded |
Path: \KnownDlls\USERENV.dll Access: write and read and execute Type: unknown Baseaddress:
769C0000 Size: 737280 Protection: read write Mapped to pid: own pid
|
success or wait |
626497891 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Name:
UserEnvDebugLevel
|
object name not found |
626503249 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Name:
ChkAccDebugLevel
|
object name not found |
626504015 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ProductOptions Name: ProductType |
success or wait |
626504789 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Name: Personal
|
success or wait |
626506120 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Name: Local Settings
|
success or wait |
626506524 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Name:
RsopDebugLevel
|
object name not found |
626507533 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Name:
UserEnvDebugLevel
|
object name not found |
626508266 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Name:
RsopLogging
|
object name not found |
626508669 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System Name: UserEnvDebugLevel |
object name not found |
626509461 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System Name: RsopLogging |
object name not found |
626509859 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Name:
UserEnvDebugLevel
|
object name not found |
626510590 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System Name: UserEnvDebugLevel |
object name not found |
626511334 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-507921405-1960408961-839522115-500
Name: ProfileImagePath
|
success or wait |
626512159 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dot
Name: Progid
|
object name not found |
626513549 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dot
Name: Application
|
object name not found |
626514322 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.dot Name: NULL |
success or wait |
626515894 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.dot Name: PerceivedType |
object name not found |
626518598 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Word.Template.8 Name: DocObject |
object name not found |
626519530 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.dot Name: DocObject |
object name not found |
626520241 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Word.Template.8 Name: BrowseInPlace |
object name not found |
626520931 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.dot Name: BrowseInPlace |
object name not found |
626521609 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Word.Template.8\CLSID Name: NULL |
success or wait |
626522686 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Word.Template.8 Name: IsShortcut |
object name not found |
626523681 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.dot Name: IsShortcut |
object name not found |
626524356 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Word.Template.8 Name: AlwaysShowExt |
object name not found |
626525025 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.dot Name: AlwaysShowExt |
object name not found |
626525764 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Word.Template.8 Name: NeverShowExt |
object name not found |
626526451 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.dot Name: NeverShowExt |
object name not found |
626527126 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\ReviewCycle Name: ReviewToken |
success or wait |
626528601 |
Mutant created |
Name: \BaseNamedObjects\Global\MTX_MSO_Formal1_S-1-5-21-507921405-1960408961-839522115-500 |
success or wait |
626529626 |
Section loaded |
Path: \BaseNamedObjects\Local\MSO_Formal11108172_S-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read and execute and extend size Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
626529984 |
Section loaded |
Path: \BaseNamedObjects\Local\MSO_Formal11108172_S-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read Type: commit Baseaddress: 1F10000 Size: 8192 Protection:
read write Mapped to pid: own pid
|
success or wait |
626530236 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\review.rcd
Access: synchronize and generic read Options: synchronous io non alert and non directory
file Overwritten: false
|
object name not found |
626531919 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\review.rcd
Access: read attributes and synchronize and generic read Options: sequential only
and synchronous io non alert and non directory file and open no recall Attributes:
normal Content Overwritten: true
|
object name not found |
626533579 |
Mutant created |
Name: \BaseNamedObjects\Global\MTX_MSO_AdHoc1_S-1-5-21-507921405-1960408961-839522115-500 |
success or wait |
626534559 |
Section loaded |
Path: \BaseNamedObjects\Local\MSO_AdHoc11108172_S-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read and execute and extend size Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
626534902 |
Section loaded |
Path: \BaseNamedObjects\Local\MSO_AdHoc11108172_S-1-5-21-507921405-1960408961-839522115-500
Access: query and write and read Type: commit Baseaddress: 1F20000 Size: 8192 Protection:
read write Mapped to pid: own pid
|
success or wait |
626535150 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\adhoc.rcd
Access: synchronize and generic read Options: synchronous io non alert and non directory
file Overwritten: false
|
object name not found |
626536529 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\adhoc.rcd
Access: read attributes and synchronize and generic read Options: sequential only
and synchronous io non alert and non directory file and open no recall Attributes:
normal Content Overwritten: true
|
object name not found |
626537670 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: DoNotDismissFileNewTaskPane |
object name not found |
626538681 |
Window placement got |
HWND: 5012E CMD: show maximized |
success |
626539024 |
Message sent |
HWND: 90058 Message: WINDOWPOSCHANGING WParam: 0 LParam: 1201920 |
error |
626539342 |
Message sent |
HWND: 40134 Message: WINDOWPOSCHANGING WParam: 0 LParam: 1201932 |
error |
626539573 |
Message sent |
HWND: 5010A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1202020 |
error |
626539835 |
Message sent |
HWND: 5010A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1202020 |
error |
626540068 |
Message sent |
HWND: 5010A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1202020 |
error |
626540278 |
Message sent |
HWND: 5010A Message: WINDOWPOSCHANGING WParam: 0 LParam: 1202020 |
error |
626540487 |
Message sent |
HWND: 40134 Message: WINDOWPOSCHANGING WParam: 0 LParam: 1202008 |
error |
626540825 |
Message sent |
HWND: 40134 Message: WINDOWPOSCHANGING WParam: 0 LParam: 1202008 |
error |
626541043 |
Window created |
Window Name: _WwB Class Name: _WwB HWND: 5012C |
success |
626541312 |
Message sent |
HWND: 5012C Message: NCCREATE WParam: 0 LParam: 1200884 |
success |
626541532 |
Message sent |
HWND: 5012C Message: NCCALCSIZE WParam: 0 LParam: 1200924 |
error |
626541766 |
Foreground Window Got |
HWND: 5012E |
success |
626557465 |
Window created |
Window Name: _WwG Class Name: _WwG HWND: 50106 |
success |
626558602 |
Window created |
Window Name: 6.0.2600.6028!ScrollBar Class Name: SCROLLBAR HWND: 400EC |
success |
626561968 |
Window created |
Window Name: _WwC Class Name: _WwC HWND: 40120 |
success |
626563378 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 40128 |
success |
626591524 |
Window created |
Window Name: 6.0.2600.6028!ScrollBar Class Name: SCROLLBAR HWND: 400E4 |
success |
626592832 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 400DE |
success |
626615778 |
Window created |
Window Name: _WwC Class Name: _WwC HWND: 400DA |
success |
626616986 |
Window created |
Window Name: _WwC Class Name: _WwC HWND: 500DC |
success |
626617515 |
Window created |
Window Name: _WwC Class Name: _WwC HWND: 400D6 |
success |
626618331 |
Window shown |
HWND: 400EC CMD: show normal |
error |
626644839 |
Window shown |
HWND: 400E4 CMD: show normal |
error |
626645010 |
Window shown |
HWND: 400DE CMD: show normal |
error |
626645173 |
Window shown |
HWND: 40128 CMD: show normal |
error |
626645728 |
Window shown |
HWND: 500DC CMD: show normal |
error |
626646364 |
Window shown |
HWND: 400D6 CMD: show normal |
error |
626646527 |
Message sent |
HWND: 5012E Message: NCACTIVATE WParam: 1 LParam: 0 |
success |
626652502 |
Message posted |
TID: 6E8 Message: C087 WParam: 17 LParam: 327942 |
success |
626652856 |
File opened |
Path: C:\WINDOWS\system32\Msimtf.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
626653906 |
Section loaded |
Path: C:\WINDOWS\system32\msimtf.dll Access: write and read and execute Type: commit
Baseaddress: 1F70000 Size: 159744 Protection: execute Mapped to pid: own pid
|
success or wait |
626654872 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Internet Name: PixelsPerInch |
object name not found |
626658519 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Internet Name: PixelsPerInch |
object name not found |
626658865 |
Window shown |
HWND: 400EC CMD: show normal |
success |
626659203 |
Window shown |
HWND: 400E4 CMD: show normal |
success |
626659362 |
Window shown |
HWND: 400DE CMD: show normal |
success |
626659518 |
Window shown |
HWND: 40128 CMD: show normal |
success |
626660319 |
Window shown |
HWND: 500DC CMD: show normal |
success |
626660835 |
Window shown |
HWND: 400D6 CMD: show normal |
success |
626660991 |
Window shown |
HWND: 400EC CMD: show normal |
success |
626662701 |
Window shown |
HWND: 400E4 CMD: show normal |
success |
626662856 |
Window shown |
HWND: 400DE CMD: show normal |
success |
626663012 |
Window shown |
HWND: 40128 CMD: show normal |
success |
626663392 |
Window shown |
HWND: 500DC CMD: show normal |
success |
626663731 |
Window shown |
HWND: 400D6 CMD: show normal |
success |
626663887 |
Window shown |
HWND: 40134 CMD: show normal |
success |
626664059 |
Window shown |
HWND: 5012C CMD: show normal |
error |
626664216 |
Message sent |
HWND: 5012E Message: NCPAINT WParam: 1 LParam: 0 |
error |
626664615 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
626665208 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
626665448 |
Message sent |
HWND: 5012E Message: NCPAINT WParam: 1 LParam: 0 |
error |
626665701 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
626665940 |
Message sent |
HWND: 5012E Message: NCPAINT WParam: 1 LParam: 0 |
error |
626666174 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
626666410 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
626666644 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
626667267 |
Window shown |
HWND: 50106 CMD: show normal |
error |
626673791 |
Message sent |
HWND: 5012E Message: NCPAINT WParam: 1 LParam: 0 |
error |
626674055 |
Window shown |
HWND: 500DC CMD: show |
success |
626674518 |
Window shown |
HWND: 400D6 CMD: show |
success |
626674676 |
Window shown |
HWND: 40134 CMD: show normal |
success |
626675495 |
Window shown |
HWND: 400EC CMD: show normal |
success |
626675652 |
Window shown |
HWND: 400E4 CMD: show normal |
success |
626677700 |
Window shown |
HWND: 400DE CMD: show normal |
success |
626679047 |
Window shown |
HWND: 40128 CMD: show normal |
success |
626679898 |
Window shown |
HWND: 500DC CMD: show normal |
success |
626680515 |
Window shown |
HWND: 400D6 CMD: show normal |
success |
626680671 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
HideFileExt
|
success or wait |
626684955 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
HideFileExt
|
success or wait |
626695296 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
626697835 |
Section loaded |
Path: \BaseNamedObjects\Global\RotHintTable Access: read Type: unknown Baseaddress:
1F70000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
626698558 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
626699712 |
File opened |
Path: C:\Documents and Settings\ Access: read data or list directory and synchronize
Options: directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
626701333 |
File opened |
Path: C:\Documents and Settings\Administrator\Desktop\ Access: read data or list
directory and synchronize Options: directory file and synchronous io non alert and
open for backup ident Overwritten: false
|
success or wait |
626702628 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common Name: VbaOff |
object name not found |
626708638 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common Name: VbaOff |
object name not found |
626708978 |
Section loaded |
Path: \KnownDlls\msi.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
626709520 |
File opened |
Path: C:\WINDOWS\system32\msi.dll Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
626710206 |
Section loaded |
Path: C:\WINDOWS\system32\msi.dll Access: query and write and read and execute Type:
image Baseaddress: 7D1E0000 Size: 2867200 Protection: read write Mapped to pid: own
pid
|
success or wait |
626710953 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer Name: DisableUserInstalls |
object name not found |
626720084 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer Name: Debug |
object name not found |
626720595 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\InstallProperties
Name: WindowsInstaller
|
success or wait |
626722997 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Registration\{90110409-6000-11D3-8CFE-0150048383C9}
Name: DigitalProductID
|
buffer overflow |
626724585 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Registration\{90110409-6000-11D3-8CFE-0150048383C9}
Name: DigitalProductID
|
success or wait |
626724977 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\InstallProperties
Name: WindowsInstaller
|
success or wait |
626727128 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: WORDFiles
|
success or wait |
626728770 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
626730002 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
626730329 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
success or wait |
626730648 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626731292 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A453DD12EE71CEF49A4EB2A8684FB83A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626732025 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5861C19D5F3D8C8439408F306F31034A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626732751 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\311714883E93F274A838DDB012991F9D
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626733447 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\72E940125B15C02498F17C8F91EADC14
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626734135 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\16EFE5D0815A2D11A92E0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626734829 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\41AE703BF87339947BDCC4715F97EFED
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626735553 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: ProductFiles
|
success or wait |
626736130 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
626736834 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
626737164 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
success or wait |
626737488 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626738283 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\379E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626738985 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1650EACF3C291D11A92C0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626740057 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C2DC6651A24AD4BB2DE51C70F5C3E0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626740810 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
626741541 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626741878 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBA0D1302088D1E44B6F7E0DC6732662
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626742583 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2516E66D0FE30B64EB1CDE1F52E7C357
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626743317 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
626744036 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626744401 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE6545E80813C4542A70D28194279382
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626745110 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626745847 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A27DD755B98E23499AA660C6A835D0C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626746548 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86FBBBBDC3EB97D4989B210DB8D577D2
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626747250 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19A12162A748EF94E899C354C0912213
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626747946 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles
|
success or wait |
626750088 |
Key value replaced with new |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles Type: dword Data: 1089994754 Old data: 1089994753
|
success or wait |
626750472 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626751986 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: ProductFiles
|
success or wait |
626753812 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
626754511 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
626754838 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
success or wait |
626755156 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626755903 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\379E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626756876 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1650EACF3C291D11A92C0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626757564 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C2DC6651A24AD4BB2DE51C70F5C3E0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626758552 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
626759246 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626759571 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBA0D1302088D1E44B6F7E0DC6732662
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626760266 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2516E66D0FE30B64EB1CDE1F52E7C357
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626760952 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
626761636 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626761960 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE6545E80813C4542A70D28194279382
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626762649 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626763337 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A27DD755B98E23499AA660C6A835D0C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626764022 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86FBBBBDC3EB97D4989B210DB8D577D2
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626764707 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19A12162A748EF94E899C354C0912213
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626765391 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: ProductFiles
|
success or wait |
626767319 |
Key value replaced with new |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: ProductFiles Type: dword Data: 1089994755 Old data: 1089994754
|
success or wait |
626767671 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: VBAFiles
|
success or wait |
626768685 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: VBAFiles
|
buffer overflow |
626769435 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: VBAFiles
|
buffer overflow |
626769789 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: VBAFiles
|
success or wait |
626770119 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0020F700D33C1D112897000CF42C6133
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
626771148 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0020F700D33C1D112897000CF42C6133
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626771484 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\359E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626772205 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1C1B74D56F7A1D11A9CC0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
626773469 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1C1B74D56F7A1D11A9CC0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626773806 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4EEF86DD963C1D111A37000A9CA05BF0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626774676 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2EEF86DD963C1D111A37000A9CA05BF0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626775471 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A457B2D1A9DC1D112897000CF42C6133
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626776357 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1178400169C22D11A9790006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626777080 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: SHAREDFiles
|
success or wait |
626777706 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: SHAREDFiles
|
success or wait |
626778426 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: SHAREDFiles
|
success or wait |
626778758 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626779345 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: ProductFiles
|
success or wait |
626779943 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
626780661 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
626780997 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
success or wait |
626781333 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626782115 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\379E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626782836 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1650EACF3C291D11A92C0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626783553 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C2DC6651A24AD4BB2DE51C70F5C3E0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626784270 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
626784990 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626785329 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBA0D1302088D1E44B6F7E0DC6732662
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626786053 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2516E66D0FE30B64EB1CDE1F52E7C357
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626786767 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
626787520 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626787858 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE6545E80813C4542A70D28194279382
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626788582 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626789302 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A27DD755B98E23499AA660C6A835D0C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626790021 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86FBBBBDC3EB97D4989B210DB8D577D2
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626790739 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19A12162A748EF94E899C354C0912213
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626791459 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VBA Name: Vbe6DllPath |
success or wait |
626792816 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
626794308 |
Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: write and read and execute
Type: commit Baseaddress: 2830000 Size: 2588672 Protection: execute Mapped to pid:
own pid
|
success or wait |
626795113 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: read attributes and
synchronize and generic read Options: synchronous io non alert and non directory file
Attributes: none Content Overwritten: true
|
success or wait |
626797893 |
Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: query and read Type:
commit Baseaddress: 2830000 Size: 2588672 Protection: readonly Mapped to pid: own
pid
|
success or wait |
626798689 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
626821070 |
Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: write and read and execute
Type: commit Baseaddress: 2830000 Size: 2588672 Protection: execute Mapped to pid:
own pid
|
success or wait |
626821867 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: read attributes and
synchronize and generic read Options: synchronous io non alert and non directory file
Attributes: none Content Overwritten: true
|
success or wait |
626823363 |
Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: query and read Type:
commit Baseaddress: 2830000 Size: 2588672 Protection: readonly Mapped to pid: own
pid
|
success or wait |
626824148 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Components\029E403DA86A1D115B5B0006799C897E
Name: vbe.dll_6.0
|
success or wait |
626835875 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: VBAFiles
|
success or wait |
626836791 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: VBAFiles
|
buffer overflow |
626837520 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: VBAFiles
|
buffer overflow |
626837856 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: VBAFiles
|
success or wait |
626838190 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0020F700D33C1D112897000CF42C6133
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
626838834 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0020F700D33C1D112897000CF42C6133
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626839175 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\359E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626839888 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1C1B74D56F7A1D11A9CC0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
626840600 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1C1B74D56F7A1D11A9CC0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626840937 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4EEF86DD963C1D111A37000A9CA05BF0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626841654 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2EEF86DD963C1D111A37000A9CA05BF0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626842387 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A457B2D1A9DC1D112897000CF42C6133
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626843152 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1178400169C22D11A9790006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626843862 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: SHAREDFiles
|
success or wait |
626844478 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: SHAREDFiles
|
success or wait |
626845200 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: SHAREDFiles
|
success or wait |
626845536 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626846078 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: ProductFiles
|
success or wait |
626846678 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
626847405 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
626847747 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
success or wait |
626848082 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626848858 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\379E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626849583 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1650EACF3C291D11A92C0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626850307 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C2DC6651A24AD4BB2DE51C70F5C3E0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626851030 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
626851757 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626852099 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBA0D1302088D1E44B6F7E0DC6732662
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626852831 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2516E66D0FE30B64EB1CDE1F52E7C357
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626853555 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
626854276 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626854616 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE6545E80813C4542A70D28194279382
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626855347 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626856078 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A27DD755B98E23499AA660C6A835D0C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626856799 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86FBBBBDC3EB97D4989B210DB8D577D2
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626857517 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19A12162A748EF94E899C354C0912213
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626858776 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\359E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626860022 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: VBAFiles
|
object name not found |
626861855 |
Key value set |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: VBAFiles Type: dword Data: 1089994753 Old data:
|
success or wait |
626862200 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\vbe6.dll Access: execute
or traverse and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
success or wait |
626864385 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6.DLL Access: write
and read and execute Type: commit Baseaddress: 2830000 Size: 2588672 Protection: execute
Mapped to pid: own pid
|
success or wait |
626865224 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\vbe6.dll Access: read
attributes and synchronize and generic read Options: synchronous io non alert and
non directory file Attributes: none Content Overwritten: true
|
success or wait |
626866729 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6.DLL Access: query
and read Type: commit Baseaddress: 2830000 Size: 2588672 Protection: readonly Mapped
to pid: own pid
|
success or wait |
626867560 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\vbe6.dll Access: execute
or traverse and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
success or wait |
626887365 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6.DLL Access: write
and read and execute Type: commit Baseaddress: 2830000 Size: 2588672 Protection: execute
Mapped to pid: own pid
|
success or wait |
626888199 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\vbe6.dll Access: read
attributes and synchronize and generic read Options: synchronous io non alert and
non directory file Attributes: none Content Overwritten: true
|
success or wait |
626889693 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6.DLL Access: query
and read Type: commit Baseaddress: 2830000 Size: 2588672 Protection: readonly Mapped
to pid: own pid
|
success or wait |
626890519 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
626904024 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
626904682 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020906-0000-0000-C000-000000000046}\LocalServer32
Name: LocalServer32
|
success or wait |
626906984 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Group Policy\AppMgmt Name:
{90110409-6000-11D3-8CFE-0150048383C9}
|
object name not found |
626908141 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: WORDFiles
|
success or wait |
626909278 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
626910029 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
626910379 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
success or wait |
626910721 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626911372 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A453DD12EE71CEF49A4EB2A8684FB83A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626912755 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5861C19D5F3D8C8439408F306F31034A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626914112 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\311714883E93F274A838DDB012991F9D
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626915467 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\72E940125B15C02498F17C8F91EADC14
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626916874 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\16EFE5D0815A2D11A92E0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626918237 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\41AE703BF87339947BDCC4715F97EFED
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626919628 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: ProductFiles
|
success or wait |
626920861 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
626921613 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
626921968 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
success or wait |
626922315 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626923086 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\379E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626924841 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1650EACF3C291D11A92C0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626926221 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C2DC6651A24AD4BB2DE51C70F5C3E0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626927785 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
626928822 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626929178 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBA0D1302088D1E44B6F7E0DC6732662
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626930589 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2516E66D0FE30B64EB1CDE1F52E7C357
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626931965 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
626933340 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626933694 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE6545E80813C4542A70D28194279382
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626935073 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626936446 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A27DD755B98E23499AA660C6A835D0C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626937199 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86FBBBBDC3EB97D4989B210DB8D577D2
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626938570 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19A12162A748EF94E899C354C0912213
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626939942 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626941689 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles
|
success or wait |
626944767 |
Key value replaced with new |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles Type: dword Data: 1089994755 Old data: 1089994754
|
success or wait |
626945151 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020906-0000-0000-C000-000000000046}\InprocHandler32
Name: NULL
|
success or wait |
626946800 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
626948549 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
626949170 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020906-0000-0000-C000-000000000046}\LocalServer32
Name: LocalServer32
|
success or wait |
626951408 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Group Policy\AppMgmt Name:
{90110409-6000-11D3-8CFE-0150048383C9}
|
object name not found |
626952104 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: WORDFiles
|
success or wait |
626953230 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
626953979 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
626954376 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
success or wait |
626954720 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626955379 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A453DD12EE71CEF49A4EB2A8684FB83A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626956752 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5861C19D5F3D8C8439408F306F31034A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626958113 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\311714883E93F274A838DDB012991F9D
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626959516 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\72E940125B15C02498F17C8F91EADC14
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626960872 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\16EFE5D0815A2D11A92E0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626962235 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\41AE703BF87339947BDCC4715F97EFED
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626963593 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: ProductFiles
|
success or wait |
626964832 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
626965584 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
626965938 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
success or wait |
626966286 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626967058 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\379E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626968468 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1650EACF3C291D11A92C0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626969834 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C2DC6651A24AD4BB2DE51C70F5C3E0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626971203 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
626972227 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626972585 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBA0D1302088D1E44B6F7E0DC6732662
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626974005 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2516E66D0FE30B64EB1CDE1F52E7C357
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626975373 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
626976740 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626977092 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE6545E80813C4542A70D28194279382
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626978463 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626979995 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A27DD755B98E23499AA660C6A835D0C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626980755 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86FBBBBDC3EB97D4989B210DB8D577D2
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626982372 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19A12162A748EF94E899C354C0912213
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626983755 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
626985500 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles
|
success or wait |
626988609 |
Key value replaced with new |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles Type: dword Data: 1089994756 Old data: 1089994755
|
success or wait |
626988993 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020906-0000-0000-C000-000000000046}\InprocHandler32
Name: NULL
|
success or wait |
626990612 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
627005453 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
627006100 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F4754C9B-64F5-4B40-8AF4-679732AC0607}\LocalServer32
Name: LocalServer32
|
object name not found |
627008467 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F4754C9B-64F5-4B40-8AF4-679732AC0607}\LocalServer32
Name: NULL
|
success or wait |
627010591 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
627013621 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
627014258 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{18A06B6B-2F3F-4E2B-A611-52BE631B2D22}\LocalServer32
Name: LocalServer32
|
object name not found |
627016577 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{18A06B6B-2F3F-4E2B-A611-52BE631B2D22}\LocalServer32
Name: NULL
|
success or wait |
627018709 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
627021725 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
627022366 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020907-0000-0000-C000-000000000046}\LocalServer32
Name: LocalServer32
|
success or wait |
627024631 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Group Policy\AppMgmt Name:
{90110409-6000-11D3-8CFE-0150048383C9}
|
object name not found |
627025371 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: WORDFiles
|
success or wait |
627026569 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
627027331 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
buffer overflow |
627027685 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: WORDFiles
|
success or wait |
627028028 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
627028677 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A453DD12EE71CEF49A4EB2A8684FB83A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
627030611 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5861C19D5F3D8C8439408F306F31034A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
627031973 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\311714883E93F274A838DDB012991F9D
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
627033324 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\72E940125B15C02498F17C8F91EADC14
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
627034672 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\16EFE5D0815A2D11A92E0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
627037743 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\41AE703BF87339947BDCC4715F97EFED
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
627039533 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040110900063D11C8EF10054038389C
Name: ProductFiles
|
success or wait |
627040823 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
627041580 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
buffer overflow |
627041936 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Features
Name: ProductFiles
|
success or wait |
627042283 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EAE1CE3652AD1140BB010C68A730687
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
627043085 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\379E92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
627044484 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1650EACF3C291D11A92C0006794C4E25
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
627045891 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C2DC6651A24AD4BB2DE51C70F5C3E0
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
627047265 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
627048295 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D562284CE147D0E4CB6C801C80461A10
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
627048650 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DBA0D1302088D1E44B6F7E0DC6732662
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
627050029 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2516E66D0FE30B64EB1CDE1F52E7C357
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
627051406 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
buffer overflow |
627052831 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F53EF4649650FD468E7990AAA2398BA
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
627053188 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE6545E80813C4542A70D28194279382
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
627054569 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\987E83843F00AC84188BFB846FC86492
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
627055932 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A27DD755B98E23499AA660C6A835D0C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
627056680 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86FBBBBDC3EB97D4989B210DB8D577D2
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
627058046 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19A12162A748EF94E899C354C0912213
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
627059441 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB4EDBE115A903645B145216AF54CC5C
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
627061182 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles
|
success or wait |
627063733 |
Key value replaced with new |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Usage
Name: WORDFiles Type: dword Data: 1089994758 Old data: 1089994757
|
success or wait |
627064113 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00020907-0000-0000-C000-000000000046}\InprocHandler32
Name: NULL
|
success or wait |
627065743 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 4011A |
success |
627098208 |
Window created |
Window Name: CLIPBRDWNDCLASS Class Name: CLIPBRDWNDCLASS HWND: 7010C |
success |
627099099 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.3\0\win32
Name: NULL
|
success or wait |
627103289 |
Section loaded |
Path: \KnownDlls\SXS.DLL Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
627103962 |
File opened |
Path: C:\WINDOWS\system32\SXS.DLL Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
627104663 |
Section loaded |
Path: C:\WINDOWS\system32\sxs.dll Access: query and write and read and execute Type:
image Baseaddress: 7E720000 Size: 720896 Protection: read write Mapped to pid: own
pid
|
success or wait |
627105426 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
627112162 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
627112852 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
627113658 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
627114289 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
627116484 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
627117112 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
627118840 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
627119480 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
627121181 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
627121918 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020905-0000-0000-C000-000000000046}\8.3\0\win32
Name: NULL
|
success or wait |
627126829 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Access: read attributes
and synchronize and generic read Options: synchronous io non alert and non directory
file and random access Attributes: none Content Overwritten: true
|
success or wait |
627127586 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 0
|
success or wait |
627128691 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00
40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 B8 00 00 00
|
success or wait |
627128903 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 0
|
success or wait |
627130445 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 184
|
success or wait |
627130682 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
4 Value: 50 45 00 00
|
success or wait |
627130874 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
20 Value: 4C 01 02 00 A1 95 00 46 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
627131093 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 432
|
success or wait |
627131339 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
40 Value: 2E 72 73 72 63 00 00 00 98 06 0A 00 00 10 00 00 00 08 0A 00 00 02 00 00
00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40
|
success or wait |
627131533 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 472
|
success or wait |
627131786 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 512
|
success or wait |
627131985 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
16 Value: 00 00 00 00 00 00 00 00 00 00 00 00 01 00 01 00
|
success or wait |
627132178 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
8 Value: A0 00 00 80 20 00 00 80
|
success or wait |
627132402 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 536
|
success or wait |
627132628 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 672
|
success or wait |
627132825 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
2 Value: 07 00
|
success or wait |
627133018 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
14 Value: 54 00 59 00 50 00 45 00 4C 00 49 00 42 00
|
success or wait |
627133235 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 536
|
success or wait |
627133461 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 472
|
success or wait |
627133658 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 472
|
success or wait |
627133859 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 544
|
success or wait |
627134057 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
16 Value: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00
|
success or wait |
627134249 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 560
|
success or wait |
627134481 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
8 Value: 01 00 00 00 50 00 00 80
|
success or wait |
627134673 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 472
|
success or wait |
627134896 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 472
|
success or wait |
627135096 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 592
|
success or wait |
627135293 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
16 Value: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00
|
success or wait |
627135486 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
8 Value: 09 04 00 00 80 00 00 00
|
success or wait |
627135709 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 472
|
success or wait |
627135932 |
File other op |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB New path: Disposition:
PositionInformation Data : Offset: 640
|
success or wait |
627136127 |
File read |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Offset: unknown Length:
16 Value: B0 10 00 00 44 01 0A 00 00 00 00 00 00 00 00 00
|
success or wait |
627136316 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\MSWORD.OLB Access: query and read
Type: commit Baseaddress: 2830000 Size: 659456 Protection: readonly Mapped to pid:
own pid
|
success or wait |
627136595 |
System info queried |
Type: ProcessorInformation |
success or wait |
627137113 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VBA Name: Vbe6DllPath |
success or wait |
627146312 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VBA Name: Vbe6DllPath |
success or wait |
627146648 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
627147384 |
Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: write and read and execute
Type: commit Baseaddress: 28E0000 Size: 2588672 Protection: execute Mapped to pid:
own pid
|
success or wait |
627148197 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
627150038 |
Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: query and write and
read and execute Type: image Baseaddress: 65000000 Size: 2588672 Protection: read
write Mapped to pid: own pid
|
success or wait |
627150840 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution
Options\vbe6.dll Name: CheckAppHelp
|
success or wait |
627162611 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\1033\VBE6INTL.DLL Access: execute or
traverse and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
success or wait |
627252525 |
Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\1033\VBE6INTL.DLL Access: write and read
and execute Type: commit Baseaddress: 1FA0000 Size: 163840 Protection: execute Mapped
to pid: own pid
|
success or wait |
627253376 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\1033\VBE6INTL.DLL Access: execute or
traverse and synchronize Options: synchronous io non alert and non directory file
Overwritten: false
|
success or wait |
627256391 |
Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\1033\VBE6INTL.DLL Access: query and write
and read and execute Type: image Baseaddress: 65300000 Size: 155648 Protection: read
write Mapped to pid: own pid
|
success or wait |
627257218 |
Window created |
Window Name: ThunderMain Class Name: ThunderMain HWND: 400EE |
success |
627260481 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage Name: 932 |
success or wait |
627261746 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage Name: 949 |
success or wait |
627262328 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage Name: 950 |
success or wait |
627262892 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage Name: 936 |
success or wait |
627263456 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: DoNotDismissFileNewTaskPane |
object name not found |
627266352 |
Window placement got |
HWND: 5012E CMD: show maximized |
success |
627266739 |
Window created |
Window Name: OpusApp Class Name: OpusApp HWND: 9014E |
success |
627267020 |
Section loaded |
Path: \KnownDlls\MSIMG32.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
627303167 |
File opened |
Path: C:\WINDOWS\system32\MSIMG32.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
627306156 |
Section loaded |
Path: C:\WINDOWS\system32\msimg32.dll Access: query and write and read and execute
Type: image Baseaddress: 76380000 Size: 20480 Protection: read write Mapped to pid:
own pid
|
success or wait |
627307144 |
Window created |
Window Name: _WwC Class Name: _WwC HWND: 400D8 |
success |
627324436 |
Window created |
Window Name: _WwF Class Name: _WwF HWND: 7013C |
success |
627324986 |
Window created |
Window Name: _WwB Class Name: _WwB HWND: 400F2 |
success |
627328828 |
Window created |
Window Name: _WwG Class Name: _WwG HWND: 50124 |
success |
627330095 |
Window created |
Window Name: 6.0.2600.6028!ScrollBar Class Name: SCROLLBAR HWND: 900FE |
success |
627333481 |
Window created |
Window Name: _WwC Class Name: _WwC HWND: 400EA |
success |
627334233 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 500F8 |
success |
627356428 |
Window created |
Window Name: 6.0.2600.6028!ScrollBar Class Name: SCROLLBAR HWND: 90152 |
success |
627361306 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 9013E |
success |
627387146 |
Window created |
Window Name: _WwC Class Name: _WwC HWND: 700FC |
success |
627388434 |
Window created |
Window Name: _WwC Class Name: _WwC HWND: 60112 |
success |
627388949 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Internet Name: PixelsPerInch |
object name not found |
627392115 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Internet Name: PixelsPerInch |
object name not found |
627392463 |
Window shown |
HWND: 900FE CMD: show normal |
error |
627392790 |
Window shown |
HWND: 90152 CMD: show normal |
error |
627392958 |
Window shown |
HWND: 9013E CMD: show normal |
error |
627393118 |
Window shown |
HWND: 500F8 CMD: show normal |
error |
627394081 |
Window shown |
HWND: 60112 CMD: show normal |
error |
627394744 |
Window shown |
HWND: 900FE CMD: show normal |
success |
627397726 |
Window shown |
HWND: 90152 CMD: show normal |
success |
627397881 |
Window shown |
HWND: 9013E CMD: show normal |
success |
627398034 |
Window shown |
HWND: 500F8 CMD: show normal |
success |
627398420 |
Window shown |
HWND: 60112 CMD: show normal |
success |
627398764 |
Window shown |
HWND: 40134 CMD: show normal |
success |
627398942 |
Window shown |
HWND: 50124 CMD: show normal |
error |
627399172 |
Window shown |
HWND: 60112 CMD: show |
success |
627399338 |
Window shown |
HWND: 400D8 CMD: show normal |
error |
627401081 |
Window shown |
HWND: 900FE CMD: show normal |
success |
627401251 |
Window shown |
HWND: 90152 CMD: show normal |
success |
627401408 |
Window shown |
HWND: 9013E CMD: show normal |
success |
627401563 |
Window shown |
HWND: 500F8 CMD: show normal |
success |
627401982 |
Window shown |
HWND: 60112 CMD: show normal |
success |
627402370 |
Window shown |
HWND: 400F2 CMD: hide |
error |
627402550 |
File opened |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.Word\~WRF0001.tmp
Access: read data or list directory and read ea and read attributes and read control
and synchronize Options: no options Attributes: normal Content Overwritten: true
|
object name not found |
627405459 |
Section loaded |
Path: \BaseNamedObjects\DfSharedHeap38B25 Access: query and write and read Type: reserve
Baseaddress: 2A30000 Size: 4194304 Protection: read write Mapped to pid: own pid
|
success or wait |
627406557 |
File created |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.Word\~WRF0001.tmp
Access: read attributes and synchronize and generic read and generic write Options:
synchronous io non alert and non directory file Attributes: normal Content Overwritten:
true
|
success or wait |
627407794 |
File other op |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.Word\~WRF0001.tmp
New path: Disposition: PositionInformation Data : Offset: 512
|
success or wait |
627412151 |
File other op |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.Word\~WRF0001.tmp
New path: Disposition: EndOfFileInformation Data : unknown
|
success or wait |
627412353 |
File other op |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.Word\~WRF0001.tmp
New path: Disposition: AllocationInformation Data : unknown
|
success or wait |
627413191 |
File other op |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.Word\~WRF0001.tmp
New path: Disposition: PositionInformation Data : Offset: 0
|
success or wait |
627413841 |
System info queried |
Type: PerformanceInformation |
success or wait |
627414026 |
Process information queried |
PID: 1160 Info Class: QuotaLimits |
success or wait |
627414422 |
Process information queried |
PID: 1160 Info Class: VmCounters |
success or wait |
627414628 |
Section loaded |
Path: \BaseNamedObjects\DFMap0-232234 Access: query and write and read Type: commit
Baseaddress: 2E30000 Size: 524288 Protection: read write Mapped to pid: own pid
|
success or wait |
627414884 |
Section loaded |
Path: \BaseNamedObjects\DfRoot000038B25 Access: query and write and read Type: commit
Baseaddress: 1FE0000 Size: 4096 Protection: read write Mapped to pid: own pid
|
success or wait |
627415963 |
Key created |
Path: HKEY_USERS\Software\Microsoft\VBA |
success or wait |
627478613 |
Key created |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0 |
success or wait |
627481384 |
Key created |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common |
success or wait |
627482617 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: RequireDeclaration |
object name not found |
627560301 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: CompileOnDemand |
object name not found |
627560631 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: NotifyUserBeforeStateLoss |
object name not found |
627560953 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: BackGroundCompile |
object name not found |
627561273 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: BreakOnAllErrors |
object name not found |
627561590 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\VBA\6.0\Common Name: BreakOnServerErrors |
object name not found |
627561906 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020905-0000-0000-C000-000000000046}\8.3\0\win32
Name: NULL
|
success or wait |
627602409 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{000204EF-0000-0000-C000-000000000046}\4.0\9\win32
Name: NULL
|
success or wait |
627638101 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: read attributes and
synchronize and generic read Options: synchronous io non alert and non directory file
and random access Attributes: none Content Overwritten: true
|
success or wait |
627651981 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 0
|
success or wait |
627652858 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 64 Value:
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 F8 00 00 00
|
success or wait |
627653046 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 0
|
success or wait |
627653863 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 248
|
success or wait |
627654055 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 4 Value:
50 45 00 00
|
success or wait |
627654239 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 20 Value:
4C 01 04 00 F1 05 41 46 00 00 00 00 00 00 00 00 E0 00 02 21
|
success or wait |
627655433 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 496
|
success or wait |
627655661 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 40 Value:
2E 74 65 78 74 00 00 00 CC FF 22 00 00 10 00 00 00 00 23 00 00 10 00 00 00 00 00 00
00 00 00 00 00 00 00 00 20 00 00 60
|
success or wait |
627655842 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 40 Value:
2E 64 61 74 61 00 00 00 A0 F0 00 00 00 10 23 00 00 D0 00 00 00 10 23 00 00 00 00 00
00 00 00 00 00 00 00 00 40 00 00 C0
|
success or wait |
627656079 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 40 Value:
2E 72 73 72 63 00 00 00 A0 E7 01 00 00 10 24 00 00 F0 01 00 00 E0 23 00 00 00 00 00
00 00 00 00 00 00 00 00 40 00 00 40
|
success or wait |
627656308 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 616
|
success or wait |
627656547 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2351104
|
success or wait |
627656735 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 16 Value:
00 00 00 00 00 00 00 00 00 00 00 00 01 00 09 00
|
success or wait |
627656921 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 8 Value:
40 18 00 80 60 00 00 80
|
success or wait |
627657242 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2351128
|
success or wait |
627657989 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2357312
|
success or wait |
627658182 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 2 Value:
07 00
|
success or wait |
627658366 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 14 Value:
54 00 59 00 50 00 45 00 4C 00 49 00 42 00
|
success or wait |
627658620 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2351128
|
success or wait |
627658838 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 616
|
success or wait |
627659030 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 616
|
success or wait |
627659220 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2351200
|
success or wait |
627659406 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 16 Value:
00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00
|
success or wait |
627659590 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2351216
|
success or wait |
627659853 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 8 Value:
01 00 00 00 E0 04 00 80
|
success or wait |
627660038 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 616
|
success or wait |
627660252 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 616
|
success or wait |
627660443 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2352352
|
success or wait |
627660632 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 16 Value:
00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00
|
success or wait |
627660816 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 8 Value:
09 04 00 00 80 10 00 00
|
success or wait |
627661031 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 616
|
success or wait |
627661244 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2355328
|
success or wait |
627661428 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 16 Value:
00 3E 25 00 40 B9 00 00 00 00 00 00 00 00 00 00
|
success or wait |
627661609 |
Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: query and read Type:
commit Baseaddress: 2F40000 Size: 53248 Protection: readonly Mapped to pid: own pid
|
success or wait |
627661883 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32
Name: NULL
|
success or wait |
627673453 |
File opened |
Path: C:\WINDOWS\system32\stdole2.tlb Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file and random access
Attributes: none Content Overwritten: true
|
success or wait |
627674575 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 0
|
success or wait |
627675339 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 64 Value: 4D 5A 90 00
03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
C0 00 00 00
|
success or wait |
627675542 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 0
|
success or wait |
627676279 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 192
|
success or wait |
627676488 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 4 Value: 50 45 00 00
|
success or wait |
627676689 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 20 Value: 4C 01 01 00
CE 29 02 48 00 00 00 00 00 00 00 00 E0 00 0F 21
|
success or wait |
627676916 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 440
|
success or wait |
627677159 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 40 Value: 2E 72 73 72
63 00 00 00 60 3E 00 00 00 10 00 00 00 40 00 00 00 02 00 00 00 00 00 00 00 00 00 00
00 00 00 00 40 00 00 40
|
success or wait |
627677358 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 480
|
success or wait |
627677613 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 512
|
success or wait |
627677818 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 16 Value: 00 00 00 00
00 00 00 00 00 00 00 00 01 00 01 00
|
success or wait |
627678019 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 8 Value: A0 00 00 80
20 00 00 80
|
success or wait |
627678253 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 536
|
success or wait |
627678490 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 672
|
success or wait |
627678696 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 2 Value: 07 00 |
success or wait |
627678899 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 14 Value: 54 00 59 00
50 00 45 00 4C 00 49 00 42 00
|
success or wait |
627679123 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 536
|
success or wait |
627679359 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 480
|
success or wait |
627679567 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 480
|
success or wait |
627679776 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 544
|
success or wait |
627679981 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 16 Value: 00 00 00 00
00 00 00 00 00 00 00 00 00 00 01 00
|
success or wait |
627680184 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 560
|
success or wait |
627680424 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 8 Value: 01 00 00 00
50 00 00 80
|
success or wait |
627680624 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 480
|
success or wait |
627680856 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 480
|
success or wait |
627681063 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 592
|
success or wait |
627681267 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 16 Value: 00 00 00 00
00 00 00 00 00 00 00 00 00 00 01 00
|
success or wait |
627681469 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 8 Value: 09 04 00 00
80 00 00 00
|
success or wait |
627681700 |
File other op |
Path: C:\WINDOWS\system32\stdole2.tlb New path: Disposition: PositionInformation
Data : Offset: 480
|
success or wait |
627681933 |
File read |
Path: C:\WINDOWS\system32\stdole2.tlb Offset: unknown Length: 16 Value: B0 10 00 00
40 3A 00 00 00 00 00 00 00 00 00 00
|
success or wait |
627682331 |
Section loaded |
Path: C:\WINDOWS\system32\stdole2.tlb Access: query and read Type: commit Baseaddress:
2F50000 Size: 16384 Protection: readonly Mapped to pid: own pid
|
success or wait |
627682620 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32
Name: NULL
|
success or wait |
627694841 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL\3 Access: read attributes and
synchronize and generic read Options: synchronous io non alert and non directory file
and random access Attributes: none Content Overwritten: true
|
object path not found |
627700113 |
File opened |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: read attributes and
synchronize and generic read Options: synchronous io non alert and non directory file
and random access Attributes: none Content Overwritten: true
|
success or wait |
627701535 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 0
|
success or wait |
627702336 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 64 Value:
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 F8 00 00 00
|
success or wait |
627702518 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 0
|
success or wait |
627702921 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 248
|
success or wait |
627703109 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 4 Value:
50 45 00 00
|
success or wait |
627703290 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 20 Value:
4C 01 04 00 F1 05 41 46 00 00 00 00 00 00 00 00 E0 00 02 21
|
success or wait |
627703496 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 496
|
success or wait |
627703718 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 40 Value:
2E 74 65 78 74 00 00 00 CC FF 22 00 00 10 00 00 00 00 23 00 00 10 00 00 00 00 00 00
00 00 00 00 00 00 00 00 20 00 00 60
|
success or wait |
627703897 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 40 Value:
2E 64 61 74 61 00 00 00 A0 F0 00 00 00 10 23 00 00 D0 00 00 00 10 23 00 00 00 00 00
00 00 00 00 00 00 00 00 40 00 00 C0
|
success or wait |
627704125 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 40 Value:
2E 72 73 72 63 00 00 00 A0 E7 01 00 00 10 24 00 00 F0 01 00 00 E0 23 00 00 00 00 00
00 00 00 00 00 00 00 00 40 00 00 40
|
success or wait |
627704352 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 616
|
success or wait |
627704588 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2351104
|
success or wait |
627704774 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 16 Value:
00 00 00 00 00 00 00 00 00 00 00 00 01 00 09 00
|
success or wait |
627704956 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 8 Value:
40 18 00 80 60 00 00 80
|
success or wait |
627705211 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2351128
|
success or wait |
627705425 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2357312
|
success or wait |
627705611 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 2 Value:
07 00
|
success or wait |
627705790 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 14 Value:
54 00 59 00 50 00 45 00 4C 00 49 00 42 00
|
success or wait |
627705993 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2351128
|
success or wait |
627706206 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 616
|
success or wait |
627706392 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 616
|
success or wait |
627706579 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2351200
|
success or wait |
627706763 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 16 Value:
00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00
|
success or wait |
627707070 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 2351216
|
success or wait |
627707294 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 8 Value:
01 00 00 00 E0 04 00 80
|
success or wait |
627707478 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 8 Value:
03 00 00 00 F8 04 00 80
|
success or wait |
627707863 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 616
|
success or wait |
627708077 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 616
|
success or wait |
627708264 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 16 Value:
00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00
|
success or wait |
627708631 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 8 Value:
09 04 00 00 90 10 00 00
|
success or wait |
627708842 |
File other op |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL New path: Disposition: PositionInformation
Data : Offset: 616
|
success or wait |
627709053 |
File read |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Offset: unknown Length: 16 Value:
60 FE 24 00 54 0F 00 00 00 00 00 00 00 00 00 00
|
success or wait |
627709415 |
Section loaded |
Path: C:\PROGRA~1\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL Access: query and read Type:
commit Baseaddress: 2F60000 Size: 57344 Protection: readonly Mapped to pid: own pid
|
success or wait |
627709685 |
File created |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\VBE Access: read data or list directory and
synchronize Options: directory file and synchronous io non alert and open for backup
ident Attributes: normal Content Overwritten: true
|
success or wait |
627714528 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
627732251 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
627734675 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
627735589 |
File opened |
Path: C:\Documents and Settings\ Access: read data or list directory and synchronize
Options: directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
627736859 |
File opened |
Path: C:\Documents and Settings\Administrator\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
627738141 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\ Access: read data
or list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
627739456 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
627740814 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020905-0000-0000-C000-000000000046}\8.3\0\win32
Name: NULL
|
success or wait |
627749691 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.3\0\win32
Name: NULL
|
success or wait |
627764953 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Access: read
attributes and synchronize and generic read Options: synchronous io non alert and
non directory file and random access Attributes: none Content Overwritten: true
|
success or wait |
627766176 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 64 Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00
00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 60 01 00 00
|
success or wait |
627767198 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 4 Value: 50 45 00 00
|
success or wait |
627768293 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 20 Value: 4C 01 05 00 00 1B 77 46 00 00 00 00 00 00 00 00 E0 00 0E 21
|
success or wait |
627768505 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 40 Value: 2E 74 65 78 74 00 00 00 59 7A 97 00 00 10 00 00 00 7C 97 00 00 04
00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60
|
success or wait |
627768919 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 40 Value: 2E 64 61 74 61 00 00 00 B4 43 05 00 00 90 97 00 00 AC 04 00 00 80
97 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0
|
success or wait |
627769153 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 40 Value: 2E 63 64 61 74 61 00 00 04 00 00 00 00 E0 9C 00 00 02 00 00 00 2C
9C 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 C0
|
success or wait |
627769385 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 40 Value: 2E 72 73 72 63 00 00 00 E0 D6 10 00 00 F0 9C 00 00 D8 10 00 00 2E
9C 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40
|
success or wait |
627769613 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 16 Value: 00 00 00 00 00 00 00 00 00 00 00 00 03 00 0E 00
|
success or wait |
627770234 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 8 Value: B6 6A 00 80 98 00 00 80
|
success or wait |
627770554 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 2 Value: 03 00
|
success or wait |
627771153 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 8 Value: E0 6C 00 80 20 01 00 80
|
success or wait |
627771602 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 2 Value: 07 00
|
success or wait |
627772197 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 14 Value: 54 00 59 00 50 00 45 00 4C 00 49 00 42 00
|
success or wait |
627772406 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 16 Value: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00
|
success or wait |
627773386 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 8 Value: 01 00 00 00 90 14 00 80
|
success or wait |
627773796 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 16 Value: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00
|
success or wait |
627774622 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 8 Value: 09 04 00 00 98 48 00 00
|
success or wait |
627774885 |
File read |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Offset: unknown
Length: 16 Value: 20 19 AA 00 A4 AA 03 00 00 00 00 00 00 00 00 00
|
success or wait |
627775472 |
Section loaded |
Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL Access: query
and read Type: commit Baseaddress: 2FB0000 Size: 266240 Protection: readonly Mapped
to pid: own pid
|
success or wait |
627775791 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{000204EF-0000-0000-C000-000000000046}\4.0\9\win32
Name: NULL
|
success or wait |
627786505 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020905-0000-0000-C000-000000000046}\8.3\0\win32
Name: NULL
|
success or wait |
627790128 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32
Name: NULL
|
success or wait |
627793680 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.3\0\win32
Name: NULL
|
success or wait |
627798066 |
Window shown |
HWND: 90058 CMD: hide |
success |
627801189 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib
Name:
|
success or wait |
627805116 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib
Name:
|
success or wait |
627805645 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version
Name:
|
success or wait |
627806473 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version
Name:
|
success or wait |
627806989 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0\0\win32
Name: NULL
|
success or wait |
627810190 |
File created |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0 Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Attributes: normal Content Overwritten: true
|
success or wait |
627811758 |
File opened |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Access: read attributes and
synchronize and generic read Options: synchronous io non alert and non directory file
and random access Attributes: none Content Overwritten: true
|
success or wait |
627818330 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 64 Value:
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 18 01 00 00
|
success or wait |
627820105 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 4 Value:
50 45 00 00
|
success or wait |
627822197 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 20 Value:
4C 01 07 00 A1 BD 39 4F 00 00 00 00 00 00 00 00 E0 00 02 21
|
success or wait |
627822418 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 40 Value:
2E 74 65 78 74 00 00 00 B9 0A 66 00 00 10 00 00 00 0C 66 00 00 04 00 00 00 00 00 00
00 00 00 00 00 00 00 00 20 00 00 60
|
success or wait |
627822840 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 40 Value:
2E 72 6F 64 61 74 61 00 E0 10 00 00 00 20 66 00 00 12 00 00 00 10 66 00 00 00 00 00
00 00 00 00 00 00 00 00 20 00 00 60
|
success or wait |
627823079 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 40 Value:
2E 72 64 61 74 61 00 00 32 1D 14 00 00 40 66 00 00 1E 14 00 00 22 66 00 00 00 00 00
00 00 00 00 00 00 00 00 40 00 00 40
|
success or wait |
627823317 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 40 Value:
2E 64 61 74 61 00 00 00 C4 7F 11 00 00 60 7A 00 00 E6 02 00 00 40 7A 00 00 00 00 00
00 00 00 00 00 00 00 00 40 00 00 C0
|
success or wait |
627823553 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 40 Value:
2E 72 6F 64 61 74 61 00 A0 04 00 00 00 E0 8B 00 00 06 00 00 00 26 7D 00 00 00 00 00
00 00 00 00 00 00 00 00 40 00 00 C0
|
success or wait |
627823789 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 40 Value:
2E 72 73 72 63 00 00 00 0C 0D 02 00 00 F0 8B 00 00 0E 02 00 00 2C 7D 00 00 00 00 00
00 00 00 00 00 00 00 00 40 00 00 40
|
success or wait |
627824024 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 16 Value:
00 00 00 00 00 00 00 00 04 00 00 00 02 00 0A 00
|
success or wait |
627824658 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 8 Value:
E0 11 00 80 70 00 00 80
|
success or wait |
627825693 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 2 Value:
08 00
|
success or wait |
627826353 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 8 Value:
F2 11 00 80 90 00 00 80
|
success or wait |
627827523 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 2 Value:
07 00
|
success or wait |
627828141 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 14 Value:
54 00 59 00 50 00 45 00 4C 00 49 00 42 00
|
success or wait |
627828355 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 16 Value:
00 00 00 00 00 00 00 00 04 00 00 00 00 00 02 00
|
success or wait |
627829388 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 8 Value:
01 00 00 00 48 02 00 80
|
success or wait |
627829813 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 16 Value:
00 00 00 00 00 00 00 00 04 00 00 00 00 00 01 00
|
success or wait |
627830811 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 8 Value:
1F 04 00 00 B0 08 00 00
|
success or wait |
627831035 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 16 Value:
34 24 8C 00 50 37 00 00 E4 04 00 00 00 00 00 00
|
success or wait |
627831677 |
Section loaded |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Access: query and read Type:
commit Baseaddress: 3000000 Size: 40960 Protection: readonly Mapped to pid: own pid
|
success or wait |
627831960 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file and random access Attributes: none Content Overwritten: true
|
object name not found |
627833750 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
627834581 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
627834906 |
File opened |
Path: C:\DOCUME~1\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
627836163 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\ Access: read data or list directory and synchronize Options:
directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
627837420 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\ Access: read data or list directory and synchronize
Options: directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
627838684 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ Access: read data or list directory and
synchronize Options: directory file and synchronous io non alert and open for backup
ident Overwritten: false
|
success or wait |
627839917 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
627841620 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
627841924 |
File opened |
Path: C:\DOCUME~1\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
627843133 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\ Access: read data or list directory and synchronize Options:
directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
627844368 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\ Access: read data or list directory and synchronize
Options: directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
627846155 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ Access: read data or list directory and
synchronize Options: directory file and synchronous io non alert and open for backup
ident Overwritten: false
|
success or wait |
627847442 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
627848740 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
627849046 |
File opened |
Path: C:\DOCUME~1\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
627850276 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\ Access: read data or list directory and synchronize Options:
directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
627851512 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\ Access: read data or list directory and synchronize
Options: directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
627852769 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
627854017 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
627854319 |
File opened |
Path: C:\DOCUME~1\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
627855526 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\ Access: read data or list directory and synchronize Options:
directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
627856756 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
627857977 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
627858278 |
File opened |
Path: C:\DOCUME~1\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
627859483 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
627860719 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
627861021 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
627862199 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager Name: SafeProcessSearchMode |
object name not found |
627875128 |
File created |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Access:
read attributes and synchronize and generic read and generic write Options: synchronous
io non alert and non directory file Attributes: none Content Overwritten: true
|
success or wait |
627875877 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 4D 53 46 54
|
success or wait |
627881103 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 02 00 01 00
|
success or wait |
627881945 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 00 00 00 00
|
success or wait |
627882208 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 09 04 00 00
|
success or wait |
627882804 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 00 00 00 00
|
success or wait |
627883063 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 41 00
|
success or wait |
627883654 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 00 00
|
success or wait |
627883965 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 01 00
|
success or wait |
627884223 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 00 00
|
success or wait |
627884816 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 04 00 00 00
|
success or wait |
627885074 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 0B 00 00 00
|
success or wait |
627885908 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 00 00 00 00
|
success or wait |
627886506 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 00 00 00 00
|
success or wait |
627886766 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 00 00 00 00
|
success or wait |
627887358 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: A4 00 00 00
|
success or wait |
627887616 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 0E 06 00 00
|
success or wait |
627888756 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 00 00 00 00
|
success or wait |
627889014 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: FF FF FF FF
|
success or wait |
627889608 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: FF FF FF FF
|
success or wait |
627889865 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 20 00 00 00
|
success or wait |
627890460 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 80 00 00 00
|
success or wait |
627890718 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 19 00 00 00
|
success or wait |
627891311 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 13 00 00 00
|
success or wait |
627891568 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 44 Value: 00 00 00 00 64 00 00 00 C8 00 00 00 2C 01 00 00 90 01 00
00 F4 01 00 00 58 02 00 00 BC 02 00 00 20 03 00 00 84 03 00 00 E8 03 00 00
|
success or wait |
627892181 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 16 Value: FF FF FF FF C0 06 00 00 4C 04 00 00 0F 00 00 00
|
success or wait |
627892780 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 16 Value: FF FF FF FF 40 01 00 00 E4 00 00 00 0F 00 00 00
|
success or wait |
627893381 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 16 Value: FF FF FF FF 24 00 00 00 1C 00 00 00 0F 00 00 00
|
success or wait |
627893980 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 16 Value: FF FF FF FF 60 00 00 00 40 00 00 00 0F 00 00 00
|
success or wait |
627894578 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 16 Value: FF FF FF FF 80 00 00 00 FF FF FF FF 0F 00 00 00
|
success or wait |
627895176 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 16 Value: FF FF FF FF 00 02 00 00 68 01 00 00 0F 00 00 00
|
success or wait |
627895776 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 16 Value: FF FF FF FF 00 02 00 00 FF FF FF FF 0F 00 00 00
|
success or wait |
627896374 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 16 Value: FF FF FF FF 00 16 00 00 B0 0E 00 00 0F 00 00 00
|
success or wait |
627896972 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 16 Value: FF FF FF FF 80 09 00 00 10 06 00 00 0F 00 00 00
|
success or wait |
627897757 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 16 Value: FF FF FF FF 00 02 00 00 70 01 00 00 0F 00 00 00
|
success or wait |
627898359 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 16 Value: FF FF FF FF 00 00 00 00 FF FF FF FF 0F 00 00 00
|
success or wait |
627898958 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 16 Value: FF FF FF FF 00 00 00 00 FF FF FF FF 0F 00 00 00
|
success or wait |
627899558 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 16 Value: FF FF FF FF 00 00 00 00 FF FF FF FF 0F 00 00 00
|
success or wait |
627900179 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 16 Value: FF FF FF FF 00 00 00 00 FF FF FF FF 0F 00 00 00
|
success or wait |
627900776 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 16 Value: FF FF FF FF 00 00 00 00 FF FF FF FF 0F 00 00 00
|
success or wait |
627901375 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 1100 Value: 24 21 00 00 FF FF FF FF 00 20 00 00 B0 1F 00 00 0F 00
00 00 B0 DC 22 00 76 00 00 00 80 00 00 00 30 C7 22 00 38 C9 22 00 40 CB 22 00 18 00
00 00 00 50 00 00 24 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 FF FF
FF FF 01 00 D8 01 04 00 00 00 FF FF FF FF 00 00 00 00 70 6C 22 00 FF FF FF FF
|
success or wait |
627902600 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 128 Value: 38 01 00 00 F0 00 00 00 50 01 00 00 FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF 90 00 00 00 D8 00 00 00 A8 00 00 00 FF FF FF FF 60 00 00 00 20 01 00
00 18 00 00 00 FF FF FF FF FF FF FF FF 08 01 00 00 FF FF FF FF FF FF FF FF
|
success or wait |
627904638 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 360 Value: 1D 12 42 48 9E 86 7A 47 B4 FC 30 7D 2E 2C 60 66 FE FF FF
FF FF FF FF FF 6C DB 7C D2 6D AE CF 11 96 B8 44 45 53 54 00 00 00 00 00 00 FF FF FF
FF 60 8E 59 C5 07 B3 D1 11 B2 7D 00 60 08 C3 FB FB 64 00 00 00 FF FF FF FF 6D DB 7C
D2 6D AE CF 11 96 B8 44 45 53 54 00 00 C8 00 00 00 FF FF FF FF 6E DB 7C D2
|
success or wait |
627905132 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 64 Value: 00 00 00 00 01 00 00 00 FF FF FF FF 10 00 00 00 C8 00 00
00 03 00 00 00 FF FF FF FF FF FF FF FF F4 01 00 00 01 00 00 00 FF FF FF FF FF FF FF
FF 84 03 00 00 01 00 00 00 FF FF FF FF FF FF FF FF
|
success or wait |
627905430 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 228 Value: 00 00 00 01 00 00 00 00 02 00 00 00 01 00 01 03 00 00 00
00 38 01 00 00 02 00 01 03 00 00 00 00 50 01 00 00 03 00 00 01 00 00 00 00 00 00 00
00 04 00 00 01 00 00 00 00 00 00 00 00 05 00 00 01 00 00 00 00 00 00 00 00 06 00 00
01 00 00 00 00 01 00 00 00 07 00 00 01 00 00 00 00 02 00 00 00 08 00 00 01
|
success or wait |
627905852 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 28 Value: 20 01 00 00 00 00 00 00 02 00 00 00 2D 00 73 74 64 6F 6C
65 32 2E 74 6C 62 57 57 57
|
success or wait |
627906125 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 512 Value: FF FF FF FF DC 06 00 00 C8 0D 00 00 FF FF FF FF 4C 06 00
00 FF FF FF FF 00 08 00 00 D8 0B 00 00 FF FF FF FF FF FF FF FF FF FF FF FF E8 0B 00
00 90 0D 00 00 28 0A 00 00 34 04 00 00 FF FF FF FF E4 07 00 00 34 02 00 00 44 0C 00
00 FF FF FF FF FF FF FF FF FF FF FF FF 94 04 00 00 20 0B 00 00 D0 07 00 00
|
success or wait |
627906698 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 3760 Value: FF FF FF FF FF FF FF FF 15 00 B9 EB 53 68 6F 63 6B 77
61 76 65 46 6C 61 73 68 4F 62 6A 65 63 74 73 57 57 57 00 00 00 00 FF FF FF FF 0F 38
D6 B5 49 53 68 6F 63 6B 77 61 76 65 46 6C 61 73 68 57 64 00 00 00 FF FF FF FF 13 38
01 03 49 43 61 6E 48 61 6E 64 6C 65 45 78 63 65 70 74 69 6F 6E 57 C8 00 00 00
|
success or wait |
627909202 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 1552 Value: 0F 00 53 68 6F 63 6B 77 61 76 65 20 46 6C 61 73 68 57
57 57 23 00 45 76 65 6E 74 20 69 6E 74 65 72 66 61 63 65 20 66 6F 72 20 53 68 6F 63
6B 77 61 76 65 20 46 6C 61 73 68 57 57 57 17 00 49 46 6C 61 73 68 46 61 63 74 6F 72
79 20 49 6E 74 65 72 66 61 63 65 57 57 57 1F 00 49 46 6C 61 73 68 4F 62 6A 65
|
success or wait |
627911629 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 368 Value: 1D 00 FF 7F 01 00 00 00 1A 00 FF 7F 00 00 00 00 1A 00 0C
40 0C 00 0C 80 1D 00 FF 7F 25 00 00 00 1A 00 FF 7F 18 00 00 00 1A 00 00 40 18 00 00
80 1A 00 FE 7F 28 00 00 00 1A 00 13 40 17 00 13 80 1D 00 FF 7F 31 00 00 00 1A 00 FF
7F 40 00 00 00 1A 00 10 40 10 00 10 80 1A 00 FE 7F 50 00 00 00 1A 00 03 40
|
success or wait |
627912143 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 60 12 00 00
|
success or wait |
627913713 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627913975 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 30 Value: 00 00 03 00 03 80 00 00 00 00 00 00 34 00 14 04 00 00 00
00 00 00 00 00 00 00 A8 00 00 00
|
success or wait |
627914249 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627919710 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 30 Value: 01 00 03 00 03 80 00 00 00 00 04 00 34 00 14 04 01 00 00
00 00 00 00 00 00 00 C0 00 00 00
|
success or wait |
627919987 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627922061 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 30 Value: 02 00 0B 00 0B 80 00 00 00 00 08 00 34 00 14 04 03 00 00
00 00 00 00 00 00 00 D8 00 00 00
|
success or wait |
627922335 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
627924398 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 30 Value: 03 00 18 00 00 80 00 00 00 00 0C 00 44 00 24 04 02 00 01
00 00 00 00 00 00 00 D8 00 00 00
|
success or wait |
627924670 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 12 Value: 0B 00 0B 80 FF FF FF FF 01 00 00 00
|
success or wait |
627924932 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627925191 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 30 Value: 04 00 16 00 03 80 00 00 00 00 10 00 34 00 14 04 05 00 00
00 00 00 00 00 00 00 EC 00 00 00
|
success or wait |
627925462 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
627927667 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 30 Value: 05 00 18 00 00 80 00 00 00 00 14 00 44 00 24 04 04 00 01
00 00 00 00 00 00 00 EC 00 00 00
|
success or wait |
627927940 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 12 Value: 16 00 03 80 FF FF FF FF 01 00 00 00
|
success or wait |
627928201 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627928460 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 30 Value: 06 00 16 00 03 80 00 00 00 00 18 00 34 00 14 04 07 00 00
00 00 00 00 00 00 00 00 01 00 00
|
success or wait |
627928733 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
627930910 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 12 Value: 16 00 03 80 FF FF FF FF 01 00 00 00
|
success or wait |
627931979 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627932237 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
627934803 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 12 Value: 16 00 03 80 FF FF FF FF 01 00 00 00
|
success or wait |
627935337 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627935594 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
627938081 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627938869 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
627941204 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 12 Value: 0B 00 0B 80 FF FF FF FF 01 00 00 00
|
success or wait |
627941738 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627941995 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
627944333 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627945123 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
627947498 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
627949101 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627950704 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627953185 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627955579 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627957926 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627960444 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627962791 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
627965142 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627965937 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627968426 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627970806 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
627973143 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627973933 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627976789 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
627979277 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627980069 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
627982409 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627983201 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
627985539 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 12 Value: 0B 00 0B 80 FF FF FF FF 01 00 00 00
|
success or wait |
627986075 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627986334 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
627989013 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627989978 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
627992324 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627993115 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
627995453 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 12 Value: 0B 00 0B 80 FF FF FF FF 01 00 00 00
|
success or wait |
627995986 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627996242 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
627998726 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 12 Value: 0B 00 0B 80 FF FF FF FF 01 00 00 00
|
success or wait |
627999259 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
627999516 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
628001869 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
628002659 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
628005017 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
628008192 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
628008979 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
628393437 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
628394238 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
628401354 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
628417517 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
628420185 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
628421020 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
628424182 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
628424975 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
628429289 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
628430088 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
628432429 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
628433715 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
628437494 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
628439261 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
628441617 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 12 Value: 0B 00 0B 80 FF FF FF FF 01 00 00 00
|
success or wait |
628442154 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
628442413 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
628445960 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
628448450 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 12 Value: 0B 00 0B 80 FF FF FF FF 01 00 00 00
|
success or wait |
628449527 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
628449789 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
628452113 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
628452901 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
628455226 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
628456012 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
628456799 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
628457582 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
628460099 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
628462420 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 20 00
|
success or wait |
628463209 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 2C 00
|
success or wait |
628465567 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 00 00 00 00
|
success or wait |
628521067 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 00 00 00 00
|
success or wait |
628541730 |
File read |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 0 Value: unknown
|
success or wait |
628560712 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 4D 53 46 54
|
success or wait |
628560915 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 02 00 01 00
|
success or wait |
628561199 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 00 00 00 00
|
success or wait |
628561427 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 09 04 00 00
|
success or wait |
628561655 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 00 00 00 00
|
success or wait |
628561883 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 41 00
|
success or wait |
628562112 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 00 00
|
success or wait |
628562340 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 01 00
|
success or wait |
628562565 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 2 Value: 00 00
|
success or wait |
628562791 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 04 00 00 00
|
success or wait |
628563020 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 0B 00 00 00
|
success or wait |
628563247 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 00 00 00 00
|
success or wait |
628563475 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 00 00 00 00
|
success or wait |
628563734 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 00 00 00 00
|
success or wait |
628563962 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: A4 00 00 00
|
success or wait |
628564189 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 0E 06 00 00
|
success or wait |
628564418 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 00 00 00 00
|
success or wait |
628564644 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: FF FF FF FF
|
success or wait |
628564873 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: FF FF FF FF
|
success or wait |
628565099 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 20 00 00 00
|
success or wait |
628565327 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 80 00 00 00
|
success or wait |
628565555 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 19 00 00 00
|
success or wait |
628565782 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 4 Value: 13 00 00 00
|
success or wait |
628566008 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 44 Value: 00 00 00 00 64 00 00 00 C8 00 00 00 2C 01 00 00 90 01 00
00 F4 01 00 00 58 02 00 00 BC 02 00 00 20 03 00 00 84 03 00 00 E8 03 00 00
|
success or wait |
628566287 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 16 Value: FF FF FF FF 00 00 00 00 FF FF FF FF 0F 00 00 00
|
success or wait |
628568887 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 16 Value: FF FF FF FF 00 00 00 00 FF FF FF FF 0F 00 00 00
|
success or wait |
628569125 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 16 Value: FF FF FF FF 00 00 00 00 FF FF FF FF 0F 00 00 00
|
success or wait |
628569361 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 16 Value: FF FF FF FF 00 00 00 00 FF FF FF FF 0F 00 00 00
|
success or wait |
628569599 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 16 Value: FF FF FF FF 00 00 00 00 FF FF FF FF 0F 00 00 00
|
success or wait |
628569835 |
File read |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 0 Value: unknown
|
success or wait |
628571196 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
628573854 |
Key created |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4842121D-869E-477A-B4FC-307D2E2C6066} |
success or wait |
628575040 |
Key created |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4842121D-869E-477A-B4FC-307D2E2C6066}\1.0 |
success or wait |
628580410 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4842121D-869E-477A-B4FC-307D2E2C6066}\1.0
Name: NULL
|
object name not found |
628581658 |
Key value replaced with new |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4842121D-869E-477A-B4FC-307D2E2C6066}\1.0
Name: NULL Type: unicode Data: Shockwave Flash Old data:
|
success or wait |
628582246 |
Key created |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4842121D-869E-477A-B4FC-307D2E2C6066}\1.0\FLAGS |
success or wait |
628583800 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4842121D-869E-477A-B4FC-307D2E2C6066}\1.0\FLAGS
Name: NULL
|
object name not found |
628584947 |
Key value replaced with new |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4842121D-869E-477A-B4FC-307D2E2C6066}\1.0\FLAGS
Name: NULL Type: unicode Data: 4 Old data:
|
success or wait |
628585510 |
Key created |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4842121D-869E-477A-B4FC-307D2E2C6066}\1.0\0 |
success or wait |
628587217 |
Key created |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4842121D-869E-477A-B4FC-307D2E2C6066}\1.0\0\win32 |
success or wait |
628589357 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4842121D-869E-477A-B4FC-307D2E2C6066}\1.0\0\win32
Name: NULL
|
object name not found |
628590544 |
Key value replaced with new |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4842121D-869E-477A-B4FC-307D2E2C6066}\1.0\0\win32
Name: NULL Type: unicode Data: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd
Old data:
|
success or wait |
628591257 |
Key created |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4842121D-869E-477A-B4FC-307D2E2C6066}\1.0\HELPDIR |
success or wait |
628593182 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4842121D-869E-477A-B4FC-307D2E2C6066}\1.0\HELPDIR
Name: NULL
|
object name not found |
628594834 |
Key value replaced with new |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4842121D-869E-477A-B4FC-307D2E2C6066}\1.0\HELPDIR
Name: NULL Type: unicode Data: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0 Old data:
|
success or wait |
628595482 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6C-AE6D-11CF-96B8-444553540000}
Name: NULL
|
success or wait |
628597265 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6D-AE6D-11CF-96B8-444553540000}
Name: NULL
|
success or wait |
628598308 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{86230738-D762-4C50-A2DE-A753E5B1686F}
Name: NULL
|
success or wait |
628599350 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Access:
read attributes and synchronize and generic read Options: synchronous io non alert
and non directory file and random access Attributes: none Content Overwritten: true
|
success or wait |
628600997 |
File read |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Offset:
unknown Length: 64 Value: 4D 53 46 54 02 00 01 00 00 00 00 00 09 04 00 00 00 00 00
00 41 00 00 00 01 00 00 00 04 00 00 00 0B 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 A4 00 00 00 0E 06 00 00 00 00 00 00 FF FF FF FF
|
success or wait |
628602903 |
Section loaded |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd Access:
query and read Type: commit Baseaddress: 3010000 Size: 20480 Protection: readonly
Mapped to pid: own pid
|
success or wait |
628603543 |
File opened |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Access: read attributes and
synchronize and generic read Options: synchronous io non alert and non directory file
and random access Attributes: none Content Overwritten: true
|
success or wait |
628604829 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 64 Value:
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 18 01 00 00
|
success or wait |
628605808 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 4 Value:
50 45 00 00
|
success or wait |
628606583 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 20 Value:
4C 01 07 00 A1 BD 39 4F 00 00 00 00 00 00 00 00 E0 00 02 21
|
success or wait |
628606798 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 40 Value:
2E 74 65 78 74 00 00 00 B9 0A 66 00 00 10 00 00 00 0C 66 00 00 04 00 00 00 00 00 00
00 00 00 00 00 00 00 00 20 00 00 60
|
success or wait |
628607202 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 40 Value:
2E 72 6F 64 61 74 61 00 E0 10 00 00 00 20 66 00 00 12 00 00 00 10 66 00 00 00 00 00
00 00 00 00 00 00 00 00 20 00 00 60
|
success or wait |
628607435 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 40 Value:
2E 72 64 61 74 61 00 00 32 1D 14 00 00 40 66 00 00 1E 14 00 00 22 66 00 00 00 00 00
00 00 00 00 00 00 00 00 40 00 00 40
|
success or wait |
628607664 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 40 Value:
2E 64 61 74 61 00 00 00 C4 7F 11 00 00 60 7A 00 00 E6 02 00 00 40 7A 00 00 00 00 00
00 00 00 00 00 00 00 00 40 00 00 C0
|
success or wait |
628607892 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 40 Value:
2E 72 6F 64 61 74 61 00 A0 04 00 00 00 E0 8B 00 00 06 00 00 00 26 7D 00 00 00 00 00
00 00 00 00 00 00 00 00 40 00 00 C0
|
success or wait |
628608121 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 40 Value:
2E 72 73 72 63 00 00 00 0C 0D 02 00 00 F0 8B 00 00 0E 02 00 00 2C 7D 00 00 00 00 00
00 00 00 00 00 00 00 00 40 00 00 40
|
success or wait |
628608349 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 16 Value:
00 00 00 00 00 00 00 00 04 00 00 00 02 00 0A 00
|
success or wait |
628608958 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 8 Value:
E0 11 00 80 70 00 00 80
|
success or wait |
628609199 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 2 Value:
08 00
|
success or wait |
628609786 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 8 Value:
F2 11 00 80 90 00 00 80
|
success or wait |
628610179 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 2 Value:
07 00
|
success or wait |
628610764 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 14 Value:
54 00 59 00 50 00 45 00 4C 00 49 00 42 00
|
success or wait |
628610969 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 16 Value:
00 00 00 00 00 00 00 00 04 00 00 00 00 00 02 00
|
success or wait |
628611937 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 8 Value:
01 00 00 00 48 02 00 80
|
success or wait |
628612344 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 16 Value:
00 00 00 00 00 00 00 00 04 00 00 00 00 00 01 00
|
success or wait |
628613118 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 8 Value:
1F 04 00 00 B0 08 00 00
|
success or wait |
628613333 |
File read |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Offset: unknown Length: 16 Value:
34 24 8C 00 50 37 00 00 E4 04 00 00 00 00 00 00
|
success or wait |
628613910 |
Section loaded |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Access: query and read Type:
commit Baseaddress: 3000000 Size: 40960 Protection: readonly Mapped to pid: own pid
|
success or wait |
628614179 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
628614827 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0
Name: NULL
|
success or wait |
628616090 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0\FLAGS
Name: NULL
|
success or wait |
628617021 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0\0\win32
Name: NULL
|
success or wait |
628618379 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6C-AE6D-11CF-96B8-444553540000}
Name: NULL
|
success or wait |
628619762 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6C-AE6D-11CF-96B8-444553540000}\ProxyStubClsid
Name: NULL
|
success or wait |
628621219 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6C-AE6D-11CF-96B8-444553540000}\ProxyStubClsid32
Name: NULL
|
success or wait |
628622313 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6C-AE6D-11CF-96B8-444553540000}\TypeLib
Name: NULL
|
success or wait |
628623335 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6C-AE6D-11CF-96B8-444553540000}\TypeLib
Name: Version
|
success or wait |
628623894 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6D-AE6D-11CF-96B8-444553540000}
Name: NULL
|
success or wait |
628625076 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6D-AE6D-11CF-96B8-444553540000}\ProxyStubClsid
Name: NULL
|
success or wait |
628625910 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6D-AE6D-11CF-96B8-444553540000}\ProxyStubClsid32
Name: NULL
|
success or wait |
628626998 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6D-AE6D-11CF-96B8-444553540000}\TypeLib
Name: NULL
|
success or wait |
628628017 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6D-AE6D-11CF-96B8-444553540000}\TypeLib
Name: Version
|
success or wait |
628628561 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{86230738-D762-4C50-A2DE-A753E5B1686F}
Name: NULL
|
success or wait |
628629760 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{86230738-D762-4C50-A2DE-A753E5B1686F}\ProxyStubClsid
Name: NULL
|
success or wait |
628630670 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{86230738-D762-4C50-A2DE-A753E5B1686F}\ProxyStubClsid32
Name: NULL
|
success or wait |
628631750 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{86230738-D762-4C50-A2DE-A753E5B1686F}\TypeLib
Name: NULL
|
success or wait |
628632762 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{86230738-D762-4C50-A2DE-A753E5B1686F}\TypeLib
Name: Version
|
success or wait |
628633309 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0\0\win32
Name: NULL
|
success or wait |
628637463 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{000204EF-0000-0000-C000-000000000046}\4.0\9\win32
Name: NULL
|
success or wait |
628641098 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020905-0000-0000-C000-000000000046}\8.3\0\win32
Name: NULL
|
success or wait |
628644655 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32
Name: NULL
|
success or wait |
628648190 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.3\0\win32
Name: NULL
|
success or wait |
628651788 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{D27CDB6E-AE6D-11CF-96B8-444553540000}
Name: Compatibility Flags
|
success or wait |
628676988 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
628677899 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
628678698 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32
Name: InprocServer32
|
object name not found |
628680777 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32
Name: NULL
|
success or wait |
628682728 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}
Name: AppID
|
object name not found |
628685033 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
628686831 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
628687605 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32
Name: InprocServer32
|
object name not found |
628689680 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32
Name: NULL
|
success or wait |
628691660 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}
Name: AppID
|
object name not found |
628693971 |
Process information queried |
PID: 1160 Info Class: SessionInformation |
success or wait |
628694779 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32
Name: ThreadingModel
|
success or wait |
628696038 |
File opened |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
628697841 |
Section loaded |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Access: write and read and execute
Type: commit Baseaddress: 3020000 Size: 8634368 Protection: execute Mapped to pid:
own pid
|
success or wait |
628698766 |
File opened |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
628700946 |
Section loaded |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx Access: query and write and
read and execute Type: image Baseaddress: 10000000 Size: 9596928 Protection: read
write Mapped to pid: own pid
|
success or wait |
628701860 |
File opened |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx.2.Manifest Access: read data
or list directory and read ea and execute or traverse and read attributes and read
control and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
object name not found |
629182835 |
File opened |
Path: C:\WINDOWS\system32\Macromed\Flash\Flash11f.ocx.2.Config Access: read data
or list directory and read ea and execute or traverse and read attributes and read
control and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
object name not found |
629183731 |
Section loaded |
Path: \KnownDlls\WINMM.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
629188022 |
File opened |
Path: C:\WINDOWS\system32\WINMM.dll Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
629188836 |
Section loaded |
Path: C:\WINDOWS\system32\winmm.dll Access: query and write and read and execute Type:
image Baseaddress: 76B40000 Size: 184320 Protection: read write Mapped to pid: own
pid
|
success or wait |
629189765 |
Section loaded |
Path: \KnownDlls\WININET.dll Access: write and read and execute Type: unknown Baseaddress:
3D930000 Size: 942080 Protection: read write Mapped to pid: own pid
|
success or wait |
629197804 |
Section loaded |
Path: \KnownDlls\Normaliz.dll Access: write and read and execute Type: unknown Baseaddress:
3030000 Size: 36864 Protection: read write Mapped to pid: own pid
|
conflicting addresses |
629205111 |
Section loaded |
Path: \KnownDlls\urlmon.dll Access: write and read and execute Type: unknown Baseaddress:
78130000 Size: 1257472 Protection: read write Mapped to pid: own pid
|
success or wait |
629215355 |
Section loaded |
Path: \KnownDlls\iertutil.dll Access: write and read and execute Type: unknown Baseaddress:
3DFD0000 Size: 2002944 Protection: read write Mapped to pid: own pid
|
success or wait |
629229817 |
Section loaded |
Path: \KnownDlls\CRYPT32.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
629241968 |
File opened |
Path: C:\WINDOWS\system32\CRYPT32.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
629242776 |
Section loaded |
Path: C:\WINDOWS\system32\crypt32.dll Access: query and write and read and execute
Type: image Baseaddress: 77A80000 Size: 610304 Protection: read write Mapped to pid:
own pid
|
success or wait |
629243665 |
Section loaded |
Path: \KnownDlls\MSASN1.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
629248823 |
File opened |
Path: C:\WINDOWS\system32\MSASN1.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
629249647 |
Section loaded |
Path: C:\WINDOWS\system32\msasn1.dll Access: query and write and read and execute
Type: image Baseaddress: 77B20000 Size: 73728 Protection: read write Mapped to pid:
own pid
|
success or wait |
629250560 |
Section loaded |
Path: \KnownDlls\DSOUND.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
629260068 |
File opened |
Path: C:\WINDOWS\system32\DSOUND.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
629261259 |
Section loaded |
Path: C:\WINDOWS\system32\dsound.dll Access: query and write and read and execute
Type: image Baseaddress: 73F10000 Size: 376832 Protection: read write Mapped to pid:
own pid
|
success or wait |
629262142 |
Section loaded |
Path: \KnownDlls\COMDLG32.dll Access: write and read and execute Type: unknown Baseaddress:
763B0000 Size: 299008 Protection: read write Mapped to pid: own pid
|
success or wait |
629277526 |
Section loaded |
Path: \KnownDlls\WS2_32.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
629653020 |
File opened |
Path: C:\WINDOWS\system32\WS2_32.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
629653886 |
Section loaded |
Path: C:\WINDOWS\system32\ws2_32.dll Access: query and write and read and execute
Type: image Baseaddress: 71AB0000 Size: 94208 Protection: read write Mapped to pid:
own pid
|
success or wait |
629654799 |
Section loaded |
Path: \KnownDlls\WS2HELP.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
629660900 |
File opened |
Path: C:\WINDOWS\system32\WS2HELP.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
629661717 |
Section loaded |
Path: C:\WINDOWS\system32\ws2help.dll Access: query and write and read and execute
Type: image Baseaddress: 71AA0000 Size: 32768 Protection: read write Mapped to pid:
own pid
|
success or wait |
629662630 |
Section loaded |
Path: \KnownDlls\d3d9.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
629669632 |
File opened |
Path: C:\WINDOWS\system32\d3d9.dll Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
629670787 |
Section loaded |
Path: C:\WINDOWS\system32\d3d9.dll Access: query and write and read and execute Type:
image Baseaddress: 4FDD0000 Size: 1728512 Protection: read write Mapped to pid: own
pid
|
success or wait |
629671915 |
Section loaded |
Path: \KnownDlls\d3d8thk.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
629675559 |
File opened |
Path: C:\WINDOWS\system32\d3d8thk.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
629676771 |
Section loaded |
Path: C:\WINDOWS\system32\d3d8thk.dll Access: query and write and read and execute
Type: image Baseaddress: 6D990000 Size: 24576 Protection: read write Mapped to pid:
own pid
|
success or wait |
629677684 |
Section loaded |
Path: \KnownDlls\mscms.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
629693564 |
File opened |
Path: C:\WINDOWS\system32\mscms.dll Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
629694364 |
Section loaded |
Path: C:\WINDOWS\system32\mscms.dll Access: query and write and read and execute Type:
image Baseaddress: 73B30000 Size: 86016 Protection: read write Mapped to pid: own
pid
|
success or wait |
629695794 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave
|
success or wait |
629717226 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave
|
success or wait |
629718000 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave1
|
success or wait |
629718706 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave1
|
success or wait |
629719454 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave2
|
object name not found |
629720152 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave3
|
object name not found |
629720675 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave4
|
object name not found |
629721382 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave5
|
object name not found |
629722084 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave6
|
object name not found |
629722787 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave7
|
object name not found |
629723708 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave8
|
object name not found |
629724410 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave9
|
object name not found |
629725107 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi
|
success or wait |
629725802 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi
|
success or wait |
629726527 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi1
|
success or wait |
629727215 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi1
|
success or wait |
629727941 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi2
|
object name not found |
629728644 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi3
|
object name not found |
629729346 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi4
|
object name not found |
629730046 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi5
|
object name not found |
629730787 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi6
|
object name not found |
629731539 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi7
|
object name not found |
629732237 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi8
|
object name not found |
629732985 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi9
|
object name not found |
629733732 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux
|
success or wait |
629734429 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux
|
success or wait |
629735149 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux1
|
success or wait |
629735835 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux1
|
success or wait |
629736556 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux2
|
object name not found |
629737779 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux3
|
object name not found |
629738475 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux4
|
object name not found |
629739173 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux5
|
object name not found |
629739873 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux6
|
object name not found |
629740566 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux7
|
object name not found |
629741265 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux8
|
object name not found |
629741963 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux9
|
object name not found |
629742710 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaProperties\PrivateProperties\Joystick\Winmm
Name: wheel
|
success or wait |
629743537 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer
|
success or wait |
629744359 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer
|
success or wait |
629745087 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer1
|
success or wait |
629745799 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer1
|
success or wait |
629746526 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer2
|
object name not found |
629747217 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer3
|
object name not found |
629747962 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer4
|
object name not found |
629748663 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer5
|
object name not found |
629749366 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer6
|
object name not found |
629750065 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer7
|
object name not found |
629750762 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer8
|
object name not found |
629751457 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer9
|
object name not found |
629752191 |
File opened |
Path: C:\WINDOWS\system32\urlmon.dll.123.Manifest Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
629756087 |
File opened |
Path: C:\WINDOWS\system32\urlmon.dll.123.Config Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
629757079 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
Access: execute or traverse and synchronize Options: directory file and synchronous
io non alert Overwritten: false
|
success or wait |
629798188 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
Name: DisableImprovedZoneCheck
|
object name not found |
629800630 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN
Name: WINWORD.EXE
|
object name not found |
629803310 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN
Name: *
|
object name not found |
629803882 |
File opened |
Path: WMIDataDevice Access: read attributes and synchronize and generic read and generic
write Options: non directory file Attributes: normal Content Overwritten: true
|
success or wait |
629809061 |
File opened |
Path: WMIDataDevice Access: read attributes and synchronize and generic read and generic
write Options: non directory file Attributes: normal Content Overwritten: true
|
success or wait |
629811449 |
Thread created |
PID: 1160 TID: 1904 EIP: 7C8106F9 EAX: 77DF848A Imagepath: C:\Program Files\Microsoft
Office\OFFICE11\WINWORD.EXE
|
success or wait |
629814033 |
Thread resumed |
TID: 1904 PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE |
success or wait |
629814989 |
File opened |
Path: C:\WINDOWS\system32\WININET.dll.123.Manifest Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
629820365 |
File opened |
Path: C:\WINDOWS\system32\WININET.dll.123.Config Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
629821354 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
Access: execute or traverse and synchronize Options: directory file and synchronous
io non alert Overwritten: false
|
success or wait |
629861652 |
Mutant created |
Name: \BaseNamedObjects\DirectSound DllMain mutex (0x00000488) |
success or wait |
629868311 |
Mutant created |
Name: unknown |
success or wait |
629870062 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectX Name: GlitchInstrumentation |
object name not found |
629874581 |
System info queried |
Type: ProcessorInformation |
success or wait |
629875849 |
Mutant created |
Name: \BaseNamedObjects\DDrawWindowListMutex |
success or wait |
629898416 |
Mutant created |
Name: \BaseNamedObjects\__DDrawExclMode__ |
success or wait |
629898867 |
Mutant created |
Name: \BaseNamedObjects\__DDrawCheckExclMode__ |
success or wait |
629899297 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D Name: GeometryDriver |
object name not found |
629905585 |
Key value replaced with new |
Path: HKEY_USERS\Software\Microsoft\Direct3D\MostRecentApplication Name: Name Type:
unicode Data: WINWORD.EXE Old data: iexplore.exe
|
success or wait |
629907245 |
System info queried |
Type: ProcessorInformation |
success or wait |
629935193 |
Mutant created |
Name: \BaseNamedObjects\{1B655094-FE2A-433c-A877-FF9793445069} |
success or wait |
629939352 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
629949002 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
629949765 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32
Name: InprocServer32
|
object name not found |
629952541 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32
Name: NULL
|
success or wait |
629954512 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}
Name: AppID
|
object name not found |
629956756 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 400E6 |
success |
629980233 |
System info queried |
Type: ProcessorInformation |
success or wait |
629981463 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Name: ~MHz |
success or wait |
629985970 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
629986805 |
File opened |
Path: C:\WINDOWS\system32\Macromed\Flash\ss.sgn Access: read attributes and synchronize
Options: synchronous io non alert and non directory file Attributes: none Content
Overwritten: true
|
object name not found |
629989205 |
File opened |
Path: C:\WINDOWS\system32\Macromed\Flash\ Access: read data or list directory and
synchronize Options: directory file and synchronous io non alert and open for backup
ident Overwritten: false
|
success or wait |
629989878 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
629991377 |
File opened |
Path: C:\WINDOWS\system32\Macromed\Flash\ss.cfg Access: read attributes and synchronize
Options: synchronous io non alert and non directory file Attributes: none Content
Overwritten: true
|
object name not found |
629992481 |
File opened |
Path: C:\WINDOWS\system32\Macromed\Flash\ Access: read data or list directory and
synchronize Options: directory file and synchronous io non alert and open for backup
ident Overwritten: false
|
success or wait |
629993130 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
629995757 |
File opened |
Path: C:\WINDOWS\system32\Macromed\Flash\ss.sgn Access: read attributes and synchronize
Options: synchronous io non alert and non directory file Attributes: none Content
Overwritten: true
|
object name not found |
629996869 |
File opened |
Path: C:\WINDOWS\system32\Macromed\Flash\ Access: read data or list directory and
synchronize Options: directory file and synchronous io non alert and open for backup
ident Overwritten: false
|
success or wait |
629997554 |
File opened |
Path: C:\WINDOWS\system32\Macromed\Flash\mms.cfg Access: read attributes and synchronize
and generic read Options: sequential only and synchronous io non alert and non directory
file Attributes: none Content Overwritten: true
|
object name not found |
629999082 |
File opened |
Path: C:\WINDOWS\system32\Macromed\Flash\mms.cfg Access: read attributes and synchronize
and generic read Options: sequential only and synchronous io non alert and non directory
file Attributes: none Content Overwritten: true
|
object name not found |
629999752 |
File opened |
Path: C:\WINDOWS\system32\mms.cfg Access: read attributes and synchronize and generic
read Options: sequential only and synchronous io non alert and non directory file
Attributes: none Content Overwritten: true
|
object name not found |
630000792 |
File opened |
Path: C:\WINDOWS\system32\mms.cfg Access: read attributes and synchronize and generic
read Options: sequential only and synchronous io non alert and non directory file
Attributes: none Content Overwritten: true
|
object name not found |
630001504 |
File opened |
Path: C:\WINDOWS\system32\Macromed\Flash\oem.cfg Access: read attributes and synchronize
and generic read Options: sequential only and synchronous io non alert and non directory
file Attributes: none Content Overwritten: true
|
object name not found |
630002205 |
File opened |
Path: C:\WINDOWS\system32\Macromed\Flash\oem.cfg Access: read attributes and synchronize
and generic read Options: sequential only and synchronous io non alert and non directory
file Attributes: none Content Overwritten: true
|
object name not found |
630002871 |
File opened |
Path: C:\WINDOWS\system32\oem.cfg Access: read attributes and synchronize and generic
read Options: sequential only and synchronous io non alert and non directory file
Attributes: none Content Overwritten: true
|
object name not found |
630003539 |
File opened |
Path: C:\WINDOWS\system32\oem.cfg Access: read attributes and synchronize and generic
read Options: sequential only and synchronous io non alert and non directory file
Attributes: none Content Overwritten: true
|
object name not found |
630004235 |
System info queried |
Type: ProcessorInformation |
success or wait |
630015493 |
System info queried |
Type: ProcessorInformation |
success or wait |
630017136 |
System info queried |
Type: ProcessorInformation |
success or wait |
630018880 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Name: AppData
|
success or wait |
630069175 |
Key value replaced with same |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Name: AppData Type: unicode Data: C:\Documents and Settings\Administrator\Application
Data Old data:
|
success or wait |
630070991 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630071658 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Adobe\Flash Player\AssetCache
Access: read attributes and synchronize Options: synchronous io non alert and non
directory file Attributes: none Content Overwritten: true
|
file is a directory |
630072863 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Adobe\Flash Player\
Access: read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
630074789 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Adobe\Flash Player\AssetCache\
Access: read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
630080378 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 400F0 |
success |
630106012 |
Section loaded |
Path: \KnownDlls\ieframe.dll Access: write and read and execute Type: unknown Baseaddress:
3E1C0000 Size: 11096064 Protection: read write Mapped to pid: own pid
|
success or wait |
630106920 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\IEXPLORE.EXE
Name:
|
success or wait |
630119694 |
File opened |
Path: C:\Program Files\Internet Explorer\IEXPLORE.EXE Access: read attributes and
synchronize Options: synchronous io non alert and non directory file Attributes: normal
Content Overwritten: true
|
success or wait |
630120349 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Setup Name: IExploreLastModifiedLow |
success or wait |
630121769 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Setup Name: IExploreLastModifiedHigh |
success or wait |
630122524 |
File opened |
Path: C:\WINDOWS\system32\ieframe.dll.123.Manifest Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
630148500 |
File opened |
Path: C:\WINDOWS\system32\ieframe.dll.123.Config Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
630149422 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
Access: execute or traverse and synchronize Options: directory file and synchronous
io non alert Overwritten: false
|
success or wait |
630188988 |
File opened |
Path: C:\WINDOWS\system32\en-US\ieframe.dll.mui Access: read attributes and synchronize
and generic read Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630192186 |
Section loaded |
Path: C:\WINDOWS\system32\en-us\ieframe.dll.mui Access: query and read Type: commit
Baseaddress: 35B0000 Size: 1241088 Protection: write copy Mapped to pid: own pid
|
success or wait |
630193247 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EAB22AC1-30C1-11CF-A7EB-0000C05BAE0B}\TypeLib
Name: NULL
|
success or wait |
630199809 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Setup Name: InstallStarted |
object name not found |
630200837 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B722BCCB-4E68-101B-A2BC-00AA00404770}\ProxyStubClsid32
Name: NULL
|
success or wait |
630201818 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{79EAC9C4-BAF9-11CE-8C82-00AA004BA90B}\ProxyStubClsid32
Name: NULL
|
success or wait |
630202804 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{000214E6-0000-0000-C000-000000000046}\ProxyStubClsid32
Name: NULL
|
success or wait |
630203776 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{93F2F68C-1D1B-11D3-A30E-00C04F79ABD1}\ProxyStubClsid32
Name: NULL
|
success or wait |
630204741 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{D27CDB6E-AE6D-11CF-96B8-444553540000}
Name: Compatibility Flags
|
success or wait |
630214325 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0002E005-0000-0000-C000-000000000046}
Name: InsecureQI
|
object name not found |
630215664 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus\1
Name: NULL
|
success or wait |
630219612 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630221896 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630223051 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630226034 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 36E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630226842 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630228381 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 36E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630229183 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630231416 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 36E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630232221 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630233718 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 36E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630234515 |
File opened |
Path: C:\WINDOWS\system32\Macromed\Flash\FlashAuthor.cfg Access: read attributes and
synchronize and generic read Options: sequential only and synchronous io non alert
and non directory file Attributes: none Content Overwritten: true
|
object name not found |
630236169 |
File opened |
Path: C:\WINDOWS\system32\Macromed\Flash\FlashAuthor.cfg Access: read attributes and
synchronize and generic read Options: sequential only and synchronous io non alert
and non directory file Attributes: none Content Overwritten: true
|
object name not found |
630236898 |
File opened |
Path: C:\WINDOWS\system32\Macromed\Flash\FlashPlayerTrust\ Access: read data or list
directory and synchronize Options: directory file and synchronous io non alert and
open for backup ident Overwritten: false
|
object name not found |
630237602 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#Security\FlashAuthor.cfg
Access: read attributes and synchronize and generic read Options: sequential only
and synchronous io non alert and non directory file Attributes: none Content Overwritten:
true
|
object path not found |
630238403 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#Security\FlashAuthor.cfg
Access: read attributes and synchronize and generic read Options: sequential only
and synchronous io non alert and non directory file Attributes: none Content Overwritten:
true
|
object path not found |
630239377 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#Security\FlashPlayerTrust\
Access: read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
object path not found |
630240248 |
File opened |
Path: C:\WINDOWS\system32 Access: execute or traverse and synchronize Options: directory
file and synchronous io non alert Overwritten: false
|
success or wait |
630241935 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders Name: SecurityProviders |
success or wait |
630247891 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders Name: SecurityProviders |
success or wait |
630248241 |
Section loaded |
Path: \KnownDlls\msapsspc.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
630248828 |
File opened |
Path: C:\WINDOWS\system32\msapsspc.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
630249869 |
Section loaded |
Path: C:\WINDOWS\system32\msapsspc.dll Access: query and write and read and execute
Type: image Baseaddress: 71E50000 Size: 86016 Protection: read write Mapped to pid:
own pid
|
success or wait |
630250648 |
Section loaded |
Path: \KnownDlls\MSVCRT40.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
630254355 |
File opened |
Path: C:\WINDOWS\system32\MSVCRT40.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
630255430 |
Section loaded |
Path: C:\WINDOWS\system32\msvcrt40.dll Access: query and write and read and execute
Type: image Baseaddress: 78080000 Size: 69632 Protection: read write Mapped to pid:
own pid
|
success or wait |
630256230 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName
Name: ComputerName
|
success or wait |
630271004 |
Section loaded |
Path: \KnownDlls\schannel.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
630271927 |
File opened |
Path: C:\WINDOWS\system32\schannel.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
630272637 |
Section loaded |
Path: C:\WINDOWS\system32\schannel.dll Access: query and write and read and execute
Type: image Baseaddress: 767F0000 Size: 163840 Protection: read write Mapped to pid:
own pid
|
success or wait |
630273426 |
Section loaded |
Path: \KnownDlls\NETAPI32.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
630278728 |
File opened |
Path: C:\WINDOWS\system32\NETAPI32.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
630279453 |
Section loaded |
Path: C:\WINDOWS\system32\netapi32.dll Access: query and write and read and execute
Type: image Baseaddress: 5B860000 Size: 348160 Protection: read write Mapped to pid:
own pid
|
success or wait |
630281560 |
Section loaded |
Path: \KnownDlls\digest.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
630295872 |
File opened |
Path: C:\WINDOWS\system32\digest.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
630297450 |
Section loaded |
Path: C:\WINDOWS\system32\digest.dll Access: query and write and read and execute
Type: image Baseaddress: 75B00000 Size: 86016 Protection: read write Mapped to pid:
own pid
|
success or wait |
630298232 |
Mutant created |
Name: unknown |
success or wait |
630309010 |
Section loaded |
Path: \KnownDlls\msnsspc.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
630309868 |
File opened |
Path: C:\WINDOWS\system32\msnsspc.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
630310953 |
Section loaded |
Path: C:\WINDOWS\system32\msnsspc.dll Access: query and write and read and execute
Type: image Baseaddress: 747B0000 Size: 290816 Protection: read write Mapped to pid:
own pid
|
success or wait |
630311744 |
Section loaded |
Path: \KnownDlls\MSVCRT40.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
630314754 |
File opened |
Path: C:\WINDOWS\system32\MSVCRT40.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
630315470 |
Section loaded |
Path: C:\WINDOWS\system32\msvcrt40.dll Access: query and write and read and execute
Type: image Baseaddress: 78080000 Size: 69632 Protection: read write Mapped to pid:
own pid
|
success or wait |
630316314 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName
Name: ComputerName
|
success or wait |
630323034 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\msapsspc.dll Name:
Name
|
success or wait |
630324069 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\msapsspc.dll Name:
Name
|
success or wait |
630324412 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\msapsspc.dll Name:
Comment
|
success or wait |
630324771 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\msapsspc.dll Name:
Comment
|
success or wait |
630325113 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\msapsspc.dll Name:
Capabilities
|
success or wait |
630325448 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\msapsspc.dll Name:
RpcId
|
success or wait |
630325786 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\msapsspc.dll Name:
Version
|
success or wait |
630326122 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\msapsspc.dll Name:
Type
|
success or wait |
630326456 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\msapsspc.dll Name:
TokenSize
|
success or wait |
630326792 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\digest.dll Name:
Name
|
success or wait |
630327638 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\digest.dll Name:
Name
|
success or wait |
630327978 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\digest.dll Name:
Comment
|
success or wait |
630328315 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\digest.dll Name:
Comment
|
success or wait |
630328654 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\digest.dll Name:
Capabilities
|
success or wait |
630328992 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\digest.dll Name:
RpcId
|
success or wait |
630329327 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\digest.dll Name:
Version
|
success or wait |
630329664 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\digest.dll Name:
Type
|
success or wait |
630330001 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\digest.dll Name:
TokenSize
|
success or wait |
630330337 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\msnsspc.dll Name:
Name
|
success or wait |
630331184 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\msnsspc.dll Name:
Name
|
success or wait |
630331521 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\msnsspc.dll Name:
Comment
|
success or wait |
630331853 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\msnsspc.dll Name:
Comment
|
success or wait |
630332186 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\msnsspc.dll Name:
Capabilities
|
success or wait |
630332521 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\msnsspc.dll Name:
RpcId
|
success or wait |
630332857 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\msnsspc.dll Name:
Version
|
success or wait |
630333194 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\msnsspc.dll Name:
Type
|
success or wait |
630333525 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\msnsspc.dll Name:
TokenSize
|
success or wait |
630333862 |
File opened |
Path: C:\WINDOWS\system32\schannel.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
630335419 |
Section loaded |
Path: C:\WINDOWS\system32\schannel.dll Access: write and read and execute Type: commit
Baseaddress: 36E0000 Size: 151552 Protection: execute Mapped to pid: own pid
|
success or wait |
630336535 |
File opened |
Path: C:\WINDOWS\system32\schannel.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
630339418 |
Section loaded |
Path: C:\WINDOWS\system32\schannel.dll Access: query and write and read and execute
Type: image Baseaddress: 767F0000 Size: 163840 Protection: read write Mapped to pid:
own pid
|
success or wait |
630340192 |
Section loaded |
Path: \KnownDlls\NETAPI32.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
630344857 |
File opened |
Path: C:\WINDOWS\system32\NETAPI32.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
630345552 |
Section loaded |
Path: C:\WINDOWS\system32\netapi32.dll Access: query and write and read and execute
Type: image Baseaddress: 5B860000 Size: 348160 Protection: read write Mapped to pid:
own pid
|
success or wait |
630346336 |
File opened |
Path: C:\Program Files\AutoIt3 Access: execute or traverse and synchronize Options:
directory file and synchronous io non alert Overwritten: false
|
success or wait |
630356579 |
System info queried |
Type: ProcessorInformation |
success or wait |
630358231 |
System info queried |
Type: ProcessorInformation |
success or wait |
630380127 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630391432 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects
Access: read attributes and synchronize Options: synchronous io non alert and non
directory file Attributes: none Content Overwritten: true
|
file is a directory |
630392944 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\
Access: read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
630393754 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\
Access: read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
630395182 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630398218 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\WT8AYZWL\macromedia.com\support\flashplayer\sys\settings.sol
Access: read attributes and synchronize Options: synchronous io non alert and non
directory file Attributes: none Content Overwritten: true
|
object path not found |
630399366 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\WT8AYZWL\macromedia.com\support\flashplayer\sys\
Access: read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
object path not found |
630401364 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630404591 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol
Access: read attributes and synchronize Options: synchronous io non alert and non
directory file Attributes: none Content Overwritten: true
|
success or wait |
630405806 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630411449 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol
Access: read attributes and synchronize Options: synchronous io non alert and non
directory file Attributes: none Content Overwritten: true
|
success or wait |
630412584 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol
Access: read attributes and synchronize and generic read Options: sequential only
and synchronous io non alert and non directory file Attributes: none Content Overwritten:
true
|
success or wait |
630414879 |
File read |
Path: C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol
Offset: unknown Length: 16384 Value: 00 BF 00 00 02 12 54 43 53 4F 00 04 00 00 00
00 00 08 73 65 74 74 69 6E 67 73 00 00 00 00 00 07 64 6F 6D 61 69 6E 73 03 00 09 61
64 6F 62 65 2E 63 6F 6D 01 01 00 0E 6D 61 63 72 6F 6D 65 64 69 61 2E 63 6F 6D 01 01
00 0D 77 77 77 2E 61 64 6F 62 65 2E 63 6F 6D 01 01 00 0E 61 64 73 32 2E 6D 73 61 64
73
|
success or wait |
630420102 |
Thread created |
PID: 1160 TID: 292 EIP: 7C8106F9 EAX: 101DFB97 Imagepath: C:\Program Files\Microsoft
Office\OFFICE11\WINWORD.EXE
|
success or wait |
630541640 |
Thread resumed |
TID: 292 PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE |
success or wait |
630542449 |
System info queried |
Type: ProcessorInformation |
success or wait |
630547022 |
System info queried |
Type: ProcessorInformation |
success or wait |
630567176 |
System info queried |
Type: ProcessorInformation |
success or wait |
630567630 |
System info queried |
Type: ProcessorInformation |
success or wait |
630568066 |
System info queried |
Type: ProcessorInformation |
success or wait |
630569993 |
System info queried |
Type: ProcessorInformation |
success or wait |
630571119 |
System info queried |
Type: ProcessorInformation |
success or wait |
630573215 |
System info queried |
Type: ProcessorInformation |
success or wait |
630573618 |
System info queried |
Type: ProcessorInformation |
success or wait |
630574639 |
System info queried |
Type: ProcessorInformation |
success or wait |
630575087 |
System info queried |
Type: ProcessorInformation |
success or wait |
630575630 |
System info queried |
Type: ProcessorInformation |
success or wait |
630576141 |
System info queried |
Type: ProcessorInformation |
success or wait |
630576699 |
System info queried |
Type: ProcessorInformation |
success or wait |
630577378 |
System info queried |
Type: ProcessorInformation |
success or wait |
630578043 |
System info queried |
Type: ProcessorInformation |
success or wait |
630578444 |
System info queried |
Type: ProcessorInformation |
success or wait |
630579065 |
System info queried |
Type: ProcessorInformation |
success or wait |
630579804 |
System info queried |
Type: ProcessorInformation |
success or wait |
630580486 |
System info queried |
Type: ProcessorInformation |
success or wait |
630581099 |
System info queried |
Type: ProcessorInformation |
success or wait |
630583305 |
System info queried |
Type: ProcessorInformation |
success or wait |
630584234 |
System info queried |
Type: ProcessorInformation |
success or wait |
630585199 |
System info queried |
Type: ProcessorInformation |
success or wait |
630586158 |
System info queried |
Type: ProcessorInformation |
success or wait |
630586815 |
System info queried |
Type: ProcessorInformation |
success or wait |
630588222 |
System info queried |
Type: ProcessorInformation |
success or wait |
630588741 |
System info queried |
Type: ProcessorInformation |
success or wait |
630589156 |
System info queried |
Type: ProcessorInformation |
success or wait |
630589572 |
System info queried |
Type: ProcessorInformation |
success or wait |
630589979 |
System info queried |
Type: ProcessorInformation |
success or wait |
630590388 |
System info queried |
Type: ProcessorInformation |
success or wait |
630590859 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630646226 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630647418 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630649128 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630649917 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630651377 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630652169 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630654057 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630654865 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630656287 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630657082 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630658603 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630659721 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630661377 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630662169 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630663600 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630664391 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630666227 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630667017 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630668489 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630669286 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630670774 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630672797 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630674464 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630675255 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630676689 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630677516 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630679363 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630680159 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630682120 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630682916 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630684414 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630685529 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630687192 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630687983 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630689413 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630690263 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630692143 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630692939 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630694376 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630695169 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630696770 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630697899 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630699559 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630700348 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630701777 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630702568 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630704402 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630705196 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630706618 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630707409 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630708899 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630710020 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630711725 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630712519 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630714009 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630714802 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630716639 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630717431 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630718852 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630719643 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630721133 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630722249 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630723907 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630725230 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630726665 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630727758 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630731178 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630731990 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630733418 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630734215 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630735722 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630736843 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630738505 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630739313 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630740746 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630741542 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630743395 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630744193 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630745613 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630746404 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630747981 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630749105 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630750766 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630751557 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630752989 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630753823 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630755664 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630756457 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630757882 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630758675 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630760166 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630761279 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630762983 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630763778 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630765211 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630766004 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630768385 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630769237 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630770666 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630771458 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630772944 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630774064 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630775723 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630776511 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630777938 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630778730 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630780565 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630781360 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630782831 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630784487 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630786248 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630787373 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630789047 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630789837 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
630791268 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630792059 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630794713 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630796951 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630798508 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630799623 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630802070 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630804288 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630806909 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630809114 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630811144 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630812264 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630814708 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630816926 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630819543 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630821756 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630823245 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630824361 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630826847 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630829063 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630831693 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630833945 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630835436 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630836554 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630839140 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630842313 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630845008 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630849385 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630851032 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630852963 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630855975 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630858753 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630861380 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630864996 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630866495 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630867615 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630870115 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630872342 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630874975 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630877195 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630878688 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630879811 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630882297 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630884528 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630887164 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630889383 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630890871 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630891989 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630894458 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630897525 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630900327 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630902543 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630904128 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630905244 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630907734 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630909957 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630912627 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630914847 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630916328 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630917444 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630919882 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630922107 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630924733 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630926994 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630928534 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630929660 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630932168 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630934398 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630937035 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630939780 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630941265 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630942384 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630944837 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630947064 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630949685 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630952013 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630954865 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630955997 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630958452 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630962510 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630965399 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630967620 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630969888 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630971010 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630973466 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630977139 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630979778 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630982534 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630984037 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630985164 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630987612 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630989832 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630992461 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630994672 |
File opened |
Path: C:\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
630996183 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
630997325 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
630999835 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631002069 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631004700 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631046636 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
631304924 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631307492 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631311694 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631314387 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631316860 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
631320246 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631322745 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631327090 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631329746 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631331965 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
631334590 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631337078 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631339296 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631341949 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631344281 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
631347058 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631349509 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631351730 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631354396 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631356618 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
631359380 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631361827 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631364050 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631366686 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631369446 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
631372059 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631374501 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631376718 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631379346 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631381557 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
631384198 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631386646 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631388863 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631391540 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631393761 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
631396360 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631399165 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631401574 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631404218 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631406478 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
631409819 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631412816 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631415046 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631417670 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631419781 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
631422390 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631424833 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631427103 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631429789 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631432012 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
631434617 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631437062 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631439285 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631441954 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631444180 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
631446783 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631449252 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631451477 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631454475 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631566705 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
631569709 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631679635 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631681929 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631687489 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631690338 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
631693170 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631697341 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631699577 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631706632 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631710395 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
631716826 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631719318 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631722127 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631724779 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631733425 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
631737482 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631739938 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631742364 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631751191 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631753429 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
631757662 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631760122 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631769551 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631772359 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631774583 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
631784192 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631787705 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631790399 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631806530 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631808915 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
631811554 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631831248 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631833492 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631837177 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631855483 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
631858166 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631864778 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631867014 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631870660 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631881361 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: read attributes
and synchronize Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: true
|
success or wait |
631884237 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631887226 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631895884 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631898564 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631902203 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631913963 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631916336 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631919595 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631921815 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631928983 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631931699 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631935425 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631937648 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631945638 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631947869 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631950987 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631953190 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631962241 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631964462 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631967341 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631971934 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631978006 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631980285 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631984501 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631988462 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631994533 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
631998251 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632000932 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632003664 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632008726 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632010946 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632015447 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632017699 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632022796 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632025025 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632027654 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632029894 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632034946 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632037161 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632039791 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632042005 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632047075 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632049297 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632051922 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632054177 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632059746 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632061995 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632064626 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632066894 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632072769 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632075887 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632078544 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632081399 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632086846 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632089879 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632092531 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632096770 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632103230 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632105945 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632109217 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632111508 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632116608 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632118837 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632121471 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632123684 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632129181 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632131420 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632134047 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632136265 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632141328 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632144083 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632146766 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632148979 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632154092 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632156308 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632158980 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632161197 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632166270 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632168493 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632171112 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632173369 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632178432 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632180650 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632183798 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632186572 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632191638 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632193859 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632196521 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632198738 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632203812 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632206036 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632208665 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632210880 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632215993 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632218268 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632220903 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632223111 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632228225 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632231006 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632233642 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632235858 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632241280 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632243506 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632246185 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632248400 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632253465 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632255715 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632258388 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632260606 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632265648 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632267902 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632270527 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632273284 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632278331 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632280544 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632283158 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632285364 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632290496 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632292718 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632295983 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632298204 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632303284 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632305552 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632308183 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632310400 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632315980 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632318203 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632320828 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632323039 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632328078 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632330334 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632332985 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632335199 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632340295 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632342517 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632345165 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632347375 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632353113 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632355340 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632358484 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632360642 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632365757 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632367973 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632370596 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632372859 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632377905 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632380121 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632382741 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632385005 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632390102 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632392315 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632394934 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632397153 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632402741 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632404926 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632407845 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632410111 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632415174 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632417438 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632420070 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632422287 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632427330 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632429590 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632432285 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632434505 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632439551 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632441770 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632444934 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632447148 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632452202 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632454423 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632457042 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632459324 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632464798 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632467024 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632469654 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632471862 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632476955 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632479171 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632481824 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632484047 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632489630 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632491852 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632494480 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632496697 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632501780 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632504049 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632506679 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632508892 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632513937 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632516198 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632518970 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632521373 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632526451 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632528672 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632531826 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632534040 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632539130 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632541353 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632543973 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632546234 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632551276 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632553521 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632556149 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632558405 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632563459 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632565673 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632568287 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632570499 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632579452 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632581683 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632584310 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632586524 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632591630 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632593840 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632596468 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632598684 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632603759 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632605983 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632608617 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632610865 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632616465 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632618741 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632621368 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632623578 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632628648 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632631884 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632636589 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632638825 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632645221 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632647509 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632651453 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632653677 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632659270 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632661491 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632664119 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632666327 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632671368 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632673625 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632676256 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632678474 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632683518 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632686080 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632688771 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632690982 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632696030 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632698308 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632700935 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632703740 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632708781 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632710998 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632713618 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632715849 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632720950 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632723178 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632725800 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632728036 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632733123 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632735345 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632737967 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632740182 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632747107 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632749336 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632753823 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632756302 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632762158 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
632764380 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633148596 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633150889 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633157162 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633159447 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633162952 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633166734 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633171864 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633174635 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633177265 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633179485 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633184544 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633186766 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633189702 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633191926 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633196975 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633199253 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633201883 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633204142 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633209177 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633211391 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633214019 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633216230 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633221871 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633224099 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633226719 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633228934 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633234026 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633236243 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633238862 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633241081 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633246596 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633248822 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633251456 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633253667 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633258708 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633261460 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633264079 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633266289 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633271363 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633273586 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633276256 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633278473 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633283553 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633285778 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633288439 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633290661 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633295768 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633297987 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633300722 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633303497 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633308709 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633310937 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633313561 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633315768 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633320848 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633323118 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633325739 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633327954 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633333040 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633335264 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633337889 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633340099 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633345192 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633347945 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633350570 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633352779 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633358163 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633360590 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633363282 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633365509 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633370559 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633372774 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633375437 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633377651 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633382682 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633384933 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633387557 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633390320 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633395369 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633397583 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633400251 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633402523 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633407616 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633409832 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633412789 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633416481 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633421810 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633424034 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633426662 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633428881 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633434694 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633436943 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633439574 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633441796 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633446904 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633449124 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633451751 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633453969 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633459004 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633461268 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633463895 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633466111 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633471616 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633473845 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633477029 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633479251 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633484422 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633486651 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633489320 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633491536 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633496579 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633498801 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633501432 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633503685 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633508802 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633511022 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633513645 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633515860 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633521449 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633523810 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633526603 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633528820 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633533903 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633536134 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633538763 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633540868 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633545953 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633548186 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633550814 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633553031 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633558174 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633560929 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633563555 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633565781 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633570821 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633573039 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633575693 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633577973 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633583296 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633585544 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633588172 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633590411 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633595455 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633597678 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633600301 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633602513 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633608104 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633610325 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633612953 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633615170 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633620264 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633622487 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633625110 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633627359 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633632448 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633634678 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633637649 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633639867 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633644921 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633647699 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633650394 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633652605 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633657644 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633659866 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633662540 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633664755 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633669795 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633672013 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633674693 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633676915 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633681959 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633684174 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633686854 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633689616 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633695111 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633697339 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633699999 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633702212 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633707297 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633709518 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633712140 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633714406 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633719475 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633721757 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633724380 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633726593 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633732179 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633734406 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633737023 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633739240 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633744274 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633746530 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633749587 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633751805 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633756857 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633759077 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633761748 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633763965 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633769003 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633771276 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633773902 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633776643 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633781677 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633783890 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633786532 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633788748 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633793922 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633796143 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633798761 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633800972 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633806139 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633808574 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633811207 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633813420 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633819015 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633821242 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633823867 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633826082 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633831131 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633833382 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633836015 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633838260 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633843357 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633845575 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633848239 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633850459 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633855500 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633857723 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633861067 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633863460 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633868630 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633870852 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633873481 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633875735 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633880781 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633883007 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633885626 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633887865 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633892956 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633895189 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633897824 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633900047 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633905648 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633907876 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633910508 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633913590 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633919055 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633921280 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633923908 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633926121 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633931161 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633933404 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633936073 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633938296 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633943340 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633945564 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633948804 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633951022 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633956061 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633958281 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633960937 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633963158 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633968196 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633970414 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633973415 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633975678 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633980730 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633982943 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633985602 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633987825 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633993380 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633995594 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
633998216 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634000430 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634005517 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634007789 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634010413 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634012630 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634017671 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634019936 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634022559 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634024817 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634030298 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634033063 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634035697 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634037908 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634042976 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634045200 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634047863 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634050077 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634055122 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634057391 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634060013 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634062266 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634067317 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634069536 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634072162 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634074373 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634080001 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634082224 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634085320 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634087537 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634092658 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634094878 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634097505 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634099713 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634104848 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634107075 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634109696 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634111897 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634116927 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634119695 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634122324 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634124535 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634129614 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634131845 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634134501 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634136710 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634142273 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634144902 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634147570 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634149841 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634154893 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634157112 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634159734 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634162477 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634167525 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634169744 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634172370 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634174580 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634179726 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634181946 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634184572 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634186781 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634191852 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634194075 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634196882 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Access: write and read
and execute Type: commit Baseaddress: 39E0000 Size: 12312576 Protection: execute Mapped
to pid: own pid
|
success or wait |
634199294 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0\0\win32
Name: NULL
|
success or wait |
634204338 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
634210022 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
634210740 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
634211846 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
634212525 |
Process information queried |
PID: 1160 Info Class: SessionInformation |
success or wait |
634213123 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager Name: ForceNpxEmulation |
object name not found |
634231650 |
Mutant created |
Name: unknown |
success or wait |
634234577 |
File created |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~WRD0002.doc Access: read attributes and
synchronize and generic read and generic write Options: synchronous io non alert and
non directory file and open no recall Attributes: normal Content Overwritten: true
|
success or wait |
634237873 |
File created |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Access: read attributes and synchronize and generic write Options: sequential only
and synchronous io non alert and non directory file and open no recall Attributes:
temporary Content Overwritten: true
|
success or wait |
634249185 |
File opened |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Access: read attributes and synchronize and generic write Options: synchronous io
non alert and non directory file Attributes: normal Content Overwritten: true
|
success or wait |
634252763 |
File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 60 Value: 02 00 09 00 00 03 00 00 00 00 00 00 00 00 00 00
00 00 03 00 00 00 1E 00 05 00 00 00 0B 02 00 00 00 00 05 00 00 00 0C 02 C0 00 C0 00
05 00 00 00 07 01 04 00 00 00 22 D8 00 00 43 0F
|
success or wait |
634255651 |
File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 110654 Value: 20 00 CC 00 00 00 C0 00 C0 00 00 00 00 00 C0
00 C0 00 00 00 00 00 28 00 00 00 C0 00 00 00 40 FF FF FF 01 00 18 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF
|
success or wait |
634780970 |
File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 14 Value: 04 00 00 00 27 01 FF FF 03 00 00 00 00 00
|
success or wait |
634789015 |
File write |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 18 Value: 01 00 09 00 00 03 44 D8 00 00 00 00 22 D8 00 00
00 00
|
success or wait |
634789499 |
File opened |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Access: read attributes and synchronize and generic read Options: synchronous io non
alert and non directory file Attributes: none Content Overwritten: true
|
success or wait |
634791034 |
Section loaded |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Access: query and read Type: commit Baseaddress: 39F0000 Size: 114688 Protection:
readonly Mapped to pid: own pid
|
success or wait |
634792091 |
File opened |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Access: read attributes and synchronize and generic read Options: sequential only
and synchronous io non alert and non directory file and open no recall Attributes:
normal Content Overwritten: true
|
success or wait |
634793073 |
File opened |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Access: read attributes and synchronize and generic read Options: sequential only
and synchronous io non alert and non directory file and open no recall Attributes:
normal Content Overwritten: true
|
success or wait |
634795224 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: 01 00 09 00 00 03 44 D8 00 00 00 00 22 D8 00 00
00 00 03 00 00 00 1E 00 05 00 00 00 0B 02 00 00 00 00 05 00 00 00 0C 02 C0 00 C0 00
05 00 00 00 07 01 04 00 00 00 22 D8 00 00 43 0F 20 00 CC 00 00 00 C0 00 C0 00 00 00
00 00 C0 00 C0 00 00 00 00 00 28 00 00 00 C0 00 00 00 40 FF FF FF 01 00 18 00 00 00
|
success or wait |
634796672 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634873487 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634876212 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634878923 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634881630 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634884323 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634887332 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634890310 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634893572 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634896268 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634900977 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634903799 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634906514 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634909260 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634912029 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634914724 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634916764 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634919501 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634923397 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634926112 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634928909 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634931586 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634934820 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634937507 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634940221 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634942894 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 4096 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634945573 |
File read |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Offset: unknown Length: 136 Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634948815 |
File opened |
Path: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.MSO\3430B573.wmf
Access: read attributes and delete Options: non directory file and open for backup
ident and open reparse point Overwritten: false
|
success or wait |
634976602 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~WRD0002.doc Offset: unknown Length: 581
Value: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
634989114 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
634990890 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 Name: REGDBVersion |
success or wait |
634991572 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32
Name: InprocServer32
|
object name not found |
634993448 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32
Name: NULL
|
success or wait |
634997294 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}
Name: AppID
|
object name not found |
635001006 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID
Name: NULL
|
success or wait |
635002298 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0\0\win32
Name: NULL
|
success or wait |
635064595 |
Window shown |
HWND: 90058 CMD: show |
error |
635066230 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
635066842 |
Message sent |
HWND: 5012E Message: NCPAINT WParam: 1 LParam: 0 |
error |
635072231 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
635072880 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
635073118 |
Message sent |
HWND: 5012E Message: NCPAINT WParam: 1 LParam: 0 |
error |
635073375 |
Message sent |
HWND: 5012E Message: NCPAINT WParam: 1 LParam: 0 |
error |
635073818 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
635074059 |
Message sent |
HWND: 5012E Message: NCPAINT WParam: 1 LParam: 0 |
error |
635074297 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
635074534 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
635074766 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
635075618 |
Key value deleted |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems Keyname:
9
|
success or wait |
635077731 |
Key deleted |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\StartupItems |
success or wait |
635078628 |
Key deleted |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency |
success or wait |
635079409 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
HideFileExt
|
success or wait |
635080911 |
Key created |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency |
success or wait |
635086059 |
Key created |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\DocumentRecovery |
success or wait |
635086807 |
Key created |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\DocumentRecovery\2A9B4 |
success or wait |
635087646 |
Key value set |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Resiliency\DocumentRecovery\2A9B4
Name: 2A9B4 Type: binary Data: 04 00 00 00 88 04 00 00 44 00 00 00 43 00 3A 00 5C
00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00 6E 00 64 00 20
00 53 00 65 00 74 00 74 00 69 00 6E 00 67 00 73 00 5C 00 41 00 64 00 6D 00 69 00 6E
00 69 00 73 00 74 00 72 00 61 00 74 00 6F 00 72 00 5C 00 44 00 65 00 73 00 6B 00 74
00 6F 00 70 00 5C 00 69 00 50 00 68 00 6F 00 6E 00 65 00 20 00 35 00 20 00 42 00 61
00 74 00 74 00 65 00 72 00 79 00 2E 00 64 00 6F 00 63 00 10 00 00 00 69 00 50 00 68
00 6F 00 6E 00 65 00 20 00 35 00 20 00 42 00 61 00 74 00 74 00 65 00 72 00 79 00 00
00 00 00 01 00 00 00 00 00 00 00 C5 C4 CB 7C AB 7B CD 01 B4 A9 02 00 B4 A9 02 00 00
00 00 00 00 00 00 00 00 00 00 00 Old data:
|
success or wait |
635088903 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Outlook\Security Name: OutlookSecureTempFolder |
object name not found |
635090178 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\Common\Smart Tag Name: DisableDocumentAssemblies |
object name not found |
635091538 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\BaseSuite Name: 1EBDE4BC9A514630B5412561FA45CCC5 |
object name not found |
635091991 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\InstallRoot Name: InstallCount |
success or wait |
635092476 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Licensing Name: 1EBDE4BC9A514630B5412561FA45CCC5 |
object name not found |
635092883 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\ProductVersion Name:
ProInfo
|
success or wait |
635093360 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: NoTTP |
object name not found |
635101985 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Internet Name: UseOnlineContent |
success or wait |
635102335 |
Message posted |
HWND: 50136 Message: DDE_ACK WParam: 524352 LParam: 55447496 |
success |
635130760 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Word\Options Name: TOOLS-PATH |
object name not found |
635167600 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635168778 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635170637 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\General Name: Proof |
success or wait |
635171914 |
File created |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Attributes: normal Content Overwritten: true
|
success or wait |
635172742 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635176209 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools Location Name: proof |
object name not found |
635177828 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion Name: CommonFilesDir |
success or wait |
635178400 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\94BE92CC2CB71D119A12000A9CE1A22A
Name: 9040110900063D11C8EF10054038389C
|
success or wait |
635180066 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635184891 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635187106 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635189203 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635191331 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635194006 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635196119 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635198213 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635200330 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635202996 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635205210 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635207406 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635209598 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635211830 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635214036 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635216213 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635218383 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635220606 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635222766 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635224892 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635227006 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635229143 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635231249 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635233321 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635235977 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635238166 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635240301 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635242388 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635244938 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635247094 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635249203 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635251334 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635253442 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635255573 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635257836 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635260135 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635262255 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635264429 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635266535 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635268640 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635270754 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635272887 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635275070 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635277147 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635279795 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635281926 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635284034 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635286111 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635288221 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635290348 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635292585 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635294768 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635296971 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635299194 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635301296 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635303372 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635305489 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635307705 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635309936 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635312112 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635314523 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635316754 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635319003 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635321600 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635323719 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635325877 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635327985 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635330061 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635332182 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635334371 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635336518 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635338603 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635340714 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635342852 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635345123 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635347291 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635349490 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635351719 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635353943 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635356114 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635358288 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635360509 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635362707 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635365407 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635367582 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635370258 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635372468 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635374636 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635376802 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635379070 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635381277 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\ Access: read data or list directory
and synchronize Options: directory file and synchronous io non alert and open for
backup ident Overwritten: false
|
success or wait |
635383450 |
File opened |
Path: C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\ Access:
read data or list directory and synchronize Options: directory file and synchronous
io non alert and open for backup ident Overwritten: false
|
success or wait |
635385626 |
File opened |
Path: C:\Program Files\Common Files\Microsoft Shared\PROOF\ Access: read data or
list directory and synchronize Options: directory file and synchronous io non alert
and open for backup ident Overwritten: false
|
success or wait |
635387854 |
Message sent |
HWND: 5012E Message: NCPAINT WParam: 1 LParam: 0 |
error |
635389259 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\GdiPlus.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
635400620 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\GDIPLUS.DLL Access: write and read
and execute Type: commit Baseaddress: 39F0000 Size: 1703936 Protection: execute Mapped
to pid: own pid
|
success or wait |
635401452 |
File opened |
Path: C:\Program Files\Microsoft Office\OFFICE11\GdiPlus.DLL Access: execute or traverse
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
success or wait |
635404678 |
Section loaded |
Path: C:\Program Files\Microsoft Office\OFFICE11\GDIPLUS.DLL Access: query and write
and read and execute Type: image Baseaddress: 39F0000 Size: 1708032 Protection: read
write Mapped to pid: own pid
|
conflicting addresses |
635405492 |
Section loaded |
Path: \KnownDlls\WTSAPI32.DLL Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
635524811 |
File opened |
Path: C:\WINDOWS\system32\WTSAPI32.DLL Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
635525539 |
Section loaded |
Path: C:\WINDOWS\system32\wtsapi32.dll Access: query and write and read and execute
Type: image Baseaddress: 76F50000 Size: 32768 Protection: read write Mapped to pid:
own pid
|
success or wait |
635526316 |
Section loaded |
Path: \KnownDlls\WINSTA.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
635529688 |
File opened |
Path: C:\WINDOWS\system32\WINSTA.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
635530375 |
Section loaded |
Path: C:\WINDOWS\system32\winsta.dll Access: query and write and read and execute
Type: image Baseaddress: 76360000 Size: 65536 Protection: read write Mapped to pid:
own pid
|
success or wait |
635531138 |
Thread created |
PID: 1160 TID: 1624 EIP: 7C8106F9 EAX: 3B3191B Imagepath: C:\Program Files\Microsoft
Office\OFFICE11\WINWORD.EXE
|
success or wait |
635539392 |
Thread resumed |
TID: 1624 PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE |
success or wait |
635540193 |
Mutant created |
Name: unknown |
success or wait |
635544993 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 70100 |
success |
635569671 |
Windows hook set |
Module: C:\WINDOWS\system32\MSCTF.dll TID: 1624 Hook ID: keyboard |
success |
635569942 |
Windows hook set |
Module: C:\WINDOWS\system32\MSCTF.dll TID: 1624 Hook ID: mouse |
success |
635570168 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\CTF Name: Disable Thread Input Manager |
object name not found |
635571074 |
Foreground Window Got |
HWND: 5012E |
success |
635599049 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\SystemShared Name: CUAS |
success or wait |
635605124 |
Message posted |
TID: 7DC Message: C088 WParam: 0 LParam: 0 |
success |
635607885 |
Message sent |
HWND: 5012E Message: PAINT WParam: 0 LParam: 0 |
error |
635612899 |
Message sent |
HWND: 90058 Message: PAINT WParam: 0 LParam: 0 |
error |
635613191 |
Message sent |
HWND: 5012E Message: NCPAINT WParam: 1 LParam: 0 |
error |
635613483 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
635613935 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
635614539 |
Message sent |
HWND: 5012E Message: NCPAINT WParam: 1 LParam: 0 |
error |
635615578 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
635620660 |
Message sent |
HWND: 5012E Message: NCPAINT WParam: 1 LParam: 0 |
error |
635621228 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
635622794 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
635623126 |
Message sent |
HWND: 90058 Message: NCPAINT WParam: 1 LParam: 0 |
error |
635624457 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\BaseSuite Name: 1EBDE4BC9A514630B5412561FA45CCC5 |
object name not found |
635640385 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\InstallRoot Name: InstallCount |
success or wait |
635640899 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Office\11.0\Common\Licensing Name: 1EBDE4BC9A514630B5412561FA45CCC5 |
object name not found |
635641315 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Common\ProductVersion Name:
ProInfo
|
success or wait |
635641796 |
Window created |
Window Name: IPTR Class Name: IPTR HWND: 30126 |
success |
635653232 |
Message sent |
HWND: 5012E Message: NCPAINT WParam: 1 LParam: 0 |
error |
635654981 |
Message sent |
HWND: 5012E Message: NCPAINT WParam: 1 LParam: 0 |
error |
635655700 |
Thread created |
PID: 1160 TID: 496 EIP: 7C8106F9 EAX: 101DFB97 Imagepath: C:\Program Files\Microsoft
Office\OFFICE11\WINWORD.EXE
|
success or wait |
635660017 |
Thread resumed |
TID: 496 PID: 1160 Path: C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE |
success or wait |
635665205 |
Message posted |
HWND: 30126 Message: 401 WParam: 1 LParam: 53076984 |
success |
635669929 |
Message posted |
HWND: 30126 Message: 401 WParam: 1 LParam: 53076984 |
success |
635761453 |
Message posted |
HWND: 30126 Message: 401 WParam: 1 LParam: 53076984 |
success |
643649079 |
Message posted |
HWND: 30126 Message: 401 WParam: 1 LParam: 53076984 |
success |
647413246 |
Message posted |
HWND: 30126 Message: 401 WParam: 1 LParam: 53076984 |
success |
651086188 |
Message posted |
HWND: 30126 Message: 401 WParam: 1 LParam: 53076984 |
success |
654781512 |
Message posted |
HWND: 30126 Message: 401 WParam: 1 LParam: 53076984 |
success |
658472418 |
Message posted |
HWND: 30126 Message: 401 WParam: 1 LParam: 53076984 |
success |
662160312 |
Message posted |
HWND: 30126 Message: 401 WParam: 1 LParam: 53076984 |
success |
665907862 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\ Access: read data or list directory and synchronize
Options: directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
669473496 |
File created |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp Access: read attributes and synchronize
and generic write Options: synchronous io non alert and non directory file Attributes:
normal Content Overwritten: true
|
success or wait |
669475883 |
File read |
Path: C:\Documents and Settings\Administrator\Desktop\iPhone 5 Battery.doc Offset:
unknown Length: 90112 Value: C9 DF 16 87 9B 99 9A 9B 98 9D 9E 9F 6F 6E 92 93 2C 95
96 97 E8 E9 EA EB AC ED EE EF E0 E1 E2 E3 E4 E5 E6 E7 F8 F9 FA FB FC FD FE FF F0 F1
F2 F3 F4 F5 F6 F7 C8 C9 CA CB CC CD CE CF 38 C1 C2 C3 CA DA 7C C9 D8 6D D3 16 FD 65
DF 93 1D F0 86 BB BD A6 F6 A7 5A 46 4D 59 4D 40 0E 4C 41 4F 4C 4C 50 05 44 42
|
success or wait |
669487744 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp Offset: unknown Length: 90112 Value:
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 F8 00 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 70
72 6F 67 72 61 6D 20 63 61 6E 6E 6F 74 20 62 65
|
success or wait |
669610398 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp Access: read data or list directory
and execute or traverse and read attributes and synchronize Options: synchronous io
non alert and non directory file Overwritten: false
|
success or wait |
669622252 |
Section loaded |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp Access: query and write and read and
execute and extend size Type: image Baseaddress: 76360000 Size: 65536 Protection:
read write Mapped to pid: own pid
|
success or wait |
669623045 |
Message posted |
HWND: 30126 Message: 401 WParam: 1 LParam: 53076984 |
success |
669634995 |
File opened |
Path: C:\WINDOWS\system32\Apphelp.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
669640062 |
Section loaded |
Path: C:\WINDOWS\system32\apphelp.dll Access: write and read and execute Type: commit
Baseaddress: FF20000 Size: 126976 Protection: execute Mapped to pid: own pid
|
success or wait |
669640876 |
File opened |
Path: C:\WINDOWS\system32\Apphelp.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
669645904 |
Section loaded |
Path: C:\WINDOWS\system32\apphelp.dll Access: query and write and read and execute
Type: image Baseaddress: 77B40000 Size: 139264 Protection: read write Mapped to pid:
own pid
|
success or wait |
669646669 |
File opened |
Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file Attributes:
normal Content Overwritten: true
|
success or wait |
669656024 |
Section loaded |
Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 24C30000
Size: 1208320 Protection: readonly Mapped to pid: own pid
|
success or wait |
669656803 |
File opened |
Path: C:\WINDOWS\AppPatch\systest.sdb Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file Attributes:
normal Content Overwritten: true
|
object name not found |
669658565 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\WPA\MediaCenter Name: Installed |
success or wait |
669660331 |
File opened |
Path: \Device\NamedPipe\ShimViewer Access: write data or add file and append data
or add subdirectory or create pipe instance and write ea and write attributes and
read control and synchronize Options: no options Attributes: normal Content Overwritten:
true
|
object name not found |
669660953 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\ Access: read data or list directory and synchronize
Options: directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
669661416 |
File opened |
Path: C:\DOCUME~1\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
669665238 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\ Access: read data or list directory and synchronize Options:
directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
669666514 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\ Access: read data or list directory and synchronize
Options: directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
669669237 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
669670757 |
File opened |
Path: C:\DOCUME~1\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
669675811 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\ Access: read data or list directory and synchronize Options:
directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
669677074 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\ Access: read data or list directory and synchronize
Options: directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
669678362 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Name: TransparentEnabled
|
success or wait |
669681566 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Name: AuthenticodeEnabled
|
success or wait |
669681829 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Name: Levels
|
object name not found |
669686080 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}
Name: ItemData
|
success or wait |
669757228 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}
Name: SaferFlags
|
success or wait |
669758420 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}
Name: ItemData
|
success or wait |
669760040 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}
Name: HashAlg
|
success or wait |
669760454 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}
Name: ItemSize
|
success or wait |
669760854 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}
Name: SaferFlags
|
success or wait |
669761252 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}
Name: ItemData
|
success or wait |
669762781 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}
Name: HashAlg
|
success or wait |
669763186 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}
Name: ItemSize
|
success or wait |
669763589 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}
Name: SaferFlags
|
success or wait |
669763991 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}
Name: ItemData
|
success or wait |
669764754 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}
Name: HashAlg
|
success or wait |
669765157 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}
Name: ItemSize
|
success or wait |
669765557 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}
Name: SaferFlags
|
success or wait |
669765961 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}
Name: ItemData
|
success or wait |
669767131 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}
Name: HashAlg
|
success or wait |
669767535 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}
Name: ItemSize
|
success or wait |
669767937 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}
Name: SaferFlags
|
success or wait |
669768337 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}
Name: ItemData
|
success or wait |
669769231 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}
Name: HashAlg
|
success or wait |
670149655 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}
Name: ItemSize
|
success or wait |
670150077 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}
Name: SaferFlags
|
success or wait |
670150483 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Name: DefaultLevel
|
success or wait |
670156505 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Name: PolicyScope
|
success or wait |
670163687 |
File opened |
Path: C:\DOCUME~1\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
670168344 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\ Access: read data or list directory and synchronize Options:
directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
670169649 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\ Access: read data or list directory and synchronize
Options: directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
670170958 |
Section loaded |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp Access: query and read Type: commit
Baseaddress: FF20000 Size: 90112 Protection: readonly Mapped to pid: own pid
|
success or wait |
670173177 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Name: Cache
|
buffer overflow |
670174723 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Name: Cache
|
success or wait |
670175081 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Name: LogFileName
|
object name not found |
670177007 |
System info queried |
Type: WatchdogTimerHandler |
success or wait |
670178648 |
Process created |
PID: 1112 Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp Cmdline: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp
Createflags: none
|
success or wait |
670178841 |
Process information queried |
PID: 1112 Info Class: BasicInformation |
success or wait |
670181864 |
Memory read |
PID: 1112 Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp Base: 7FFDB008 Length: 4
Value: 00 00 40 00
|
success or wait |
670182064 |
File opened |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp.Manifest Access: read data or list
directory and read ea and execute or traverse and read attributes and read control
and synchronize Options: synchronous io non alert and non directory file Overwritten:
false
|
object name not found |
670182356 |
Memory read |
PID: 1112 Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp Base: 400000 Length: 4096
Value: 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 F8 00 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69
73 20 70 72 6F 67 72 61 6D 20 63 61 6E 6E 6F 74 20 62 65 20 72 75 6E 20 69 6E 20 44
4F 53 20 6D 6F 64 65 2E 0D 0D 0A 24 00 00 00 00 00 00 00 11 F8 01 BB 55 99 6F E8 55
99 6F E8 55 99 6F E8 2E 85 63 E8 54 99 6F E8 3A 86 65 E8 5E 99 6F E8 D6 85 61 E8 54
99 6F E8 3A 86 6B E8 57 99 6F E8 AF BA 76 E8 51 99 6F E8 46 91 32 E8 57 99 6F E8 D6
91 32 E8 50 99 6F E8 55 99 6E E8 04 99 6F E8 92 9F 69 E8 54 99 6F E8 BD 86 64 E8 57
99 6F E8 52 69 63 68 55 99 6F E8 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50
45 00 00 4C 01 04
|
success or wait |
670183838 |
Memory read |
PID: 1112 Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp Base: 406000 Length: 256
Value: 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 58 00 00 80 18 00 00 80 00
00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 65 00 00 00 30 00 00 80 00 00 00 00 00
00 00 00 00 00 00 00 00 00 01 00 04 08 00 00 48 00 00 00 60 60 00 00 00 F0 00 00 00
00 00 00 00 00 00 00 03 00 44 00 4C 00 4C 00 4D 5A 90 00 03 00 00 00 04 00 00 00 FF
FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 F8 00 00 00 0E 1F BA 0E 00
B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 70 72 6F 67 72 61 6D 20 63 61 6E 6E 6F 74
20 62 65 20 72 75 6E 20 69 6E 20 44 4F 53 20 6D 6F 64 65 2E 0D 0D 0A 24 00 00 00 00
00 00 00 D1 D9 B8 42 95 B8 D6 11 95 B8 D6 11 95 B8 D6 11 6F 9B CF 11 97 B8 D6 11 B2
7E AD 11 97 B8 D6
|
success or wait |
670186684 |
Process information queried |
PID: 1112 Info Class: BasicInformation |
success or wait |
670188070 |
Memory allocated |
PID: 1112 Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp Base: 10000 Length: 12DFE4
Allocation Type: unknown Protection: page read and write
|
success or wait |
670189397 |
Memory written |
PID: 1112 Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp Base: 10000 Length: 2116
Value: 3D 00 3A 00 3A 00 3D 00 3A 00 3A 00 5C 00 00 00 3D 00 5A 00 3A 00 3D 00 5A
00 3A 00 5C 00 00 00 41 00 4C 00 4C 00 55 00 53 00 45 00 52 00 53 00 50 00 52 00 4F
00 46 00 49 00 4C 00 45 00 3D 00 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65
00 6E 00 74 00 73 00 20 00 61 00 6E 00 64 00 20 00 53 00 65 00 74 00 74 00 69 00 6E
00 67 00 73 00 5C 00 41 00 6C 00 6C 00 20 00 55 00 73 00 65 00 72 00 73 00 00 00 41
00 50 00 50 00 44 00 41 00 54 00 41 00 3D 00 43 00 3A 00 5C 00 44 00 6F 00 63 00 75
00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00 6E 00 64 00 20 00 53 00 65 00 74 00 74
00 69 00 6E 00 67 00 73 00 5C 00 41 00 64 00 6D 00 69 00 6E 00 69 00 73 00 74 00 72
00 61 00 74 00 6F 00 72 00 5C 00 41 00 70 00 70 00 6C 00 69 00 63 00 61 00 74 00 69
00 6F 00 6E 00 20
|
success or wait |
670191293 |
Memory allocated |
PID: 1112 Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp Base: 20000 Length: 12DFE4
Allocation Type: unknown Protection: page read and write
|
success or wait |
670191727 |
Memory written |
PID: 1112 Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp Base: 20000 Length: 1828
Value: 00 10 00 00 24 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 3C 00 08 02 90 02 00 00 00 00 00 00 68 01 6A 01 98
04 00 00 50 00 52 00 04 06 00 00 50 00 52 00 58 06 00 00 00 00 01 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00
00 00 00 50 00 52 00 AC 06 00 00 1E 00 20 00 00 07 00 00 00 00 02 00 20 07 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00
|
success or wait |
670193169 |
Memory written |
PID: 1112 Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp Base: 7FFDB010 Length: 4
Value: 00 00 02 00
|
success or wait |
670193545 |
Memory written |
PID: 1112 Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp Base: 7FFDB1E8 Length: 4
Value: 00 00 00 00
|
success or wait |
670193835 |
Memory allocated |
PID: 1112 Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp Base: 30000 Length: 12E250
Allocation Type: unknown Protection: page read and write
|
success or wait |
670194115 |
Memory allocated |
PID: 1112 Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp Base: 12E000 Length: 12E24C
Allocation Type: unknown Protection: page read and write
|
success or wait |
670194361 |
Memory attributes changed |
PID: 1112 Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp Base: 12E000 Length: 1000
New Protection: page read and write and page guard New Protection: page read and write
|
success or wait |
670194728 |
Thread created |
PID: 1112 TID: 1116 EIP: 7C810705 EAX: 4032AC Imagepath: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp |
success or wait |
670195302 |
Thread resumed |
TID: 1116 PID: 1112 Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\~WORDL.tmp |
success or wait |
670709093 |
Process information queried |
PID: 1112 Info Class: BasicInformation |
success or wait |
670710495 |
File created |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\iPhone 5.doc Access: read attributes and synchronize
and generic write Options: synchronous io non alert and non directory file Attributes:
normal Content Overwritten: true
|
success or wait |
671090526 |
File read |
Path: C:\Documents and Settings\Administrator\Desktop\iPhone 5 Battery.doc Offset:
unknown Length: 21504 Value: 32 2C F5 05 47 56 E2 18 FA FB FC FD FE FF F0 F1 F2 F3
F4 F5 F6 F7 C8 C9 F4 CB CF CD 30 30 C9 C1 C4 C3 C4 C5 C6 C7 D8 D9 DA DB DC DD DF DF
D0 D1 F7 D3 D4 D5 D6 D7 28 29 2A 3B 2C 2D 09 2F 20 21 23 23 24 25 D8 D8 C7 C6 3A 3B
3C 3D 1A 3F 30 31 CD CC CB CA C9 C8 F7 F6 F5 F4 F3 F2 F1 F0 FF FE FD FC FB FA
|
success or wait |
671097579 |
File write |
Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\iPhone 5.doc Offset: unknown Length: 21504 Value:
D0 CF 11 E0 A1 B1 1A E1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 3E 00 03 00
FE FF 09 00 06 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 25 00 00 00 00 00 00 00
00 10 00 00 27 00 00 00 01 00 00 00 FE FF FF FF 00 00 00 00 24 00 00 00 FF FF FF FF
FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
|
success or wait |
671126430 |
File opened |
Path: C:\WINDOWS\system32\cmd.exe Access: read data or list directory and execute
or traverse and read attributes and synchronize Options: synchronous io non alert
and non directory file Overwritten: false
|
success or wait |
671132252 |
Section loaded |
Path: C:\WINDOWS\system32\cmd.exe Access: query and write and read and execute and
extend size Type: image Baseaddress: FF20000 Size: 90112 Protection: readonly Mapped
to pid: own pid
|
success or wait |
671132995 |
File opened |
Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file Attributes:
normal Content Overwritten: true
|
success or wait |
671134531 |
Section loaded |
Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 24C30000
Size: 1208320 Protection: readonly Mapped to pid: own pid
|
success or wait |
671135294 |
File opened |
Path: C:\WINDOWS\AppPatch\systest.sdb Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file Attributes:
normal Content Overwritten: true
|
object name not found |
671136902 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\WPA\MediaCenter Name: Installed |
success or wait |
671137603 |
File opened |
Path: \Device\NamedPipe\ShimViewer Access: write data or add file and append data
or add subdirectory or create pipe instance and write ea and write attributes and
read control and synchronize Options: no options Attributes: normal Content Overwritten:
true
|
object name not found |
671138224 |
File opened |
Path: C:\WINDOWS\system32\ Access: read data or list directory and synchronize Options:
directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
671138678 |
File opened |
Path: C:\WINDOWS\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
671141683 |
File opened |
Path: C:\WINDOWS\system32\ Access: read data or list directory and synchronize Options:
directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
671144866 |
Process information queried |
PID: 1160 Info Class: DeviceMap |
success or wait |
671146950 |
File opened |
Path: C:\WINDOWS\system32\cmd.exe Access: read data or list directory and execute
or traverse and read attributes and synchronize Options: synchronous io non alert
and non directory file Overwritten: false
|
success or wait |
671152999 |
Section loaded |
Path: C:\WINDOWS\system32\cmd.exe Access: write and read and execute Type: commit
Baseaddress: FF30000 Size: 389120 Protection: execute Mapped to pid: own pid
|
success or wait |
671153799 |
File opened |
Path: C:\WINDOWS\system32\cmd.exe Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file Attributes: none Content
Overwritten: true
|
success or wait |
671156230 |
Section loaded |
Path: C:\WINDOWS\system32\cmd.exe Access: query and read Type: commit Baseaddress:
FF30000 Size: 389120 Protection: readonly Mapped to pid: own pid
|
success or wait |
671157027 |
File opened |
Path: C:\WINDOWS\system32\cmd.exe Access: read data or list directory and execute
or traverse and read attributes and synchronize Options: synchronous io non alert
and non directory file Overwritten: false
|
success or wait |
671162952 |
Section loaded |
Path: C:\WINDOWS\system32\cmd.exe Access: write and read and execute Type: commit
Baseaddress: FF30000 Size: 389120 Protection: execute Mapped to pid: own pid
|
success or wait |
671163754 |
File opened |
Path: C:\WINDOWS\system32\cmd.exe Access: read attributes and synchronize and generic
read Options: synchronous io non alert and non directory file Attributes: none Content
Overwritten: true
|
success or wait |
671165472 |
Section loaded |
Path: C:\WINDOWS\system32\cmd.exe Access: query and read Type: commit Baseaddress:
FF30000 Size: 389120 Protection: readonly Mapped to pid: own pid
|
success or wait |
671166265 |
File opened |
Path: C:\WINDOWS\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
671174023 |
File opened |
Path: C:\WINDOWS\system32\ Access: read data or list directory and synchronize Options:
directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
671175337 |
File opened |
Path: C:\WINDOWS\ Access: read data or list directory and synchronize Options: directory
file and synchronous io non alert and open for backup ident Overwritten: false
|
success or wait |
671181689 |
File opened |
Path: C:\WINDOWS\system32\ Access: read data or list directory and synchronize Options:
directory file and synchronous io non alert and open for backup ident Overwritten:
false
|
success or wait |
671182959 |
Section loaded |
Path: C:\WINDOWS\system32\cmd.exe Access: query and read Type: commit Baseaddress:
FF30000 Size: 389120 Protection: readonly Mapped to pid: own pid
|
success or wait |
671186020 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Name: LogFileName
|
object name not found |
671186939 |
System info queried |
Type: WatchdogTimerHandler |
success or wait |
671188213 |
Process created |
PID: 1096 Path: C:\WINDOWS\system32\cmd.exe Cmdline: cmd.exe /c iPhone 5.doc Createflags:
none
|
success or wait |
671188387 |
Process information queried |
PID: 1096 Info Class: BasicInformation |
success or wait |
671196841 |
Memory read |
PID: 1096 Path: C:\WINDOWS\system32\cmd.exe Base: 7FFD9008 Length: 4 Value: 00 00
D0 4A
|
success or wait |
671197045 |
File opened |
Path: C:\WINDOWS\system32\cmd.exe.Manifest Access: read data or list directory and
read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
671197332 |
Memory read |
PID: 1096 Path: C:\WINDOWS\system32\cmd.exe Base: 4AD00000 Length: 4096 Value: 4D
5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 B8 00 00 00 00 00 00 00 40 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 D8 00 00 00 0E 1F BA 0E 00 B4 09 CD 21 B8 01 4C CD 21 54 68 69 73 20 70 72
6F 67 72 61 6D 20 63 61 6E 6E 6F 74 20 62 65 20 72 75 6E 20 69 6E 20 44 4F 53 20 6D
6F 64 65 2E 0D 0D 0A 24 00 00 00 00 00 00 00 1D ED D5 EA 59 8C BB B9 59 8C BB B9 59
8C BB B9 9A 83 B4 B9 5F 8C BB B9 59 8C BA B9 80 8C BB B9 9A 83 E6 B9 5E 8C BB B9 E6
83 DB B9 5B 8C BB B9 9A 83 E5 B9 58 8C BB B9 9A 83 E4 B9 6D 8C BB B9 9A 83 E1 B9 58
8C BB B9 52 69 63 68 59 8C BB B9 00 00 00 00 00 00 00 00 50 45 00 00 4C 01 03 00 AF
5B 02 48 00 00 00 00 00 00 00 00 E0 00 0F 01 0B 01 07 0A 00 F8 01 00 00 F6 03 00 00
00 00
|
success or wait |
671198058 |
Memory read |
PID: 1096 Path: C:\WINDOWS\system32\cmd.exe Base: 4AD3E000 Length: 256 Value: 00 00
00 00 00 00 00 00 00 00 00 00 00 00 04 00 03 00 00 00 30 00 00 80 0B 00 00 00 80 00
00 80 0E 00 00 00 98 00 00 80 10 00 00 00 B0 00 00 80 00 00 00 00 00 00 00 00 00 00
00 00 00 00 08 00 01 00 00 00 C8 00 00 80 02 00 00 00 E0 00 00 80 03 00 00 00 F8 00
00 80 04 00 00 00 10 01 00 80 05 00 00 00 28 01 00 80 06 00 00 00 40 01 00 80 07 00
00 00 58 01 00 80 08 00 00 00 70 01 00 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00
01 00 01 00 00 00 88 01 00 80 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 80 02
00 80 A0 01 00 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 01 00 00 00 B8 01
00 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 09 04 00 00 D0 01 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 01 00 09 04 00 00 E0 01 00 00 00 00 00 00 00 00
00
|
success or wait |
671200966 |
Process information queried |
PID: 1096 Info Class: BasicInformation |
success or wait |
671207472 |
Memory allocated |
PID: 1096 Path: C:\WINDOWS\system32\cmd.exe Base: 10000 Length: 12DFE4 Allocation
Type: unknown Protection: page read and write
|
success or wait |
671208881 |
Memory written |
PID: 1096 Path: C:\WINDOWS\system32\cmd.exe Base: 10000 Length: 2116 Value: 3D 00
3A 00 3A 00 3D 00 3A 00 3A 00 5C 00 00 00 3D 00 5A 00 3A 00 3D 00 5A 00 3A 00 5C 00
00 00 41 00 4C 00 4C 00 55 00 53 00 45 00 52 00 53 00 50 00 52 00 4F 00 46 00 49 00
4C 00 45 00 3D 00 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00
73 00 20 00 61 00 6E 00 64 00 20 00 53 00 65 00 74 00 74 00 69 00 6E 00 67 00 73 00
5C 00 41 00 6C 00 6C 00 20 00 55 00 73 00 65 00 72 00 73 00 00 00 41 00 50 00 50 00
44 00 41 00 54 00 41 00 3D 00 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00
6E 00 74 00 73 00 20 00 61 00 6E 00 64 00 20 00 53 00 65 00 74 00 74 00 69 00 6E 00
67 00 73 00 5C 00 41 00 64 00 6D 00 69 00 6E 00 69 00 73 00 74 00 72 00 61 00 74 00
6F 00 72 00 5C 00 41 00 70 00 70 00 6C 00 69 00 63 00 61 00 74 00 69 00 6F 00 6E 00
20
|
success or wait |
671210752 |
Memory allocated |
PID: 1096 Path: C:\WINDOWS\system32\cmd.exe Base: 20000 Length: 12DFE4 Allocation
Type: unknown Protection: page read and write
|
success or wait |
671211118 |
Memory written |
PID: 1096 Path: C:\WINDOWS\system32\cmd.exe Base: 20000 Length: 1720 Value: 00 10
00 00 B8 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 3C 00 08 02 90 02 00 00 00 00 00 00 54 01 56 01 98 04 00 00 36 00
38 00 F0 05 00 00 32 00 34 00 28 06 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 36 00
38 00 5C 06 00 00 1E 00 20 00 94 06 00 00 00 00 02 00 B4 06 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00
|
success or wait |
671212519 |
Memory written |
PID: 1096 Path: C:\WINDOWS\system32\cmd.exe Base: 7FFD9010 Length: 4 Value: 00 00
02 00
|
success or wait |
671212938 |
Memory allocated |
PID: 1096 Path: C:\WINDOWS\system32\cmd.exe Base: 30000 Length: 12DFE4 Allocation
Type: unknown Protection: page read and write
|
success or wait |
671213162 |
Memory written |
PID: 1096 Path: C:\WINDOWS\system32\cmd.exe Base: 30000 Length: 388 Value: 53 00 68
00 69 00 6D 00 45 00 6E 00 67 00 2E 00 64 00 6C 00 6C 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 84 01 00 00 AB ED 0D AC AA 3F 02 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 11 11 11 11 11 11 11 11 11 11 11
11 11 11 11 11 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
|
success or wait |
671213837 |
Memory written |
PID: 1096 Path: C:\WINDOWS\system32\cmd.exe Base: 7FFD91E8 Length: 4 Value: 00 00
03 00
|
success or wait |
671214204 |
Memory read |
PID: 1096 Path: C:\WINDOWS\system32\cmd.exe Base: 7FFD9010 Length: 4 Value: 00 00
02 00
|
success or wait |
671214471 |
Memory allocated |
PID: 1096 Path: C:\WINDOWS\system32\cmd.exe Base: 40000 Length: 12E250 Allocation
Type: unknown Protection: page read and write
|
success or wait |
671214838 |
Memory allocated |
PID: 1096 Path: C:\WINDOWS\system32\cmd.exe Base: 40000 Length: 12E24C Allocation
Type: unknown Protection: page read and write
|
success or wait |
671215083 |
Thread created |
PID: 1096 TID: 424 EIP: 7C810705 EAX: 4AD05046 Imagepath: C:\WINDOWS\system32\cmd.exe |
success or wait |
671219055 |
Thread resumed |
TID: 424 PID: 1096 Path: C:\WINDOWS\system32\cmd.exe |
success or wait |
671467724 |
Process information queried |
PID: 1096 Info Class: BasicInformation |
success or wait |
671468348 |