Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager Name: CWDIllegalInDLLSearch |
object name not found |
527500350 |
System info queried |
Type: BasicInformation |
success or wait |
527502592 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 90000 Length: 7FB14 Allocation Type:
unknown Protection: page read and write
|
success or wait |
527503069 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 90000 Length: 7FB18 Allocation Type:
unknown Protection: page read and write
|
success or wait |
527504355 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 91000 Length: 7F7F4 Allocation Type:
unknown Protection: page read and write
|
success or wait |
527511716 |
System info queried |
Type: BasicInformation |
success or wait |
527512008 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 190000 Length: 7FB14 Allocation Type:
unknown Protection: page read and write
|
success or wait |
527512294 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 190000 Length: 7FB18 Allocation Type:
unknown Protection: page read and write
|
success or wait |
527512549 |
File opened |
Path: C:\ Access: execute or traverse and synchronize Options: directory file and
synchronous io non alert Overwritten: false
|
success or wait |
527514743 |
File control set |
Path: C:\ Control Code: 90028 Input Buffer: NULL |
success or wait |
527523705 |
Section loaded |
Path: \KnownDlls\kernel32.dll Access: write and read and execute Type: unknown Baseaddress:
7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid
|
success or wait |
527524627 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7C801000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527526028 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7C801000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527537892 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: Cookie |
success or wait |
527538764 |
System info queried |
Type: RangeStartInformation |
success or wait |
527539061 |
System info queried |
Type: BasicInformation |
success or wait |
527539307 |
Section loaded |
Path: unknown Access: query and write and read and execute and extend size Type: reserve
Baseaddress: 7C800000 Size: 1007616 Protection: read write Mapped to pid: own pid
|
success or wait |
527539677 |
System info queried |
Type: BasicInformation |
success or wait |
527549001 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 1A0000 Length: 7F340 Allocation Type:
unknown Protection: page read and write
|
success or wait |
527549492 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server Name: TSAppCompat |
success or wait |
527550612 |
Section loaded |
Path: \NLS\NlsSectionUnicode Access: read Type: unknown Baseaddress: 1B0000 Size:
90112 Protection: readonly Mapped to pid: own pid
|
success or wait |
527552103 |
Section loaded |
Path: \NLS\NlsSectionLocale Access: read Type: unknown Baseaddress: 1D0000 Size: 266240
Protection: readonly Mapped to pid: own pid
|
success or wait |
527562308 |
Section loaded |
Path: \NLS\NlsSectionSortkey Access: query and read Type: unknown Baseaddress: 220000
Size: 266240 Protection: readonly Mapped to pid: own pid
|
success or wait |
527563669 |
Section loaded |
Path: \NLS\NlsSectionSortTbls Access: read Type: unknown Baseaddress: 270000 Size:
24576 Protection: readonly Mapped to pid: own pid
|
success or wait |
527587175 |
Section loaded |
Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: unknown
Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
527588916 |
Section loaded |
Path: \NLS\NlsSectionSortkey00000409 Access: read Type: unknown Baseaddress: unknown
Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
527597817 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 1A1000 Length: 7F168 Allocation Type:
unknown Protection: page read and write
|
success or wait |
527598151 |
Section loaded |
Path: \KnownDlls\ADVAPI32.dll Access: write and read and execute Type: unknown Baseaddress:
77DD0000 Size: 634880 Protection: read write Mapped to pid: own pid
|
success or wait |
527599128 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77DD1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527609747 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77DD1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527610356 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77DD1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527610682 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77DD1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527611223 |
Section loaded |
Path: \KnownDlls\RPCRT4.dll Access: write and read and execute Type: unknown Baseaddress:
77E70000 Size: 602112 Protection: read write Mapped to pid: own pid
|
success or wait |
527611613 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77E71000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527620791 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77E71000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527621428 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77E71000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527625592 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77E71000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527630673 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77E71000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527631030 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77E71000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527631415 |
Section loaded |
Path: \KnownDlls\Secur32.dll Access: write and read and execute Type: unknown Baseaddress:
77FE0000 Size: 69632 Protection: read write Mapped to pid: own pid
|
success or wait |
527631830 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77FE1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527640765 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77FE1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527641205 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77FE1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527641585 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77FE1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527641984 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77FE1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527642360 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77FE1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527652880 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77E71000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527653228 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77E71000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527653568 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77DD1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527653879 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77DD1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527654379 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 1001000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527655426 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 1001000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527670513 |
Section loaded |
Path: \KnownDlls\BROWSEUI.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
527670888 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 93000 Length: 7F3D0 Allocation Type:
unknown Protection: page read and write
|
success or wait |
527671206 |
File opened |
Path: C:\WINDOWS\system32\BROWSEUI.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
527672023 |
Section loaded |
Path: C:\WINDOWS\system32\browseui.dll Access: query and write and read and execute
Type: image Baseaddress: 75F80000 Size: 1036288 Protection: read write Mapped to pid:
own pid
|
success or wait |
527673056 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Name: TransparentEnabled
|
success or wait |
527684273 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 75F81000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527693685 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 75F81000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527697080 |
Section loaded |
Path: \KnownDlls\GDI32.dll Access: write and read and execute Type: unknown Baseaddress:
77F10000 Size: 299008 Protection: read write Mapped to pid: own pid
|
success or wait |
527697475 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77F11000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527703995 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77F11000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527704517 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77F11000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527704871 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77F11000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527705231 |
Section loaded |
Path: \KnownDlls\USER32.dll Access: write and read and execute Type: unknown Baseaddress:
7E410000 Size: 593920 Protection: read write Mapped to pid: own pid
|
success or wait |
527705645 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7E411000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527713756 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7E411000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527714505 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7E411000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527714892 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7E411000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527715366 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7E411000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527721122 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7E411000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527721649 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77F11000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527721991 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77F11000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527722589 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 75F81000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527722905 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 75F81000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527723239 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 75F81000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527729157 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 75F81000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527729559 |
Section loaded |
Path: \KnownDlls\msvcrt.dll Access: write and read and execute Type: unknown Baseaddress:
77C10000 Size: 360448 Protection: read write Mapped to pid: own pid
|
success or wait |
527729950 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77C11000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527736199 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77C11000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527746801 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77C11000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527747164 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77C11000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527747508 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 75F81000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527747823 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 75F81000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527748315 |
Section loaded |
Path: \KnownDlls\ole32.dll Access: write and read and execute Type: unknown Baseaddress:
774E0000 Size: 1302528 Protection: read write Mapped to pid: own pid
|
success or wait |
527750937 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 774E1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527755448 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 774E1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527755930 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 774E1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527756278 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 774E1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527763348 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 774E1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527763709 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 774E1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527764226 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 774E1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527764576 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 774E1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527764930 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 774E1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527765274 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 774E1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527769159 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 774E1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527769515 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 774E1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527769969 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 774E1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527770316 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 774E1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527770762 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 75F81000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527771079 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 75F81000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527779311 |
Section loaded |
Path: \KnownDlls\SHLWAPI.dll Access: write and read and execute Type: unknown Baseaddress:
77F60000 Size: 483328 Protection: read write Mapped to pid: own pid
|
success or wait |
527779712 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77F61000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527781233 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77F61000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527782097 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77F61000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527785475 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77F61000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527785844 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77F61000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527786192 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77F61000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527786710 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77F61000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527787058 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77F61000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527789501 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77F61000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527809152 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77F61000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527809655 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 75F81000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527809978 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 75F81000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527810554 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 1001000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527810909 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 1001000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527811437 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 1001000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527815717 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 1001000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527816180 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 1001000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527816479 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 1001000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527816770 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 1001000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527817062 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 1001000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527819604 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 1001000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527823581 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 1001000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527823878 |
Section loaded |
Path: \KnownDlls\OLEAUT32.dll Access: write and read and execute Type: unknown Baseaddress:
77120000 Size: 569344 Protection: read write Mapped to pid: own pid
|
success or wait |
527824241 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77121000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527831519 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77121000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527832135 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77121000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527832825 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77121000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527833170 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77121000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527833494 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77121000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527833964 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77121000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527839175 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77121000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527839515 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77121000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527839835 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77121000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527840162 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77121000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527840480 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77121000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527840790 |
Section loaded |
Path: \KnownDlls\SHDOCVW.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
527848462 |
File opened |
Path: C:\WINDOWS\system32\SHDOCVW.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
527849245 |
Section loaded |
Path: C:\WINDOWS\system32\shdocvw.dll Access: query and write and read and execute
Type: image Baseaddress: 7E290000 Size: 1511424 Protection: read write Mapped to pid:
own pid
|
success or wait |
527850297 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7E291000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527858591 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7E291000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527877944 |
Section loaded |
Path: \KnownDlls\CRYPT32.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
527878344 |
File opened |
Path: C:\WINDOWS\system32\CRYPT32.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
527879169 |
Section loaded |
Path: C:\WINDOWS\system32\crypt32.dll Access: query and write and read and execute
Type: image Baseaddress: 77A80000 Size: 610304 Protection: read write Mapped to pid:
own pid
|
success or wait |
527880225 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77A81000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527890931 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77A81000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527891523 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77A81000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527891884 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77A81000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527892333 |
Section loaded |
Path: \KnownDlls\MSASN1.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
527892749 |
File opened |
Path: C:\WINDOWS\system32\MSASN1.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
527893556 |
Section loaded |
Path: C:\WINDOWS\system32\msasn1.dll Access: query and write and read and execute
Type: image Baseaddress: 77B20000 Size: 73728 Protection: read write Mapped to pid:
own pid
|
success or wait |
527897793 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77B21000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527907380 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77B21000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527907836 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77B21000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527908216 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77B21000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527908593 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77B21000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527909010 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77B21000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527915721 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77A81000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527916076 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77A81000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527916597 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77A81000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527916950 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77A81000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527917404 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77A81000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527917757 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77A81000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527921828 |
Section loaded |
Path: \KnownDlls\CRYPTUI.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
527922119 |
File opened |
Path: C:\WINDOWS\system32\CRYPTUI.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
527922985 |
Section loaded |
Path: C:\WINDOWS\system32\cryptui.dll Access: query and write and read and execute
Type: image Baseaddress: 754D0000 Size: 524288 Protection: read write Mapped to pid:
own pid
|
success or wait |
527932470 |
File opened |
Path: C:\WINDOWS\system32\CRYPTUI.dll.2.Manifest Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
527939231 |
File opened |
Path: C:\WINDOWS\system32\CRYPTUI.dll.2.Config Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
527947651 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 754D1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527989657 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 754D1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527998796 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 754D1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527999170 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 754D1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
527999582 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 754D1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
527999939 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 754D1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528000367 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 754D1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528000715 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 754D1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528005114 |
Section loaded |
Path: \KnownDlls\NETAPI32.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
528005586 |
File opened |
Path: C:\WINDOWS\system32\NETAPI32.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
528006399 |
Section loaded |
Path: C:\WINDOWS\system32\netapi32.dll Access: query and write and read and execute
Type: image Baseaddress: 5B860000 Size: 348160 Protection: read write Mapped to pid:
own pid
|
success or wait |
528007475 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5B861000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528022143 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5B861000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528022623 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5B861000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528023008 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5B861000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528023466 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5B861000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528026260 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5B861000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528030770 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5B861000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528031165 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5B861000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528031599 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5B861000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528031982 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5B861000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528032364 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 754D1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528035811 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 754D1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528039008 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 754D1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528039371 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 754D1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528039718 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 754D1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528040067 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 754D1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528040409 |
Section loaded |
Path: \KnownDlls\VERSION.dll Access: write and read and execute Type: unknown Baseaddress:
77C00000 Size: 32768 Protection: read write Mapped to pid: own pid
|
success or wait |
528043966 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77C01000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528048177 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77C01000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528048722 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77C01000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528049107 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77C01000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528059798 |
Section loaded |
Path: \KnownDlls\WININET.dll Access: write and read and execute Type: unknown Baseaddress:
3D930000 Size: 942080 Protection: read write Mapped to pid: own pid
|
success or wait |
528060238 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D931000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528061939 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D931000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528064592 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D931000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528070029 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D931000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528070460 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D931000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528070842 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D931000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528071282 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D931000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528071658 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D931000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528074254 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D931000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528082308 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D931000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528083038 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D931000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528083796 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D931000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528084281 |
Section loaded |
Path: \KnownDlls\Normaliz.dll Access: write and read and execute Type: unknown Baseaddress:
400000 Size: 36864 Protection: read write Mapped to pid: own pid
|
success or wait |
528084736 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 401000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528096368 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 401000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528096857 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 401000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528097273 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 401000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528097685 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 401000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528109038 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 401000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528109528 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D931000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528109904 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D931000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528110277 |
Section loaded |
Path: \KnownDlls\urlmon.dll Access: write and read and execute Type: unknown Baseaddress:
78130000 Size: 1257472 Protection: read write Mapped to pid: own pid
|
success or wait |
528110729 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 78131000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528117774 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 78131000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528118396 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 78131000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528119191 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 78131000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528119645 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 78131000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528120445 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 78131000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528127656 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 78131000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528128082 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 78131000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528128548 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 78131000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528128958 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 78131000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528129394 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 78131000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528130825 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 78131000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528139779 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 78131000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528140201 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 78131000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528140792 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 78131000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528141210 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 78131000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528141671 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 78131000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528142374 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 78131000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528151498 |
Section loaded |
Path: \KnownDlls\iertutil.dll Access: write and read and execute Type: unknown Baseaddress:
3DFD0000 Size: 2002944 Protection: read write Mapped to pid: own pid
|
success or wait |
528152041 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3DFD1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528153932 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3DFD1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528163683 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3DFD1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528164154 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3DFD1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528164603 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3DFD1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528165100 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3DFD1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528165860 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3DFD1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528166316 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3DFD1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528175602 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3DFD1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528176080 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3DFD1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528176580 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3DFD1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528177034 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3DFD1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528177517 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 78131000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528177926 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 78131000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528190109 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D931000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528190492 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D931000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528190923 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D931000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528191206 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D931000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528191585 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 754D1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528191926 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 754D1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528197337 |
Section loaded |
Path: \KnownDlls\WINTRUST.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
528197771 |
File opened |
Path: C:\WINDOWS\system32\WINTRUST.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
528198639 |
Section loaded |
Path: C:\WINDOWS\system32\wintrust.dll Access: query and write and read and execute
Type: image Baseaddress: 76C30000 Size: 188416 Protection: read write Mapped to pid:
own pid
|
success or wait |
528217578 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76C31000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528227821 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76C31000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528228372 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76C31000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528228759 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76C31000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528229275 |
Section loaded |
Path: \KnownDlls\IMAGEHLP.dll Access: write and read and execute Type: unknown Baseaddress:
76C90000 Size: 163840 Protection: read write Mapped to pid: own pid
|
success or wait |
528229729 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76C91000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528239049 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76C91000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528243600 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76C91000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528244033 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76C91000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528245214 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76C31000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528245591 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76C31000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528251719 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76C31000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528252116 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76C31000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528252624 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76C31000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528253009 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76C31000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528253406 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76C31000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528253783 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76C31000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528257099 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76C31000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528257488 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76C31000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528257865 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76C31000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528258243 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76C31000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528259353 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 754D1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528259703 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 754D1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528266480 |
Section loaded |
Path: \KnownDlls\WLDAP32.dll Access: write and read and execute Type: unknown Baseaddress:
76F60000 Size: 180224 Protection: read write Mapped to pid: own pid
|
success or wait |
528267777 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76F61000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528269416 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76F61000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528285950 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76F61000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528286400 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76F61000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528286845 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76F61000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528287223 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76F61000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528287663 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7E291000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528288449 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7E291000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528294336 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7E291000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528294674 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7E291000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528295157 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7E291000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528295479 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7E291000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528295798 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7E291000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528296406 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7E291000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528301751 |
Section loaded |
Path: \KnownDlls\SHELL32.dll Access: write and read and execute Type: unknown Baseaddress:
7C9C0000 Size: 8482816 Protection: read write Mapped to pid: own pid
|
success or wait |
528302173 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7C9C1000 Length: 2000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528303801 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7C9C1000 Length: 2000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528309678 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7C9C1000 Length: 2000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528310015 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7C9C1000 Length: 2000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528310379 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7C9C1000 Length: 2000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528310700 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7C9C1000 Length: 2000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528311220 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7C9C1000 Length: 2000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528311542 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7C9C1000 Length: 2000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528319839 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7C9C1000 Length: 2000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528320266 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7C9C1000 Length: 2000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528320607 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7C9C1000 Length: 2000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528320930 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7C9C1000 Length: 2000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528321249 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7C9C1000 Length: 2000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528321566 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7C9C1000 Length: 2000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528327536 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7C9C1000 Length: 2000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528327870 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7C9C1000 Length: 2000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528328472 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 1001000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528328853 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 1001000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528329342 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 1001000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528329639 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 1001000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528336115 |
Section loaded |
Path: \KnownDlls\UxTheme.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
528336497 |
File opened |
Path: C:\WINDOWS\system32\UxTheme.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
528337252 |
Section loaded |
Path: C:\WINDOWS\system32\uxtheme.dll Access: query and write and read and execute
Type: image Baseaddress: 5AD70000 Size: 229376 Protection: read write Mapped to pid:
own pid
|
success or wait |
528338281 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5AD71000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528343707 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5AD71000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528344159 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5AD71000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528344486 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5AD71000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528344881 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5AD71000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528346628 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5AD71000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528349908 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5AD71000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528350240 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5AD71000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528350564 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5AD71000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528350925 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5AD71000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528351252 |
Section loaded |
Path: \KnownDlls\ShimEng.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
528353977 |
File opened |
Path: C:\WINDOWS\system32\ShimEng.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
528364507 |
Section loaded |
Path: C:\WINDOWS\system32\shimeng.dll Access: query and write and read and execute
Type: image Baseaddress: 5CB70000 Size: 155648 Protection: read write Mapped to pid:
own pid
|
success or wait |
528365968 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5CB71000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528374352 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5CB71000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528374869 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5CB71000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528375185 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5CB71000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528382185 |
File opened |
Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file Attributes:
normal Content Overwritten: null
|
success or wait |
528383234 |
Section loaded |
Path: C:\WINDOWS\AppPatch\sysmain.sdb Access: read Type: commit Baseaddress: 290000
Size: 1208320 Protection: readonly Mapped to pid: own pid
|
success or wait |
528384306 |
File opened |
Path: C:\WINDOWS\AppPatch\systest.sdb Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file Attributes:
normal Content Overwritten: null
|
object name not found |
528385527 |
System info queried |
Type: ProcessorInformation |
success or wait |
528386315 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: Wow64Information |
success or wait |
528392449 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\WPA\MediaCenter Name: Installed |
success or wait |
528392903 |
File opened |
Path: \Device\NamedPipe\ShimViewer Access: write data or add file and append data
or add subdirectory or create pipe instance and write ea and write attributes and
read control and synchronize Options: no options Attributes: normal Content Overwritten:
null
|
object name not found |
528393883 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: Wow64Information |
success or wait |
528394658 |
System info queried |
Type: BasicInformation |
success or wait |
528394906 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3C0000 Length: 7F0C8 Allocation Type:
unknown Protection: page read and write
|
success or wait |
528400526 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3C0000 Length: 7F0CC Allocation Type:
unknown Protection: page read and write
|
success or wait |
528400852 |
File opened |
Path: \Device\NamedPipe\ShimViewer Access: write data or add file and append data
or add subdirectory or create pipe instance and write ea and write attributes and
read control and synchronize Options: no options Attributes: normal Content Overwritten:
null
|
object name not found |
528401479 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3C2000 Length: 7EB64 Allocation Type:
unknown Protection: page read and write
|
success or wait |
528402396 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3C3000 Length: 7EEA8 Allocation Type:
unknown Protection: page read and write
|
success or wait |
528403021 |
File opened |
Path: C:\WINDOWS\AppPatch\AcGenral.DLL Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file Attributes:
normal Content Overwritten: null
|
success or wait |
528422126 |
File opened |
Path: C:\WINDOWS\AppPatch\AcGenral.DLL Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
528426033 |
Section loaded |
Path: C:\WINDOWS\AppPatch\acgenral.dll Access: write and read and execute Type: commit
Baseaddress: 410000 Size: 1855488 Protection: execute Mapped to pid: own pid
|
success or wait |
528429955 |
File opened |
Path: C:\WINDOWS\AppPatch\AcGenral.DLL Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
528431945 |
Section loaded |
Path: C:\WINDOWS\AppPatch\acgenral.dll Access: write and read and execute Type: commit
Baseaddress: 410000 Size: 1855488 Protection: execute Mapped to pid: own pid
|
success or wait |
528435389 |
File opened |
Path: C:\WINDOWS\AppPatch\AcGenral.DLL Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
528440262 |
Section loaded |
Path: C:\WINDOWS\AppPatch\acgenral.dll Access: query and write and read and execute
Type: image Baseaddress: 6F880000 Size: 1875968 Protection: read write Mapped to pid:
own pid
|
success or wait |
528441567 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 6F881000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528460550 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 6F881000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528461602 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 6F881000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528462043 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 6F881000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528507236 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 6F881000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528508206 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 6F881000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528508536 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 6F881000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528508864 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 6F881000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528509205 |
Section loaded |
Path: \KnownDlls\WINMM.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
528509599 |
File opened |
Path: C:\WINDOWS\system32\WINMM.dll Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
528520225 |
Section loaded |
Path: C:\WINDOWS\system32\winmm.dll Access: query and write and read and execute Type:
image Baseaddress: 76B40000 Size: 184320 Protection: read write Mapped to pid: own
pid
|
success or wait |
528522049 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76B41000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528525509 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76B41000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528532176 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76B41000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528532547 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76B41000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528532899 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76B41000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528533258 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76B41000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528533731 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76B41000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528534550 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76B41000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528539584 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76B41000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528539955 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 76B41000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528540308 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 6F881000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528540641 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 6F881000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528540964 |
Section loaded |
Path: \KnownDlls\MSACM32.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
528542808 |
File opened |
Path: C:\WINDOWS\system32\MSACM32.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
528548299 |
Section loaded |
Path: C:\WINDOWS\system32\msacm32.dll Access: query and write and read and execute
Type: image Baseaddress: 77BE0000 Size: 86016 Protection: read write Mapped to pid:
own pid
|
success or wait |
528549941 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77BE1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528559526 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77BE1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528560031 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77BE1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528560438 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77BE1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528560793 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77BE1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528561154 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77BE1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528561575 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77BE1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528576820 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77BE1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528577189 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77BE1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528577553 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77BE1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528577909 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 6F881000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528578257 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 6F881000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528578582 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 6F881000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528586115 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 6F881000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528586450 |
Section loaded |
Path: \KnownDlls\USERENV.dll Access: write and read and execute Type: unknown Baseaddress:
769C0000 Size: 737280 Protection: read write Mapped to pid: own pid
|
success or wait |
528586851 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 769C1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528588675 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 769C1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528627599 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 769C1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528627979 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 769C1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528628454 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 769C1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528628813 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 769C1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528629176 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 769C1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528630615 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 769C1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528636470 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 769C1000 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528636838 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 769C1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528637204 |
System info queried |
Type: BasicInformation |
success or wait |
528638351 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D0000 Length: 7E978 Allocation Type:
unknown Protection: page read and write
|
success or wait |
528638709 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D0000 Length: 7E97C Allocation Type:
unknown Protection: page read and write
|
success or wait |
528639311 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D1000 Length: 7E658 Allocation Type:
unknown Protection: page read and write
|
success or wait |
528644142 |
Section loaded |
Path: \NLS\NlsSectionCType Access: read Type: unknown Baseaddress: 3E0000 Size: 12288
Protection: readonly Mapped to pid: own pid
|
success or wait |
528645066 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D3000 Length: 7E70C Allocation Type:
unknown Protection: page read and write
|
success or wait |
528647008 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: Cookie |
success or wait |
528648659 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: Cookie |
success or wait |
528656041 |
Mutant created |
Name: \BaseNamedObjects\SHIMLIB_LOG_MUTEX |
object name exists |
528656587 |
File opened |
Path: \Device\NamedPipe\ShimViewer Access: write data or add file and append data
or add subdirectory or create pipe instance and write ea and write attributes and
read control and synchronize Options: no options Attributes: normal Content Overwritten:
null
|
object name not found |
528658717 |
System info queried |
Type: BasicInformation |
success or wait |
528659434 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 410000 Length: 7F04C Allocation Type:
unknown Protection: page read and write
|
success or wait |
528659781 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 410000 Length: 7F050 Allocation Type:
unknown Protection: page read and write
|
success or wait |
528665013 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 411000 Length: 7ED2C Allocation Type:
unknown Protection: page read and write
|
success or wait |
528665444 |
System info queried |
Type: BasicInformation |
success or wait |
528666069 |
System info queried |
Type: ProcessorInformation |
success or wait |
528666379 |
File opened |
Path: C:\WINDOWS\AppPatch\AcGenral.DLL Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file Attributes:
normal Content Overwritten: null
|
success or wait |
528670641 |
File opened |
Path: \Device\NamedPipe\ShimViewer Access: write data or add file and append data
or add subdirectory or create pipe instance and write ea and write attributes and
read control and synchronize Options: no options Attributes: normal Content Overwritten:
null
|
object name not found |
528672292 |
System info queried |
Type: BasicInformation |
success or wait |
528672969 |
System info queried |
Type: ProcessorInformation |
success or wait |
528678798 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 1001268 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528679387 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 1001000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528679687 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77DD1218 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528697175 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77DD1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528697485 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77E71178 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528697796 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77E71000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528698088 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77FE1098 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528698392 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77FE1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528698682 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 75F811EC Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528715309 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 75F81000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528715616 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77F110B4 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528716055 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77F11000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528716351 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7E41133C Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528716705 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7E411000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528716997 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77C110D0 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528728229 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77C11000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528728536 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 774E1218 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528728858 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 774E1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528729194 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77F61438 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528729540 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77F61000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528729834 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7712129C Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528779541 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77121000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528779849 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7E2911E8 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528780210 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 7E291000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528780503 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77A81188 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528780866 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77A81000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528781157 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77B2103C Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528786717 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77B21000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528787018 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 754D12F8 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528787327 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 754D1000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528787618 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5B8611BC Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528787926 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 5B861000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528788218 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77C01050 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528796202 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 77C01000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528796509 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D9314B0 Length: 1000 New Protection:
page read and write Old Protection: page execute read
|
success or wait |
528796849 |
Memory attributes changed |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 3D931000 Length: 1000 New Protection:
page execute read Old Protection: page read and write
|
success or wait |
528797142 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: ImageInformation |
success or wait |
528825205 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 94000 Length: 7F788 Allocation Type:
unknown Protection: page read and write
|
success or wait |
528871865 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Name:
LeakTrack
|
object name not found |
528878057 |
System info queried |
Type: BasicInformation |
success or wait |
528879127 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager Name: SafeDllSearchMode |
object name not found |
528880192 |
File opened |
Path: C:\WINDOWS\system32\IMM32.DLL Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
528888924 |
Section loaded |
Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit
Baseaddress: 360000 Size: 110592 Protection: execute Mapped to pid: own pid
|
success or wait |
528889969 |
File opened |
Path: C:\WINDOWS\system32\IMM32.DLL Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
528892679 |
Section loaded |
Path: C:\WINDOWS\system32\imm32.dll Access: write and read and execute Type: commit
Baseaddress: 360000 Size: 110592 Protection: execute Mapped to pid: own pid
|
success or wait |
528899226 |
File opened |
Path: C:\WINDOWS\system32\IMM32.DLL Access: execute or traverse and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
529096399 |
Section loaded |
Path: C:\WINDOWS\system32\imm32.dll Access: query and write and read and execute Type:
image Baseaddress: 76390000 Size: 118784 Protection: read write Mapped to pid: own
pid
|
success or wait |
529097583 |
System info queried |
Type: BasicInformation |
success or wait |
529126589 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
Name: DisableMetaFiles
|
object name not found |
529127756 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Name:
AppInit_DLLs
|
success or wait |
529130116 |
System info queried |
Type: BasicInformation |
success or wait |
529379832 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 370000 Length: 7F91C Allocation Type:
unknown Protection: page read and write
|
success or wait |
529381974 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 370000 Length: 7F920 Allocation Type:
unknown Protection: page read and write
|
success or wait |
529382435 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 371000 Length: 7F5FC Allocation Type:
unknown Protection: page read and write
|
success or wait |
529383067 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 373000 Length: 7F6B8 Allocation Type:
unknown Protection: page read and write
|
success or wait |
529390545 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: Cookie |
success or wait |
529392123 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: Cookie |
success or wait |
529392385 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 95000 Length: 7F5BC Allocation Type:
unknown Protection: page read and write
|
success or wait |
529399012 |
File opened |
Path: \Device\KsecDD Access: read data or list directory and synchronize Options:
synchronous io alert Overwritten: false
|
success or wait |
529411354 |
System info queried |
Type: BasicInformation |
success or wait |
529421570 |
System info queried |
Type: ProcessorInformation |
success or wait |
529421865 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager Name: CriticalSectionTimeout |
success or wait |
529422896 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole Name: RWLockResourceTimeOut |
object name not found |
529423826 |
System info queried |
Type: BasicInformation |
success or wait |
529474470 |
System info queried |
Type: ProcessorInformation |
success or wait |
529474775 |
System info queried |
Type: BasicInformation |
success or wait |
529477489 |
System info queried |
Type: ProcessorInformation |
success or wait |
529477843 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface Name: InterfaceHelperDisableAll |
object name not found |
529478316 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface Name: InterfaceHelperDisableAllForOle32 |
object name not found |
529478944 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface Name: InterfaceHelperDisableTypeLib |
object name not found |
529479259 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00020400-0000-0000-C000-000000000046}
Name: InterfaceHelperDisableAll
|
object name not found |
529480524 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00020400-0000-0000-C000-000000000046}
Name: InterfaceHelperDisableAllForOle32
|
object name not found |
529480849 |
File opened |
Path: C:\WINDOWS\system32\BROWSEUI.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
529485056 |
Section loaded |
Path: C:\WINDOWS\system32\browseui.dll Access: read Type: commit Baseaddress: 860000
Size: 1028096 Protection: readonly Mapped to pid: own pid
|
success or wait |
529486138 |
File opened |
Path: C:\WINDOWS\system32\BROWSEUI.dll.123.Manifest Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
529490953 |
File opened |
Path: C:\WINDOWS\system32\BROWSEUI.dll.123.Config Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
529495858 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 96000 Length: 7F244 Allocation Type:
unknown Protection: page read and write
|
success or wait |
529529808 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
Access: execute or traverse and synchronize Options: directory file and synchronous
io non alert Overwritten: false
|
success or wait |
529530837 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
Access: execute or traverse and synchronize Options: synchronous io non alert and
non directory file Overwritten: false
|
success or wait |
529532709 |
Section loaded |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
Access: write and read and execute Type: commit Baseaddress: 860000 Size: 1056768
Protection: execute Mapped to pid: own pid
|
success or wait |
529534333 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
Access: execute or traverse and synchronize Options: synchronous io non alert and
non directory file Overwritten: false
|
success or wait |
529537553 |
Section loaded |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
Access: query and write and read and execute Type: image Baseaddress: 773D0000 Size:
1060864 Protection: read write Mapped to pid: own pid
|
success or wait |
529554813 |
File opened |
Path: C:\WINDOWS\WindowsShell.Manifest Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
529575099 |
Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: write and read and execute Type: commit
Baseaddress: 390000 Size: 4096 Protection: execute Mapped to pid: own pid
|
success or wait |
529576694 |
File opened |
Path: C:\WINDOWS\WindowsShell.Manifest Access: read attributes and synchronize and
generic read Options: synchronous io non alert and non directory file Attributes:
none Content Overwritten: null
|
success or wait |
529580716 |
Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: query and read Type: commit Baseaddress:
390000 Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
529583861 |
File opened |
Path: C:\WINDOWS\WindowsShell.Manifest Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
529588317 |
Section loaded |
Path: C:\WINDOWS\WindowsShell.Manifest Access: read Type: commit Baseaddress: 390000
Size: 4096 Protection: readonly Mapped to pid: own pid
|
success or wait |
529589499 |
File opened |
Path: C:\WINDOWS\WindowsShell.Config Access: read data or list directory and read
ea and execute or traverse and read attributes and read control and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
object name not found |
529591009 |
Key value queried |
Path: HKEY_USERS\Control Panel\Desktop Name: SmoothScroll |
object name not found |
529627262 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
EnableBalloonTips
|
object name not found |
529631189 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 97000 Length: 7F680 Allocation Type:
unknown Protection: page read and write
|
success or wait |
529644315 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 98000 Length: 7F680 Allocation Type:
unknown Protection: page read and write
|
success or wait |
529646983 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 99000 Length: 7F67C Allocation Type:
unknown Protection: page read and write
|
success or wait |
529648229 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 9A000 Length: 7F6E4 Allocation Type:
unknown Protection: page read and write
|
success or wait |
529649075 |
File opened |
Path: C:\WINDOWS\system32\urlmon.dll.123.Manifest Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
529662581 |
File opened |
Path: C:\WINDOWS\system32\urlmon.dll.123.Config Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
529663634 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 9B000 Length: 7F448 Allocation Type:
unknown Protection: page read and write
|
success or wait |
529700338 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
Access: execute or traverse and synchronize Options: directory file and synchronous
io non alert Overwritten: false
|
success or wait |
529702228 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
Name: DisableImprovedZoneCheck
|
object name not found |
529710202 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN
Name: explorer.exe
|
success or wait |
529730073 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 9C000 Length: 7F6CC Allocation Type:
unknown Protection: page read and write
|
success or wait |
529738784 |
System info queried |
Type: BasicInformation |
success or wait |
529739341 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 860000 Length: 7F918 Allocation Type:
unknown Protection: page read and write
|
success or wait |
529739715 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 860000 Length: 7F91C Allocation Type:
unknown Protection: page read and write
|
success or wait |
529741002 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 861000 Length: 7F5F8 Allocation Type:
unknown Protection: page read and write
|
success or wait |
529741464 |
File opened |
Path: WMIDataDevice Access: read attributes and synchronize and generic read and generic
write Options: non directory file Attributes: normal Content Overwritten: true
|
success or wait |
529742071 |
File opened |
Path: WMIDataDevice Access: read attributes and synchronize and generic read and generic
write Options: non directory file Attributes: normal Content Overwritten: true
|
success or wait |
529748511 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 863000 Length: 7F590 Allocation Type:
unknown Protection: page read and write
|
success or wait |
529749165 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 960000 Length: 7F368 Allocation Type:
unknown Protection: page read and write
|
success or wait |
529749622 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 991000 Length: 7F364 Allocation Type:
unknown Protection: page read and write
|
success or wait |
529750243 |
Thread created |
PID: 1696 TID: 2000 EIP: 7C8106F9 EAX: 77DF848A Imagepath: C:\WINDOWS\explorer.exe |
success or wait |
529751974 |
Thread resumed |
TID: 2000 PID: 1696 Path: C:\WINDOWS\explorer.exe |
success or wait |
529753591 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 865000 Length: 7F4FC Allocation Type:
unknown Protection: page read and write
|
success or wait |
529756403 |
File opened |
Path: C:\WINDOWS\system32\WININET.dll.123.Manifest Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
529764285 |
File opened |
Path: C:\WINDOWS\system32\WININET.dll.123.Config Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
529765532 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
Access: execute or traverse and synchronize Options: directory file and synchronous
io non alert Overwritten: false
|
success or wait |
529801281 |
System info queried |
Type: BasicInformation |
success or wait |
529811289 |
System info queried |
Type: ProcessorInformation |
success or wait |
529811594 |
System info queried |
Type: BasicInformation |
success or wait |
529813408 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 9A0000 Length: 7F9A0 Allocation Type:
unknown Protection: page read and write
|
success or wait |
529814396 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 9A0000 Length: 7F9A4 Allocation Type:
unknown Protection: page read and write
|
success or wait |
529814687 |
Mutant created |
Name: unknown |
success or wait |
529815714 |
Mutant created |
Name: unknown |
success or wait |
529816019 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ldap Name: LdapClientIntegrity |
success or wait |
529816582 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 9E000 Length: 7F418 Allocation Type:
unknown Protection: page read and write
|
success or wait |
529817497 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
Access: execute or traverse and synchronize Options: directory file and synchronous
io non alert Overwritten: false
|
success or wait |
529818482 |
Section loaded |
Path: \KnownDlls\RichEd20.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
529821413 |
File opened |
Path: C:\WINDOWS\system32\RichEd20.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
529823223 |
Section loaded |
Path: C:\WINDOWS\system32\riched20.dll Access: query and write and read and execute
Type: image Baseaddress: 74E30000 Size: 446464 Protection: read write Mapped to pid:
own pid
|
success or wait |
529824411 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 374000 Length: 7EFA4 Allocation Type:
unknown Protection: page read and write
|
success or wait |
529854977 |
File opened |
Path: C:\WINDOWS\system32\SHDOCVW.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
529857211 |
Section loaded |
Path: C:\WINDOWS\system32\shdocvw.dll Access: read Type: commit Baseaddress: AA0000
Size: 1499136 Protection: readonly Mapped to pid: own pid
|
success or wait |
529859261 |
File opened |
Path: C:\WINDOWS\system32\SHDOCVW.dll.123.Manifest Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
529883461 |
File opened |
Path: C:\WINDOWS\system32\SHDOCVW.dll.123.Config Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
529885822 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
Access: execute or traverse and synchronize Options: directory file and synchronous
io non alert Overwritten: false
|
success or wait |
529900589 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EAB22AC1-30C1-11CF-A7EB-0000C05BAE0B}\TypeLib
Name: NULL
|
success or wait |
529905740 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B722BCCB-4E68-101B-A2BC-00AA00404770}\ProxyStubClsid32
Name: NULL
|
success or wait |
529906692 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{79EAC9C4-BAF9-11CE-8C82-00AA004BA90B}\ProxyStubClsid32
Name: NULL
|
success or wait |
529908080 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{000214E6-0000-0000-C000-000000000046}\ProxyStubClsid32
Name: NULL
|
success or wait |
529909049 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{93F2F68C-1D1B-11D3-A30E-00C04F79ABD1}\ProxyStubClsid32
Name: NULL
|
success or wait |
529909700 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\Setup Name: SystemSetupInProgress |
success or wait |
529910332 |
File opened |
Path: C:\WINDOWS\system32\SHELL32.dll Access: read data or list directory and read
ea and execute or traverse and read attributes and read control and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
529911479 |
Section loaded |
Path: C:\WINDOWS\system32\shell32.dll Access: read Type: commit Baseaddress: 1100000
Size: 8462336 Protection: readonly Mapped to pid: own pid
|
success or wait |
529912099 |
File opened |
Path: C:\WINDOWS\system32\SHELL32.dll.124.Manifest Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
529912989 |
File opened |
Path: C:\WINDOWS\system32\SHELL32.dll.124.Config Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
529913601 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: 9F000 Length: 7F24C Allocation Type:
unknown Protection: page read and write
|
success or wait |
529927408 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
Access: execute or traverse and synchronize Options: directory file and synchronous
io non alert Overwritten: false
|
success or wait |
529927761 |
Section loaded |
Path: \KnownDlls\comctl32.dll Access: write and read and execute Type: unknown Baseaddress:
5D090000 Size: 630784 Protection: read write Mapped to pid: own pid
|
success or wait |
529928852 |
System info queried |
Type: BasicInformation |
success or wait |
529937723 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: AB0000 Length: 7F1B8 Allocation Type:
unknown Protection: page read and write
|
success or wait |
529937865 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: AB0000 Length: 7F1BC Allocation Type:
unknown Protection: page read and write
|
success or wait |
529937994 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: AB1000 Length: 7EE98 Allocation Type:
unknown Protection: page read and write
|
success or wait |
529938287 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: AB3000 Length: 7EF4C Allocation Type:
unknown Protection: page read and write
|
success or wait |
529938565 |
File opened |
Path: C:\WINDOWS\system32\comctl32.dll Access: read data or list directory and read
ea and execute or traverse and read attributes and read control and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
529939124 |
Section loaded |
Path: C:\WINDOWS\system32\comctl32.dll Access: read Type: commit Baseaddress: AC0000
Size: 618496 Protection: readonly Mapped to pid: own pid
|
success or wait |
529939549 |
File opened |
Path: C:\WINDOWS\system32\comctl32.dll.124.Manifest Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
529939922 |
File opened |
Path: C:\WINDOWS\system32\comctl32.dll.124.Config Access: read data or list directory
and read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
529940828 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: SessionInformation |
success or wait |
529943955 |
Key value queried |
Path: HKEY_USERS\Control Panel\Desktop Name: SmoothScroll |
object name not found |
529944996 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\ThemeManager Name: Compositing |
object name not found |
529946721 |
Key value queried |
Path: HKEY_USERS\Control Panel\Desktop Name: LameButtonText |
object name not found |
529947623 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave
|
success or wait |
529948713 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: AC0000 Length: 7F52C Allocation Type:
unknown Protection: page read and write
|
success or wait |
529949460 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: AC0000 Length: 7F528 Allocation Type:
unknown Protection: page read and write
|
success or wait |
529949714 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave
|
success or wait |
529949861 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave1
|
success or wait |
529950222 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave1
|
success or wait |
529950607 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave2
|
object name not found |
529950980 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave3
|
object name not found |
529951392 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave4
|
object name not found |
529952197 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave5
|
object name not found |
529952616 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave6
|
object name not found |
529953243 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave7
|
object name not found |
529954184 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave8
|
object name not found |
529954851 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
wave9
|
object name not found |
529955227 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi
|
success or wait |
529955725 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi
|
success or wait |
529956095 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi1
|
success or wait |
529956479 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi1
|
success or wait |
529957072 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi2
|
object name not found |
529957454 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi3
|
object name not found |
529957811 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi4
|
object name not found |
529958621 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi5
|
object name not found |
529959026 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi6
|
object name not found |
529959653 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi7
|
object name not found |
529960568 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi8
|
object name not found |
529961237 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
midi9
|
object name not found |
529961597 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux
|
success or wait |
529962125 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux
|
success or wait |
529962495 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux1
|
success or wait |
529962851 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux1
|
success or wait |
529963230 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux2
|
object name not found |
529963603 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux3
|
object name not found |
529963959 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux4
|
object name not found |
529964760 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux5
|
object name not found |
529965180 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux6
|
object name not found |
529966387 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux7
|
object name not found |
529967286 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux8
|
object name not found |
529967951 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
aux9
|
object name not found |
529968326 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaProperties\PrivateProperties\Joystick\Winmm
Name: wheel
|
success or wait |
529968907 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer
|
success or wait |
529969374 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer
|
success or wait |
529969745 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer1
|
success or wait |
529970119 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer1
|
success or wait |
529970969 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer2
|
object name not found |
529971639 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer3
|
object name not found |
529972036 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer4
|
object name not found |
529972954 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer5
|
object name not found |
529973602 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer6
|
object name not found |
529973976 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer7
|
object name not found |
529974481 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer8
|
object name not found |
529974839 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
mixer9
|
object name not found |
529975196 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Multimedia\Audio Name: SystemFormats |
success or wait |
529975992 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: A0000 Length: 7EEE8 Allocation Type:
unknown Protection: page read and write
|
success or wait |
529977341 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
msacm.imaadpcm
|
buffer overflow |
529977660 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
msacm.imaadpcm
|
success or wait |
529978343 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm
Name: fdwSupport
|
success or wait |
529983777 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm
Name: cFormatTags
|
success or wait |
529984158 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm
Name: aFormatTagCache
|
success or wait |
529984347 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm
Name: cFilterTags
|
success or wait |
529984531 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
msacm.msadpcm
|
buffer overflow |
529985414 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
msacm.msadpcm
|
success or wait |
529985541 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm
Name: fdwSupport
|
success or wait |
529986143 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm
Name: cFormatTags
|
success or wait |
529986916 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm
Name: aFormatTagCache
|
success or wait |
529987121 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm
Name: cFilterTags
|
success or wait |
529987306 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
msacm.msg711
|
buffer overflow |
529988166 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
msacm.msg711
|
success or wait |
529988383 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711
Name: fdwSupport
|
success or wait |
529988695 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711
Name: cFormatTags
|
success or wait |
529989050 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711
Name: aFormatTagCache
|
success or wait |
529989237 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711
Name: cFilterTags
|
success or wait |
529989421 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
msacm.msgsm610
|
buffer overflow |
529990335 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
msacm.msgsm610
|
success or wait |
529990731 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610
Name: fdwSupport
|
success or wait |
529991036 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610
Name: cFormatTags
|
success or wait |
529991782 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610
Name: aFormatTagCache
|
success or wait |
529991997 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610
Name: cFilterTags
|
success or wait |
529992489 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
msacm.trspch
|
buffer overflow |
529993238 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
msacm.trspch
|
success or wait |
529993378 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch
Name: fdwSupport
|
success or wait |
529993690 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch
Name: cFormatTags
|
success or wait |
529994381 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch
Name: aFormatTagCache
|
success or wait |
529994595 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch
Name: cFilterTags
|
success or wait |
529995022 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
msacm.msg723
|
buffer overflow |
529996306 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
msacm.msg723
|
success or wait |
529996580 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723
Name: fdwSupport
|
success or wait |
530001103 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723
Name: cFormatTags
|
success or wait |
530001322 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723
Name: aFormatTagCache
|
success or wait |
530001518 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723
Name: cFilterTags
|
success or wait |
530001709 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
msacm.msaudio1
|
buffer overflow |
530002849 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
msacm.msaudio1
|
success or wait |
530003546 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1
Name: fdwSupport
|
success or wait |
530004139 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1
Name: cFormatTags
|
success or wait |
530004484 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1
Name: aFormatTagCache
|
success or wait |
530004678 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1
Name: cFilterTags
|
success or wait |
530004870 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
msacm.sl_anet
|
buffer overflow |
530005319 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
msacm.sl_anet
|
success or wait |
530005915 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: A1000 Length: 7EF90 Allocation Type:
unknown Protection: page read and write
|
success or wait |
530006410 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet
Name: fdwSupport
|
success or wait |
530007193 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet
Name: cFormatTags
|
success or wait |
530007677 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet
Name: aFormatTagCache
|
success or wait |
530007874 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet
Name: cFilterTags
|
success or wait |
530008211 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
msacm.iac2
|
buffer overflow |
530009276 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
msacm.iac2
|
success or wait |
530009413 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2
Name: fdwSupport
|
success or wait |
530010213 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2
Name: cFormatTags
|
success or wait |
530010671 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2
Name: aFormatTagCache
|
success or wait |
530010870 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2
Name: cFilterTags
|
success or wait |
530011649 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
msacm.l3acm
|
buffer overflow |
530012507 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Name:
msacm.l3acm
|
success or wait |
530012644 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm
Name: fdwSupport
|
success or wait |
530012988 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm
Name: cFormatTags
|
success or wait |
530013185 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm
Name: aFormatTagCache
|
success or wait |
530013409 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm
Name: cFilterTags
|
success or wait |
530014161 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Multimedia\Audio Compression Manager\MSACM Name:
NoPCMConverter
|
object name not found |
530020146 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: A2000 Length: 7EFB0 Allocation Type:
unknown Protection: page read and write
|
success or wait |
530020903 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Multimedia\Audio Compression Manager\Priority
v4.00 Name: Priority1
|
object name not found |
530023350 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Name:
UserEnvDebugLevel
|
object name not found |
530023938 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Name:
ChkAccDebugLevel
|
object name not found |
530024286 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ProductOptions Name: ProductType |
success or wait |
530026066 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Name: Personal
|
success or wait |
530030568 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Name: Local Settings
|
success or wait |
530030779 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Name:
RsopDebugLevel
|
object name not found |
530031693 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Name:
UserEnvDebugLevel
|
object name not found |
530032875 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Name:
RsopLogging
|
object name not found |
530033071 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System Name: UserEnvDebugLevel |
object name not found |
530033872 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System Name: RsopLogging |
object name not found |
530034063 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Name:
UserEnvDebugLevel
|
object name not found |
530034411 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System Name: UserEnvDebugLevel |
object name not found |
530034749 |
File opened |
Path: WMIDataDevice Access: read attributes and synchronize and generic read and generic
write Options: non directory file Attributes: normal Content Overwritten: true
|
success or wait |
530040398 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: DefaultHardErrorMode |
success or wait |
530043095 |
File opened |
Path: C:\WINDOWS\explorer.exe Access: read data or list directory and read ea and
execute or traverse and read attributes and read control and synchronize Options:
synchronous io non alert and non directory file Overwritten: false
|
success or wait |
530043634 |
Section loaded |
Path: C:\WINDOWS\explorer.exe Access: read Type: commit Baseaddress: B70000 Size:
1036288 Protection: readonly Mapped to pid: own pid
|
success or wait |
530044028 |
File opened |
Path: C:\WINDOWS\explorer.exe.123.Manifest Access: read data or list directory and
read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
530044384 |
File opened |
Path: C:\WINDOWS\explorer.exe.123.Config Access: read data or list directory and
read ea and execute or traverse and read attributes and read control and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
object name not found |
530044800 |
File opened |
Path: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
Access: execute or traverse and synchronize Options: directory file and synchronous
io non alert Overwritten: false
|
success or wait |
530057930 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: NoNetHood
|
object name not found |
530067279 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoNetHood
|
object name not found |
530067766 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: NoPropertiesMyComputer
|
object name not found |
530068204 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoPropertiesMyComputer
|
object name not found |
530068642 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: NoInternetIcon
|
object name not found |
530069069 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoInternetIcon
|
object name not found |
530069540 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: NoCommonGroups
|
object name not found |
530070259 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoCommonGroups
|
object name not found |
530070690 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: NoControlPanel
|
object name not found |
530071273 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoControlPanel
|
object name not found |
530075553 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: NoSetFolders
|
object name not found |
530076141 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoSetFolders
|
object name not found |
530076656 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32
Name: NULL
|
success or wait |
530077418 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: DeviceMap |
success or wait |
530077884 |
Section loaded |
Path: \KnownDlls\SETUPAPI.dll Access: write and read and execute Type: unknown Baseaddress:
unknown Size: unknown Protection: unknown Mapped to pid: unknown
|
object name not found |
530078162 |
File opened |
Path: C:\WINDOWS\system32\SETUPAPI.dll Access: execute or traverse and synchronize
Options: synchronous io non alert and non directory file Overwritten: false
|
success or wait |
530078524 |
Section loaded |
Path: C:\WINDOWS\system32\setupapi.dll Access: query and write and read and execute
Type: image Baseaddress: 77920000 Size: 995328 Protection: read write Mapped to pid:
own pid
|
success or wait |
530079000 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: Wow64Information |
success or wait |
530084773 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\Setup Name: SystemSetupInProgress |
success or wait |
530085061 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\WPA\PnP Name: seed |
success or wait |
530085622 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\Setup Name: OsLoaderPath |
success or wait |
530086164 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\Setup Name: OsLoaderPath |
success or wait |
530086462 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\Setup Name: SystemPartition |
success or wait |
530087014 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\Setup Name: SystemPartition |
success or wait |
530087309 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: SourcePath |
success or wait |
530087886 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: SourcePath |
success or wait |
530088199 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: ServicePackSourcePath |
success or wait |
530088746 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: ServicePackSourcePath |
success or wait |
530089045 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: ServicePackCachePath |
success or wait |
530092932 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: ServicePackCachePath |
success or wait |
530094321 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: DriverCachePath |
success or wait |
530094922 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: DriverCachePath |
success or wait |
530095219 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion Name: DevicePath |
success or wait |
530095777 |
Mutant created |
Name: unknown |
success or wait |
530096270 |
Mutant created |
Name: unknown |
success or wait |
530096476 |
Mutant created |
Name: unknown |
success or wait |
530096680 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: LogLevel |
success or wait |
530096984 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: LogLevel |
success or wait |
530097283 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup Name: LogPath |
object name not found |
530097590 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName
Name: ComputerName
|
success or wait |
530098247 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters Name: Hostname |
success or wait |
530098793 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters Name: Domain |
success or wait |
530099335 |
System info queried |
Type: BasicInformation |
success or wait |
530100241 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc Name: MaxRpcSize |
object name not found |
530100538 |
System time queried |
Time: 129718679881093750 |
success or wait |
530101087 |
System info queried |
Type: PerformanceInformation |
success or wait |
530101384 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: QuotaLimits |
success or wait |
530101736 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: VmCounters |
success or wait |
530101954 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName
Name: ComputerName
|
success or wait |
530102410 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: A3000 Length: 7EA88 Allocation Type:
unknown Protection: page read and write
|
success or wait |
530103138 |
File opened |
Path: \pipe\lsarpc Access: read attributes and synchronize and generic read and generic
write Options: non directory file Attributes: none Content Overwritten: true
|
success or wait |
530103487 |
File other op |
Path: \lsarpc New path: Disposition: PipeInformation Data : unknown |
success or wait |
530103883 |
File other op |
Path: \lsarpc New path: Disposition: CompletionInformation Data : unknown |
success or wait |
530104134 |
File write |
Path: \lsarpc Offset: 0 Length: 72 Value: 05 00 0b 03 10 00 00 00 48 00 00 00 01 00
00 00 b8 10 b8 10 00 00 00 00 01 00 00 00 00 00 01 00 78 57 34 12 34 12 cd ab ef 00
01 23 45 67 89 ab 00 00 00 00 04 5d 88 8a eb 1c c9 11 9f e8 08 00 2b 10 48 60 02 00
00 00
|
success or wait |
530114763 |
File read |
Path: \lsarpc Offset: 0 Length: 1024 |
pending |
530115552 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........@.......(.....,......................................... |
pending |
530115997 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........j.......R...........h.F...P@..\../,.*.,.................S.e.L.o.a.d.D.r.i.v.e.r.P.r.i.v.i.l.e.g.e. |
pending |
530116733 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........,...................h.F...P@..\../,. |
pending |
530117269 |
File opened |
Path: \pipe\lsarpc Access: read attributes and synchronize and generic read and generic
write Options: non directory file Attributes: none Content Overwritten: true
|
success or wait |
530118351 |
File other op |
Path: \lsarpc New path: Disposition: PipeInformation Data : unknown |
success or wait |
530118725 |
File other op |
Path: \lsarpc New path: Disposition: CompletionInformation Data : unknown |
success or wait |
530118968 |
File write |
Path: \lsarpc Offset: 0 Length: 72 Value: 05 00 0b 03 10 00 00 00 48 00 00 00 01 00
00 00 b8 10 b8 10 00 00 00 00 01 00 00 00 00 00 01 00 78 57 34 12 34 12 cd ab ef 00
01 23 45 67 89 ab 00 00 00 00 04 5d 88 8a eb 1c c9 11 9f e8 08 00 2b 10 48 60 02 00
00 00
|
success or wait |
530128241 |
File read |
Path: \lsarpc Offset: 0 Length: 1024 |
pending |
530129008 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........@.......(.....,......................................... |
pending |
530129374 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........b.......J...........J.kfz..I./v.LP..".$.................S.e.U.n.d.o.c.k.P.r.i.v.i.l.e.g.e. |
pending |
530130029 |
File control set |
Path: \lsarpc Control Code: 11C017 Input Buffer: ........,...................J.kfz..I./v.LP.. |
pending |
530130555 |
Privilege adjusted |
Privilege: Load Driver On or off: on |
success or wait |
530131528 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: A4000 Length: 7EFEC Allocation Type:
unknown Protection: page read and write
|
success or wait |
530131893 |
Privilege adjusted |
Privilege: Load Driver On or off: on |
success or wait |
530145109 |
File opened |
Path: IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#42562d3131303066333036662020202020202020#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Access: read attributes and synchronize Options: synchronous io non alert and non
directory file Overwritten: false
|
success or wait |
530148448 |
File opened |
Path: IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#42562d3131303066333036662020202020202020#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Access: read attributes and synchronize Options: synchronous io non alert and non
directory file Overwritten: false
|
success or wait |
530149630 |
File opened |
Path: MountPointManager Access: read attributes and synchronize Options: synchronous
io non alert and non directory file Attributes: normal Content Overwritten: true
|
success or wait |
530151172 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: A5000 Length: 7EE70 Allocation Type:
unknown Protection: page read and write
|
success or wait |
530153267 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{e9036068-1842-11df-9766-806d6172696f}
Name: Data
|
buffer overflow |
530157702 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{e9036068-1842-11df-9766-806d6172696f}
Name: Data
|
success or wait |
530158017 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{e9036068-1842-11df-9766-806d6172696f}
Name: Generation
|
success or wait |
530159116 |
File opened |
Path: STORAGE#Volume#1&30a96598&0&SignatureF4ACF4ACOffset7E00Length3BFEFCE00#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Access: read attributes and synchronize Options: synchronous io non alert and non
directory file Overwritten: false
|
success or wait |
530159600 |
File opened |
Path: STORAGE#Volume#1&30a96598&0&SignatureF4ACF4ACOffset7E00Length3BFEFCE00#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Access: read attributes and synchronize Options: synchronous io non alert and non
directory file Overwritten: false
|
success or wait |
530160575 |
File opened |
Path: MountPointManager Access: read attributes and synchronize Options: synchronous
io non alert and non directory file Attributes: normal Content Overwritten: true
|
success or wait |
530161838 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{0d6ab97b-ade6-11de-bdcc-806d6172696f}
Name: Data
|
buffer overflow |
530163985 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{0d6ab97b-ade6-11de-bdcc-806d6172696f}
Name: Data
|
success or wait |
530164252 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{0d6ab97b-ade6-11de-bdcc-806d6172696f}
Name: Generation
|
success or wait |
530165197 |
File opened |
Path: MountPointManager Access: read attributes and synchronize Options: synchronous
io non alert and non directory file Attributes: normal Content Overwritten: true
|
success or wait |
530165687 |
File opened |
Path: MountPointManager Access: read attributes and synchronize Options: synchronous
io non alert and non directory file Attributes: normal Content Overwritten: true
|
success or wait |
530167858 |
Key value replaced with same |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0d6ab97b-ade6-11de-bdcc-806d6172696f}
Name: BaseClass Type: unicode Data: Drive Old data:
|
success or wait |
530174459 |
File opened |
Path: MountPointManager Access: read attributes and synchronize Options: synchronous
io non alert and non directory file Attributes: normal Content Overwritten: true
|
success or wait |
530174854 |
File opened |
Path: MountPointManager Access: read attributes and synchronize Options: synchronous
io non alert and non directory file Attributes: normal Content Overwritten: true
|
success or wait |
530177144 |
Key value replaced with same |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e9036068-1842-11df-9766-806d6172696f}
Name: BaseClass Type: unicode Data: Drive Old data:
|
success or wait |
530180248 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: DeviceMap |
success or wait |
530180563 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: DeviceMap |
success or wait |
530180754 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: DeviceMap |
success or wait |
530180917 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{0d6ab97b-ade6-11de-bdcc-806d6172696f}
Name: Generation
|
success or wait |
530181379 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
Name: DriveMask
|
success or wait |
530182294 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: DeviceMap |
success or wait |
530182657 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: SeparateProcess
|
object name not found |
530183111 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
SeparateProcess
|
object name not found |
530183528 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer Name: ShellState |
success or wait |
530187908 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer Name: ShellState |
success or wait |
530188174 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: ForceActiveDesktopOn
|
object name not found |
530188601 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
ForceActiveDesktopOn
|
object name not found |
530189015 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: NoActiveDesktop
|
object name not found |
530189431 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoActiveDesktop
|
object name not found |
530189839 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: NoWebView
|
object name not found |
530190289 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoWebView
|
object name not found |
530190698 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: ClassicShell
|
object name not found |
530191141 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
ClassicShell
|
object name not found |
530197533 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: DontShowSuperHidden
|
object name not found |
530198016 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
DontShowSuperHidden
|
object name not found |
530198430 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: NoNetCrawling
|
object name not found |
530198855 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoNetCrawling
|
object name not found |
530199262 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Name: NoSimpleStartMenu
|
object name not found |
530199678 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Name:
NoSimpleStartMenu
|
object name not found |
530200085 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
Hidden
|
success or wait |
530200515 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
ShowCompColor
|
success or wait |
530200752 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
HideFileExt
|
success or wait |
530200968 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
DontPrettyPath
|
success or wait |
530201183 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
ShowInfoTip
|
success or wait |
530201399 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
HideIcons
|
success or wait |
530201614 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
MapNetDrvBtn
|
success or wait |
530201831 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
WebView
|
success or wait |
530202056 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
Filter
|
success or wait |
530202271 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
ShowSuperHidden
|
success or wait |
530202487 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
SeparateProcess
|
success or wait |
530202742 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced Name:
NoNetCrawling
|
success or wait |
530202960 |
Key value queried |
Path: HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer Name: DesktopProcess |
object name not found |
530206928 |
Section loaded |
Path: unknown Access: query and write and read Type: commit Baseaddress: B50000 Size:
4096 Protection: read write Mapped to pid: own pid
|
success or wait |
530207891 |
Message posted |
HWND: 10084 Message: 40B WParam: 0 LParam: 2356 |
success |
530209377 |
Process information queried |
Path: unknown PID: 1552 Info Class: BasicInformation |
success or wait |
530209521 |
Process terminated |
PID: 1696 Path: C:\WINDOWS\explorer.exe |
success or wait |
530212507 |
Memory allocated |
PID: 1696 Path: C:\WINDOWS\explorer.exe Base: A6000 Length: 7FAAC Allocation Type:
unknown Protection: page read and write
|
success or wait |
530213681 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: Cookie |
success or wait |
530214266 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: Cookie |
success or wait |
530214412 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: Cookie |
success or wait |
530218907 |
Process information queried |
Path: C:\WINDOWS\explorer.exe PID: 1696 Info Class: Cookie |
success or wait |
530219032 |
Key value queried |
Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
Name: DisableMetaFiles
|
object name not found |
530219259 |