VMRay Analyzer Report
Monitored Processes
Process Graph
Behavior Information - Grouped by Category
Process #1: cb91b8695d3990b5b5eae8a714bd357e.exe
(Host: 408, Network: 0)
+
InformationValue
ID / OS PID#1 / 0x7a8
OS Parent PID0x358 (c:\windows\explorer.exe)
Initial Working DirectoryC:\Users\uWZPA0LPqa\Desktop
File Namec:\users\uwzpa0lpqa\desktop\cb91b8695d3990b5b5eae8a714bd357e.exe
Command Line"C:\Users\uWZPA0LPqa\Desktop\cb91b8695d3990b5b5eae8a714bd357e.exe"
MonitorStart Time: 00:00:38, Reason: Analysis Target
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:01:29
OS Thread IDs
#1
0xA98
#2
0x5FC
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x00000000000100000x000100000x0002ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000000000100000x000100000x0001ffffPagefile Backed FileReadable, WritableTrue
private_0x00000000000200000x000200000x00023fffPrivate MemoryReadable, WritableTrue
private_0x00000000000300000x000300000x00030fffPrivate MemoryReadable, WritableTrue
private_0x00000000000300000x000300000x00030fffPrivate MemoryReadable, WritableTrue
pagefile_0x00000000000400000x000400000x0004efffPagefile Backed FileReadableTrue
private_0x00000000000500000x000500000x0008ffffPrivate MemoryReadable, WritableTrue
private_0x00000000000900000x000900000x0018ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000000001900000x001900000x00193fffPagefile Backed FileReadableTrue
private_0x00000000001a00000x001a00000x001a1fffPrivate MemoryReadable, WritableTrue
private_0x00000000001b00000x001b00000x001b0fffPrivate MemoryReadable, WritableTrue
private_0x00000000001d00000x001d00000x001dffffPrivate MemoryReadable, WritableTrue
private_0x00000000001e00000x001e00000x001effffPrivate MemoryReadable, WritableTrue
locale.nls0x001f00000x0026dfffMemory Mapped FileReadableFalse
private_0x00000000002700000x002700000x002d3fffPrivate MemoryReadableTrue
private_0x00000000002e00000x002e00000x003dffffPrivate MemoryReadable, WritableTrue
cb91b8695d3990b5b5eae8a714bd357e.exe0x004000000x00463fffMemory Mapped FileReadable, Writable, ExecutableTrue
private_0x00000000004700000x004700000x00495fffPrivate MemoryReadable, WritableTrue
private_0x00000000005200000x005200000x0052ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000000005300000x005300000x006b7fffPagefile Backed FileReadableTrue
pagefile_0x00000000006c00000x006c00000x00840fffPagefile Backed FileReadableTrue
pagefile_0x00000000008500000x008500000x01c4ffffPagefile Backed FileReadableTrue
SortDefault.nls0x01c500000x01f24fffMemory Mapped FileReadableFalse
winspool.drv0x74ab00000x74b14fffMemory Mapped FileReadable, Writable, ExecutableFalse
profapi.dll0x74b200000x74b2efffMemory Mapped FileReadable, Writable, ExecutableFalse
userenv.dll0x74b300000x74b4afffMemory Mapped FileReadable, Writable, ExecutableFalse
iertutil.dll0x74b500000x74d81fffMemory Mapped FileReadable, Writable, ExecutableFalse
wininet.dll0x74d900000x74f65fffMemory Mapped FileReadable, Writable, ExecutableFalse
comctl32.dll0x74f700000x74ff8fffMemory Mapped FileReadable, Writable, ExecutableFalse
apphelp.dll0x750000000x7509ffffMemory Mapped FileReadable, Writable, ExecutableFalse
bcryptprimitives.dll0x750a00000x750f3fffMemory Mapped FileReadable, Writable, ExecutableFalse
cryptbase.dll0x751000000x75109fffMemory Mapped FileReadable, Writable, ExecutableFalse
sspicli.dll0x751100000x7512dfffMemory Mapped FileReadable, Writable, ExecutableFalse
KernelBase.dll0x751900000x75266fffMemory Mapped FileReadable, Writable, ExecutableFalse
imagehlp.dll0x752700000x75283fffMemory Mapped FileReadable, Writable, ExecutableFalse
gdi32.dll0x753200000x7542dfffMemory Mapped FileReadable, Writable, ExecutableFalse
advapi32.dll0x754300000x754abfffMemory Mapped FileReadable, Writable, ExecutableFalse
shlwapi.dll0x755000000x75544fffMemory Mapped FileReadable, Writable, ExecutableFalse
psapi.dll0x755500000x75555fffMemory Mapped FileReadable, Writable, ExecutableFalse
rpcrt4.dll0x756200000x756d9fffMemory Mapped FileReadable, Writable, ExecutableFalse
sechost.dll0x757900000x757d0fffMemory Mapped FileReadable, Writable, ExecutableFalse
combase.dll0x757e00000x7595cfffMemory Mapped FileReadable, Writable, ExecutableFalse
kernel32.dll0x759600000x75a9ffffMemory Mapped FileReadable, Writable, ExecutableFalse
ole32.dll0x75aa00000x75bc7fffMemory Mapped FileReadable, Writable, ExecutableFalse
shell32.dll0x75c600000x76f0cfffMemory Mapped FileReadable, Writable, ExecutableFalse
msvcrt.dll0x772400000x77302fffMemory Mapped FileReadable, Writable, ExecutableFalse
msctf.dll0x773500000x77462fffMemory Mapped FileReadable, Writable, ExecutableFalse
user32.dll0x776a00000x777f2fffMemory Mapped FileReadable, Writable, ExecutableFalse
imm32.dll0x778000000x77826fffMemory Mapped FileReadable, Writable, ExecutableFalse
wow64.dll0x778400000x7788afffMemory Mapped FileReadable, Writable, ExecutableFalse
wow64win.dll0x778900000x778f7fffMemory Mapped FileReadable, Writable, ExecutableFalse
wow64cpu.dll0x779000000x77908fffMemory Mapped FileReadable, Writable, ExecutableFalse
ntdll.dll0x779100000x77a7dfffMemory Mapped FileReadable, Writable, ExecutableFalse
pagefile_0x000000007feb00000x7feb00000x7ffaffffPagefile Backed FileReadableTrue
pagefile_0x000000007ffb00000x7ffb00000x7ffd2fffPagefile Backed FileReadableTrue
private_0x000000007ffdb0000x7ffdb0000x7ffddfffPrivate MemoryReadable, WritableTrue
private_0x000000007ffde0000x7ffde0000x7ffdefffPrivate MemoryReadable, WritableTrue
private_0x000000007ffdf0000x7ffdf0000x7ffdffffPrivate MemoryReadable, WritableTrue
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x000000007fff00000x7fff00000x7ff80c08ffffPrivate MemoryReadableTrue
ntdll.dll0x7ff80c0900000x7ff80c23bfffMemory Mapped FileReadable, Writable, ExecutableFalse
private_0x00007ff80c23c0000x7ff80c23c0000x7ffffffeffffPrivate MemoryReadableTrue
Created or Modified Files
+
FilenameFile SizeHash Values
c:\users\uwzpa0~1\appdata\local\temp\3e0d.tmp 225.50 KB (230912 bytes)MD5: cb91b8695d3990b5b5eae8a714bd357e
SHA1: 3cd6ef10dd6cbe6f158a360cf5b112cef2e18304
SHA256: eec6bfe112155ab94029f0f8f27a484edf35b5d743503e0199637084d9520ebc
Host Behavior
File (6)
+
OperationFilenameAdditional InformationSuccessAmountLogfile
CREATE_TMPFILEc:\users\uwzpa0~1\appdata\local\temp\ff1e.tmppath = C:\Users\UWZPA0~1\AppData\Local\Temp\True1
Fn
CREATE_TMPFILEc:\users\uwzpa0~1\appdata\local\temp\3e0d.tmppath = C:\Users\UWZPA0~1\AppData\Local\Temp\True1
Fn
OPENc:desired_access = SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERTTrue1
Fn
OPEN\device\harddisk0\dr0desired_access = SYNCHRONIZE, GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERTTrue1
Fn
MOVEc:\users\uwzpa0~1\appdata\local\temp\3e0d.tmpfile_name = c:\users\uwzpa0lpqa\desktop\cb91b8695d3990b5b5eae8a714bd357e.exeTrue1
Fn
MOVEc:\users\uwzpa0~1\appdata\local\temp\3e0d.tmpTrue1
Fn
Module (134)
+
OperationModuleAdditional InformationSuccessAmountLogfile
LOADimagehlp.dllbase_address = 0x75270000True1
Fn
LOADPSAPI.DLLbase_address = 0x75550000True1
Fn
LOADWININET.dllbase_address = 0x74d90000True1
Fn
LOADSHELL32.dllbase_address = 0x75c60000True1
Fn
LOADole32.dllbase_address = 0x75aa0000True1
Fn
LOADWINSPOOL.DRVbase_address = 0x74ab0000True1
Fn
GET_HANDLEKERNEL32.dllTrue1
Fn
GET_HANDLEADVAPI32.dllTrue1
Fn
GET_HANDLEntdll.dllTrue2
Fn
GET_HANDLESHLWAPI.dllTrue1
Fn
GET_HANDLEimagehlp.dllFalse1
Fn
GET_HANDLEPSAPI.DLLFalse1
Fn
GET_HANDLERPCRT4.dllTrue1
Fn
GET_HANDLEWININET.dllFalse1
Fn
GET_HANDLESHELL32.dllFalse1
Fn
GET_HANDLEole32.dllFalse1
Fn
GET_HANDLEWINSPOOL.DRVFalse1
Fn
GET_HANDLEc:\users\uwzpa0lpqa\desktop\cb91b8695d3990b5b5eae8a714bd357e.exeTrue1
Fn
GET_HANDLEkernel32.dllTrue1
Fn
GET_PROC_ADDRESSfunction = StrCmpNIA, address_out = 0x7551b430True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = GetTempPathA, address_out = 0x75985890True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = GetProcAddress, address_out = 0x75977b50True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = GetModuleHandleA, address_out = 0x75978f60True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = CopyFileA, address_out = 0x7597fe50True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = LoadLibraryExA, address_out = 0x7597a970True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = FreeLibrary, address_out = 0x7597a790True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = DeleteFileA, address_out = 0x75988950True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = GetPrivateProfileIntA, address_out = 0x7597ca90True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = GetPrivateProfileStringA, address_out = 0x7597cb60True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = WritePrivateProfileStringA, address_out = 0x7597c590True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = CreateFileA, address_out = 0x75988920True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = WriteFile, address_out = 0x75988cf0True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = CloseHandle, address_out = 0x759886f0True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = GetTempFileNameA, address_out = 0x759a3bf0True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = GetSystemTime, address_out = 0x75979200True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = GetFileAttributesA, address_out = 0x75988aa0True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = DeviceIoControl, address_out = 0x75978a50True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = SystemTimeToFileTime, address_out = 0x7597a950True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = GetCurrentProcessId, address_out = 0x759722d0True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = FreeLibraryAndExitThread, address_out = 0x75985c10True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = GetCurrentProcess, address_out = 0x759728e0True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = CreateFileW, address_out = 0x75988930True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = GetFileSize, address_out = 0x75988af0True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = ReadFile, address_out = 0x75988c00True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = SetFilePointer, address_out = 0x75988c90True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = SetEndOfFile, address_out = 0x75988c50True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = GetModuleHandleW, address_out = 0x7597a0c0True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = CopyFileW, address_out = 0x75986770True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = CreateFileMappingA, address_out = 0x759770f0True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = MapViewOfFile, address_out = 0x75978b50True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = UnmapViewOfFile, address_out = 0x7597a100True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = Sleep, address_out = 0x759782d0True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = DeleteFileW, address_out = 0x75988960True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = ExitProcess, address_out = 0x75989850True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = GetCommandLineA, address_out = 0x7597b5a0True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = CreateThread, address_out = 0x7597a740True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = GetSystemTimeAsFileTime, address_out = 0x759770c0True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = VirtualProtect, address_out = 0x75978ab0True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = VirtualFree, address_out = 0x75978f20True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = GetLastError, address_out = 0x759726e0True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = GetVersionExA, address_out = 0x75978b10True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = MoveFileExW, address_out = 0x7597b950True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = GetTempFileNameW, address_out = 0x75988b80True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = GetTempPathW, address_out = 0x75988b90True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = GetModuleFileNameW, address_out = 0x7597a0e0True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = GetWindowsDirectoryW, address_out = 0x7597b6c0True1
Fn
GET_PROC_ADDRESSKERNEL32.dllfunction = VirtualAlloc, address_out = 0x75978b90True1
Fn
GET_PROC_ADDRESSADVAPI32.dllfunction = QueryServiceStatusEx, address_out = 0x7545ce30True1
Fn
GET_PROC_ADDRESSADVAPI32.dllfunction = StartServiceA, address_out = 0x754746d0True1
Fn
GET_PROC_ADDRESSADVAPI32.dllfunction = OpenSCManagerA, address_out = 0x75439510True1
Fn
GET_PROC_ADDRESSADVAPI32.dllfunction = OpenServiceA, address_out = 0x75474320True1
Fn
GET_PROC_ADDRESSADVAPI32.dllfunction = GetUserNameW, address_out = 0x75447190True1
Fn
GET_PROC_ADDRESSADVAPI32.dllfunction = OpenProcessToken, address_out = 0x75439290True1
Fn
GET_PROC_ADDRESSADVAPI32.dllfunction = RegCloseKey, address_out = 0x75439330True1
Fn
GET_PROC_ADDRESSADVAPI32.dllfunction = RegSetValueExA, address_out = 0x75446fb0True1
Fn
GET_PROC_ADDRESSADVAPI32.dllfunction = RegCreateKeyA, address_out = 0x7545c620True1
Fn
GET_PROC_ADDRESSADVAPI32.dllfunction = CloseServiceHandle, address_out = 0x754394f0True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = RtlComputeCrc32, address_out = 0x779e7db0True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = LdrAddRefDll, address_out = 0x77973f70True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = ZwImpersonateThread, address_out = 0x7794d7e0True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = ZwOpenThread, address_out = 0x7794da70True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = RtlEqualUnicodeString, address_out = 0x7795a050True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = ZwQueryInformationToken, address_out = 0x7794cb40True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = wcsncpy, address_out = 0x779ad5b0True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = ZwOpenFile, address_out = 0x7794cc60True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = ZwClose, address_out = 0x7794ca20True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = ZwLoadDriver, address_out = 0x7794d850True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = strncat, address_out = 0x77938c30True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = ZwCreateEvent, address_out = 0x7794cdb0True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = RtlInitUnicodeString, address_out = 0x77937520True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = _snwprintf, address_out = 0x779ac100True2
Fn
GET_PROC_ADDRESSntdll.dllfunction = atoi, address_out = 0x779abbf0True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = ZwTestAlert, address_out = 0x7794e2f0True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = RtlRandom, address_out = 0x779f2780True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = ZwRaiseHardError, address_out = 0x7794ddb0True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = RtlAdjustPrivilege, address_out = 0x779ab650True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = ZwQuerySystemInformation, address_out = 0x7794cc90True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = sscanf, address_out = 0x779acff0True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = strncpy, address_out = 0x77938d70True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = _chkstk, address_out = 0x77951140True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = memcpy, address_out = 0x779382c0True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = _snprintf, address_out = 0x779ac050True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = RtlImageNtHeader, address_out = 0x77964af0True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = ZwDeviceIoControlFile, address_out = 0x7794c9a0True1
Fn
GET_PROC_ADDRESSntdll.dllfunction = memset, address_out = 0x77938940True1
Fn
GET_PROC_ADDRESSSHLWAPI.dllfunction = StrStrIW, address_out = 0x75508bc0True1
Fn
GET_PROC_ADDRESSSHLWAPI.dllfunction = SHDeleteKeyA, address_out = 0x7551ba40True1
Fn
GET_PROC_ADDRESSSHLWAPI.dllfunction = PathFileExistsW, address_out = 0x75508fc0True1
Fn
GET_PROC_ADDRESSSHLWAPI.dllfunction = StrStrIA, address_out = 0x7550f9c0True1
Fn
GET_PROC_ADDRESSSHLWAPI.dllfunction = PathFileExistsA, address_out = 0x7551ab40True1
Fn
GET_PROC_ADDRESSSHLWAPI.dllfunction = PathAppendA, address_out = 0x7551aa60True1
Fn
GET_PROC_ADDRESSSHLWAPI.dllfunction = PathFindFileNameW, address_out = 0x75508ba0True1
Fn
GET_PROC_ADDRESSSHLWAPI.dllfunction = SHGetValueA, address_out = 0x7550f890True1
Fn
GET_PROC_ADDRESSSHLWAPI.dllfunction = PathRemoveFileSpecA, address_out = 0x7551aee0True1
Fn
GET_PROC_ADDRESSimagehlp.dllfunction = CheckSumMappedFile, address_out = 0x75277d30True1
Fn
GET_PROC_ADDRESSPSAPI.DLLfunction = GetMappedFileNameW, address_out = 0x75551720True1
Fn
GET_PROC_ADDRESSRPCRT4.dllfunction = UuidCreateSequential, address_out = 0x7564bb50True1
Fn
GET_PROC_ADDRESSWININET.dllfunction = InternetCrackUrlA, address_out = 0x74e0fd30True1
Fn
GET_PROC_ADDRESSWININET.dllfunction = InternetConnectA, address_out = 0x74e3a3c0True1
Fn
GET_PROC_ADDRESSWININET.dllfunction = HttpOpenRequestA, address_out = 0x74e3a450True1
Fn
GET_PROC_ADDRESSWININET.dllfunction = HttpSendRequestA, address_out = 0x74e370c0True1
Fn
GET_PROC_ADDRESSWININET.dllfunction = InternetQueryOptionA, address_out = 0x74da1e40True1
Fn
GET_PROC_ADDRESSWININET.dllfunction = InternetSetOptionA, address_out = 0x74da4230True1
Fn
GET_PROC_ADDRESSWININET.dllfunction = InternetCloseHandle, address_out = 0x74db43c0True1
Fn
GET_PROC_ADDRESSWININET.dllfunction = InternetOpenA, address_out = 0x74dd34f0True1
Fn
GET_PROC_ADDRESSSHELL32.dllfunction = ShellExecuteW, address_out = 0x75d408f0True1
Fn
GET_PROC_ADDRESSole32.dllfunction = CoCreateInstance, address_out = 0x75800590True1
Fn
GET_PROC_ADDRESSole32.dllfunction = CoInitialize, address_out = 0x75aa9ec0True1
Fn
GET_PROC_ADDRESSole32.dllfunction = CoUninitialize, address_out = 0x757eb890True1
Fn
GET_PROC_ADDRESSWINSPOOL.DRVfunction = DeletePrintProvidorW, address_out = 0x74ad6410True1
Fn
GET_PROC_ADDRESSWINSPOOL.DRVfunction = AddPrintProvidorW, address_out = 0x74ad4aa0True1
Fn
GET_PROC_ADDRESSkernel32.dllfunction = IsWow64Process, address_out = 0x75978f40True1
Fn
Driver (267)
+
OperationDriverAdditional InformationSuccessAmountLogfile
CONTROLc:control_code = 0x560000True1
Fn
CONTROL\device\harddisk0\dr0control_code = 0x4d014True266
Fn
User (1)
+
OperationUser/Group/ServerAdditional InformationSuccessAmountLogfile
SET_PRIVILEGELocalhostprivilege = SeShutdownPrivilege, enable_privilege = 1True1
Fn
Process #2: System
+
InformationValue
ID / OS PID#2 / 0x4
OS Parent PID0xffffffffffffffff (Unknown)
Initial Working Directory
File NameSystem
Command Line
MonitorStart Time: 00:01:20, Reason: Kernel Analysis
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:47
OS Thread IDs
#3
0x8
#4
0x18
#5
0x14
#6
0x28
#7
0x38
#8
0x70
#9
0x74
#10
0x90
#11
0x94
#12
0x5C
#13
0x30
#14
0x9C
#15
0xAC
#16
0xB0
#17
0x88
#18
0x84
#19
0x80
#20
0x8C
#21
0xC8
#22
0x78
#23
0x7C
#24
0xE0
#26
0x4C
#28
0xFC
#29
0x100
#30
0x104
#31
0x108
#32
0x110
#33
0xF4
#34
0x10C
#35
0x58
#36
0x11C
#37
0x10
#38
0x34
#39
0x124
#42
0x13C
#43
0x144
#44
0x148
#57
0x20
#60
0x190
#61
0x140
#70
0xE8
#86
0x128
#89
0x1F0
#96
0x3C
#118
0x48
RemarksNo high level activity detected in monitored regions
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
pagefile_0x000000d9847a00000xd9847a00000xd9847c2fffPagefile Backed FileReadable, WritableTrue
Process #3: smss.exe
+
InformationValue
ID / OS PID#3 / 0xec
OS Parent PID0x4 (System)
Initial Working DirectoryX:\windows
File Namec:\windows\system32\smss.exe
Command Line\SystemRoot\System32\smss.exe
MonitorStart Time: 00:01:27, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:40
OS Thread IDs
#25
0xF0
#27
0xF8
#66
0x1A8
RemarksNo high level activity detected in monitored regions
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x00000075205b00000x75205b00000x75205cffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000075205d00000x75205d00000x75205defffPagefile Backed FileReadableTrue
private_0x00000075205e00000x75205e00000x752065ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007ff6fef700000x7ff6fef700000x7ff6fef92fffPagefile Backed FileReadableTrue
private_0x00007ff6fef9c0000x7ff6fef9c0000x7ff6fef9cfffPrivate MemoryReadable, WritableTrue
private_0x00007ff6fef9e0000x7ff6fef9e0000x7ff6fef9ffffPrivate MemoryReadable, WritableTrue
smss.exe0x7ff6ff8f00000x7ff6ff914fffMemory Mapped FileReadable, Writable, ExecutableFalse
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Process #4: smss.exe
+
InformationValue
ID / OS PID#4 / 0x12c
OS Parent PID0xec (c:\windows\system32\smss.exe)
Initial Working DirectoryX:\windows
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\smss.exe
Command Line\SystemRoot\System32\smss.exe 00000000 00000050
MonitorStart Time: 00:01:32, Reason: Child Process
UnmonitorEnd Time: 00:01:33, Reason: Terminated
Monitor Duration00:00:01
OS Thread IDs
#40
0x130
RemarksNo high level activity detected in monitored regions
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x000000af73b500000xaf73b500000xaf73b6ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000af73b700000xaf73b700000xaf73b7efffPagefile Backed FileReadableTrue
private_0x000000af73b800000xaf73b800000xaf73bfffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007ff6fef000000x7ff6fef000000x7ff6fef22fffPagefile Backed FileReadableTrue
private_0x00007ff6fef2c0000x7ff6fef2c0000x7ff6fef2dfffPrivate MemoryReadable, WritableTrue
private_0x00007ff6fef2e0000x7ff6fef2e0000x7ff6fef2efffPrivate MemoryReadable, WritableTrue
smss.exe0x7ff6ff8f00000x7ff6ff914fffMemory Mapped FileReadable, Writable, ExecutableFalse
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Process #5: csrss.exe
(Host: 258, Network: 0)
+
InformationValue
ID / OS PID#5 / 0x134
OS Parent PID0x12c (\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\smss.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe
Command Line%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
MonitorStart Time: 00:01:32, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:35
OS Thread IDs
#41
0x138
#45
0x14C
#46
0x150
#47
0x154
#48
0x158
#58
0x188
#63
0x1A0
#64
0x1A4
#87
0x200
#128
0x2BC
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x00000045829600000x45829600000x458297ffffPrivate MemoryReadable, WritableTrue
private_0x00000045829600000x45829600000x4582966fffPrivate MemoryReadable, WritableTrue
csrss.exe.mui0x45829700000x4582970fffMemory Mapped FileReadableFalse
pagefile_0x00000045829800000x45829800000x458298efffPagefile Backed FileReadableTrue
private_0x00000045829900000x45829900000x45829cffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000045829900000x45829900000x458299ffffPagefile Backed FileReadable, WritableTrue
MARLETT.TTF0x45829a00000x45829a6fffMemory Mapped FileReadableFalse
pagefile_0x00000045829b00000x45829b00000x45829c7fffPagefile Backed FileReadableTrue
locale.nls0x45829d00000x4582a4dfffMemory Mapped FileReadableFalse
winsrv.DLL.mui0x4582a500000x4582a51fffMemory Mapped FileReadableFalse
private_0x0000004582a600000x4582a600000x4582a60fffPrivate MemoryReadable, WritableTrue
VGASYS.FON0x4582a700000x4582a71fffMemory Mapped FileReadableFalse
private_0x0000004582a800000x4582a800000x4582abffffPrivate MemoryReadable, WritableTrue
private_0x0000004582ac00000x4582ac00000x4582ac0fffPrivate MemoryReadable, WritableTrue
private_0x0000004582ad00000x4582ad00000x4582ad0fffPrivate MemoryReadable, WritableTrue
private_0x0000004582ae00000x4582ae00000x4582ae0fffPrivate MemoryReadable, WritableTrue
private_0x0000004582af00000x4582af00000x4582beffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000004582bf00000x4582bf00000x4582d70fffPagefile Backed FileReadableTrue
private_0x0000004582d800000x4582d800000x4582dbffffPrivate MemoryReadable, WritableTrue
private_0x0000004582dc00000x4582dc00000x4582dfffffPrivate MemoryReadable, WritableTrue
private_0x0000004582e000000x4582e000000x4582e3ffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000004582e400000x4582e400000x4582fc7fffPagefile Backed FileReadableTrue
private_0x0000004582fd00000x4582fd00000x458300ffffPrivate MemoryReadable, WritableTrue
private_0x00000045830100000x45830100000x458304ffffPrivate MemoryReadable, WritableTrue
private_0x00000045830500000x45830500000x458308ffffPrivate MemoryReadable, WritableTrue
TAHOMABD.TTF0x45830900000x4583139fffMemory Mapped FileReadableFalse
TAHOMA.TTF0x45831400000x45831f6fffMemory Mapped FileReadableFalse
pagefile_0x00000045832000000x45832000000x458322ffffPagefile Backed FileReadableTrue
pagefile_0x00000045832300000x45832300000x458462ffffPagefile Backed FileReadableTrue
pagefile_0x00000045846300000x45846300000x458463ffffPagefile Backed FileReadable, WritableTrue
pagefile_0x00000045846400000x45846400000x458464ffffPagefile Backed FileReadable, WritableTrue
private_0x00000045846500000x45846500000x458468ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000045846900000x45846900000x458469ffffPagefile Backed FileReadable, WritableTrue
pagefile_0x00000045846a00000x45846a00000x45846affffPagefile Backed FileReadable, WritableTrue
private_0x00007ff61939c0000x7ff61939c0000x7ff61939dfffPrivate MemoryReadable, WritableTrue
private_0x00007ff61939e0000x7ff61939e0000x7ff61939ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007ff6193a00000x7ff6193a00000x7ff61949ffffPagefile Backed FileReadable, WritableTrue
pagefile_0x00007ff6194a00000x7ff6194a00000x7ff6194c2fffPagefile Backed FileReadableTrue
private_0x00007ff6194c30000x7ff6194c30000x7ff6194c4fffPrivate MemoryReadable, WritableTrue
private_0x00007ff6194c50000x7ff6194c50000x7ff6194c6fffPrivate MemoryReadable, WritableTrue
private_0x00007ff6194c70000x7ff6194c70000x7ff6194c8fffPrivate MemoryReadable, WritableTrue
private_0x00007ff6194c90000x7ff6194c90000x7ff6194cafffPrivate MemoryReadable, WritableTrue
private_0x00007ff6194cb0000x7ff6194cb0000x7ff6194ccfffPrivate MemoryReadable, WritableTrue
private_0x00007ff6194cd0000x7ff6194cd0000x7ff6194cefffPrivate MemoryReadable, WritableTrue
private_0x00007ff6194cd0000x7ff6194cd0000x7ff6194cefffPrivate MemoryReadable, WritableTrue
private_0x00007ff6194cf0000x7ff6194cf0000x7ff6194cffffPrivate MemoryReadable, WritableTrue
csrss.exe0x7ff61a1000000x7ff61a106fffMemory Mapped FileReadable, Writable, ExecutableFalse
bcryptPrimitives.dll0x7ffb715800000x7ffb715e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTBASE.dll0x7ffb715f00000x7ffb715fafffMemory Mapped FileReadable, Writable, ExecutableFalse
sxs.dll0x7ffb716000000x7ffb71698fffMemory Mapped FileReadable, Writable, ExecutableFalse
sxssrv.DLL0x7ffb716d00000x7ffb716dcfffMemory Mapped FileReadable, Writable, ExecutableFalse
winsrv.DLL0x7ffb716e00000x7ffb71713fffMemory Mapped FileReadable, Writable, ExecutableFalse
basesrv.DLL0x7ffb717200000x7ffb71732fffMemory Mapped FileReadable, Writable, ExecutableFalse
CSRSRV.dll0x7ffb717400000x7ffb71755fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
gdi32.dll0x7ffb71ad00000x7ffb71c20fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
user32.dll0x7ffb73e900000x7ffb74006fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Host Behavior
File (57)
+
OperationFilenameAdditional InformationSuccessAmountLogfile
CREATETrue11
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.systemcompatible_6595b64144ccf1df_6.0.9600.16384_none_69e3a25fa94e130a.manifestdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.isolationautomation_6595b64144ccf1df_1.0.0.0_none_ee2620cf57bc84de.manifestdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.17415_none_932b3b5547500489.manifestdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52.manifestdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_1.0.9600.17415_none_bd4349237a1100f7.manifestdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.9600.16384_en-us_4ab3da74c23648d7.manifestdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
READTrue18
Fn
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.systemcompatible_6595b64144ccf1df_6.0.9600.16384_none_69e3a25fa94e130a.manifestsize = 4095True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.systemcompatible_6595b64144ccf1df_6.0.9600.16384_none_69e3a25fa94e130a.manifestsize = 8180False1
Fn
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.isolationautomation_6595b64144ccf1df_1.0.0.0_none_ee2620cf57bc84de.manifestsize = 2True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.isolationautomation_6595b64144ccf1df_1.0.0.0_none_ee2620cf57bc84de.manifestsize = 4095True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.isolationautomation_6595b64144ccf1df_1.0.0.0_none_ee2620cf57bc84de.manifestsize = 8180False1
Fn
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.17415_none_932b3b5547500489.manifestsize = 2True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.17415_none_932b3b5547500489.manifestsize = 4095True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.17415_none_932b3b5547500489.manifestsize = 8180False1
Fn
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52.manifestsize = 2True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52.manifestsize = 4095True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52.manifestsize = 8180False1
Fn
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_1.0.9600.17415_none_bd4349237a1100f7.manifestsize = 2True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_1.0.9600.17415_none_bd4349237a1100f7.manifestsize = 4095True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_1.0.9600.17415_none_bd4349237a1100f7.manifestsize = 8180False1
Fn
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.9600.16384_en-us_4ab3da74c23648d7.manifestsize = 2True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.9600.16384_en-us_4ab3da74c23648d7.manifestsize = 4095True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.9600.16384_en-us_4ab3da74c23648d7.manifestsize = 8180False1
Fn
Process (17)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True7
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True10
Fn
Module (26)
+
OperationModuleAdditional InformationSuccessAmountLogfile
GET_HANDLEcsrsrv.dllTrue1
Fn
CREATE_MAPPINGNameless FileMappingTrue5
Fn
CREATE_MAPPINGNameless FileMappingmaximum_size = 298550618448, protection = PAGE_READWRITETrue1
Fn
CREATE_MAPPINGNameless FileMappingmaximum_size = 298550618992, protection = PAGE_READWRITETrue1
Fn
CREATE_MAPPINGNameless FileMappingmaximum_size = 298548457472, protection = PAGE_READWRITETrue2
Fn
CREATE_MAPPINGNameless FileMappingmaximum_size = 298548458592, protection = PAGE_READWRITETrue1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, address = 0x4584630000True3
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x4584630000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x4584630000True2
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, address = 0x4584690000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x4584690000True1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, address = 0x45846b0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x45846b0000True1
Fn
UNMAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True5
Fn
Registry (131)
+
OperationKeyAdditional InformationSuccessAmountLogfile
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Terminal ServerTrue1
Fn
OPEN_KEY\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_InitializeTrue1
Fn
OPEN_KEYTrue66
Fn
OPEN_KEYFalse48
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Terminal Servervalue_name = TSAppCompatFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Terminal Servervalue_name = TSUserEnabledFalse1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initializevalue_name = DisableMetaFilesFalse1
Fn
READ_VALUETrue6
Fn
READ_VALUEvalue_name = 298550616872True1
Fn
READ_VALUEvalue_name = 298550613992True5
Fn
Driver (2)
+
OperationDriverAdditional InformationSuccessAmountLogfile
CONTROLTrue1
Fn
CONTROLcontrol_code = 0x390008True1
Fn
System (24)
+
OperationInformationSuccessAmountLogfile
GET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
GET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue13
Fn
GET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue10
Fn
Mutex (1)
+
OperationNameAdditional InformationSuccessAmountLogfile
CREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
Process #6: smss.exe
+
InformationValue
ID / OS PID#6 / 0x15c
OS Parent PID0xec (c:\windows\system32\smss.exe)
Initial Working DirectoryX:\windows
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\smss.exe
Command Line\SystemRoot\System32\smss.exe 00000001 00000050
MonitorStart Time: 00:01:33, Reason: Child Process
UnmonitorEnd Time: 00:01:34, Reason: Terminated
Monitor Duration00:00:01
OS Thread IDs
#49
0x160
RemarksNo high level activity detected in monitored regions
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x000000ae85eb00000xae85eb00000xae85ecffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000ae85ed00000xae85ed00000xae85edefffPagefile Backed FileReadableTrue
private_0x000000ae85ee00000xae85ee00000xae85f5ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007ff6ff7900000x7ff6ff7900000x7ff6ff7b2fffPagefile Backed FileReadableTrue
private_0x00007ff6ff7bd0000x7ff6ff7bd0000x7ff6ff7bdfffPrivate MemoryReadable, WritableTrue
private_0x00007ff6ff7be0000x7ff6ff7be0000x7ff6ff7bffffPrivate MemoryReadable, WritableTrue
smss.exe0x7ff6ff8f00000x7ff6ff914fffMemory Mapped FileReadable, Writable, ExecutableFalse
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Process #7: wininit.exe
(Host: 447, Network: 0)
+
InformationValue
ID / OS PID#7 / 0x164
OS Parent PID0x12c (\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\smss.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wininit.exe
Command Linewininit.exe
MonitorStart Time: 00:01:33, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:34
OS Thread IDs
#50
0x168
#59
0x18C
#62
0x19C
#65
0x1BC
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x0000005ebd1400000x5ebd1400000x5ebd15ffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000005ebd1400000x5ebd1400000x5ebd14ffffPagefile Backed FileReadable, WritableTrue
private_0x0000005ebd1500000x5ebd1500000x5ebd156fffPrivate MemoryReadable, WritableTrue
pagefile_0x0000005ebd1600000x5ebd1600000x5ebd16efffPagefile Backed FileReadableTrue
private_0x0000005ebd1700000x5ebd1700000x5ebd1effffPrivate MemoryReadable, WritableTrue
private_0x0000005ebd1f00000x5ebd1f00000x5ebd1f6fffPrivate MemoryReadable, WritableTrue
wininit.exe.mui0x5ebd2000000x5ebd201fffMemory Mapped FileReadableFalse
USER32.dll.mui0x5ebd2000000x5ebd204fffMemory Mapped FileReadableFalse
private_0x0000005ebd2100000x5ebd2100000x5ebd210fffPrivate MemoryReadable, WritableTrue
private_0x0000005ebd2200000x5ebd2200000x5ebd220fffPrivate MemoryReadable, WritableTrue
USER32.dll.mui0x5ebd2400000x5ebd244fffMemory Mapped FileReadableFalse
private_0x0000005ebd2600000x5ebd2600000x5ebd35ffffPrivate MemoryReadable, WritableTrue
locale.nls0x5ebd3600000x5ebd3ddfffMemory Mapped FileReadableFalse
private_0x0000005ebd3e00000x5ebd3e00000x5ebd45ffffPrivate MemoryReadable, WritableTrue
private_0x0000005ebd4600000x5ebd4600000x5ebd4dffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000005ebd4e00000x5ebd4e00000x5ebd50ffffPagefile Backed FileReadableTrue
private_0x0000005ebd5100000x5ebd5100000x5ebd51ffffPrivate MemoryReadable, WritableTrue
private_0x0000005ebd5600000x5ebd5600000x5ebd56ffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000005ebd5700000x5ebd5700000x5ebd6f7fffPagefile Backed FileReadableTrue
pagefile_0x0000005ebd7000000x5ebd7000000x5ebd880fffPagefile Backed FileReadableTrue
sortdefault.nls0x5ebd8900000x5ebdb64fffMemory Mapped FileReadableFalse
private_0x0000005ebdb700000x5ebdb700000x5ebdbeffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007df5ffd900000x7df5ffd900000x7ff5ffd8ffffPagefile Backed File-True
pagefile_0x00007df5ffd900000x7df5ffd900000x7ff5ffd8ffffPagefile Backed File-True
pagefile_0x00007ff73ef700000x7ff73ef700000x7ff73f06ffffPagefile Backed FileReadableTrue
pagefile_0x00007ff73f0700000x7ff73f0700000x7ff73f092fffPagefile Backed FileReadableTrue
private_0x00007ff73f0960000x7ff73f0960000x7ff73f097fffPrivate MemoryReadable, WritableTrue
private_0x00007ff73f0980000x7ff73f0980000x7ff73f099fffPrivate MemoryReadable, WritableTrue
private_0x00007ff73f09a0000x7ff73f09a0000x7ff73f09bfffPrivate MemoryReadable, WritableTrue
private_0x00007ff73f09c0000x7ff73f09c0000x7ff73f09dfffPrivate MemoryReadable, WritableTrue
private_0x00007ff73f09e0000x7ff73f09e0000x7ff73f09efffPrivate MemoryReadable, WritableTrue
wininit.exe0x7ff73f3b00000x7ff73f3d7fffMemory Mapped FileReadable, Writable, ExecutableFalse
KBDUS.DLL0x7ffb716900000x7ffb71693fffMemory Mapped FileReadable, Writable, ExecutableFalse
KBDUS.DLL0x7ffb716900000x7ffb71693fffMemory Mapped FileReadable, Writable, ExecutableFalse
wininitext.dll0x7ffb716a00000x7ffb716aafffMemory Mapped FileReadable, Writable, ExecutableFalse
profapi.dll0x7ffb716b00000x7ffb716c4fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
gdi32.dll0x7ffb71ad00000x7ffb71c20fffMemory Mapped FileReadable, Writable, ExecutableTrue
WS2_32.dll0x7ffb733600000x7ffb733b9fffMemory Mapped FileReadable, Writable, ExecutableTrue
sechost.dll0x7ffb733c00000x7ffb73418fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
advapi32.dll0x7ffb736900000x7ffb73739fffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
NSI.dll0x7ffb73e800000x7ffb73e88fffMemory Mapped FileReadable, Writable, ExecutableTrue
user32.dll0x7ffb73e900000x7ffb74006fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSVCRT.dll0x7ffb740500000x7ffb740f9fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Host Behavior
File (9)
+
OperationFilenameAdditional InformationSuccessAmountLogfile
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\tempdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\kbdus.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nlsdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE_DIRFalse1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\segoeuib.ttfdesired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, open_options = FILE_SYNCHRONOUS_IO_NONALERTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\segoeui.ttfdesired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, open_options = FILE_SYNCHRONOUS_IO_NONALERTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\tahoma.ttfdesired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, open_options = FILE_SYNCHRONOUS_IO_NONALERTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\micross.ttfdesired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, open_options = FILE_SYNCHRONOUS_IO_NONALERTTrue1
Fn
Process (108)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
CREATETrue2
Fn
CREATEdesired_access = MAXIMUM_ALLOWED, creation_flags = CREATE_IDLE_PRIORITY_CLASS, CREATE_NEW_PROCESS_GROUPTrue1
Fn
CREATEdesired_access = MAXIMUM_ALLOWED, creation_flags = CREATE_NEW_PROCESS_GROUPTrue1
Fn
OPEN_TOKENTrue1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True3
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True86
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True5
Fn
GET_INFOTrue2
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True3
Fn
Memory (3)
+
OperationAddressAdditional InformationSuccessAmountLogfile
ALLOC0x5ebd1eeb78process_name = , size = 406899846360, allocation_type = MEM_COMMIT, protection = PAGE_READWRITETrue1
Fn
WRITE0x6b29b00000process_name = , size = 4704True1
Fn
Data
WRITE0x7ff676b272d8process_name = , size = 8True1
Fn
Data
Thread (4)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
CREATE_WORKITEMTrue2
Fn
RESUMETrue2
Fn
Module (19)
+
OperationModuleAdditional InformationSuccessAmountLogfile
LOADrpcrt4.dllbase_address = 0x0True1
Fn
LOADKBDUS.DLLbase_address = 0x0True2
Fn
LOADkernel32.dllbase_address = 0x0True1
Fn
GET_HANDLE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wininit.exeTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\segoeuib.ttf, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\segoeui.ttf, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\tahoma.ttf, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\micross.ttf, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x5ebd890000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x5ebd890000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x5ebd890000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x5ebd890000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x5ebd890000True1
Fn
UNMAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, base_address = 0x5ebd890000True4
Fn
Service (9)
+
OperationServiceAdditional InformationSuccessAmountLogfile
OPEN_MGRSERVICES_ACTIVE_DATABASEhost = LocalhostTrue3
Fn
OPENTrue3
Fn
GET_INFOtype = StatusTrue3
Fn
Registry (275)
+
OperationKeyAdditional InformationSuccessAmountLogfile
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\VersionsTrue1
Fn
OPEN_KEYFalse7
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameFalse4
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNameTrue4
Fn
OPEN_KEY\Registry\Machine\System\SetupTrue3
Fn
OPEN_KEYTrue18
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Error Message Instrument\False1
Fn
OPEN_KEY\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_InitializeTrue1
Fn
OPEN_KEYKeyboard Layout\PreloadTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Keyboard Layouts\00000409True2
Fn
OPEN_KEY\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRTrue1
Fn
OPEN_KEY\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR\Control Panel\InternationalTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocaleTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocaleTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\LocaleTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Locale\Alternate SortsTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Language GroupsTrue1
Fn
OPEN_KEYControl Panel\Input Method\Hot KeysTrue2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000010True2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000011True2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000012True2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000070True2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000071True2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000072True2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000104True2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000200True2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000201True2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000202True2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000203True2
Fn
OPEN_KEY\REGISTRY\USER\S-1-5-18True4
Fn
OPEN_KEY\REGISTRY\USER\S-1-5-18\Keyboard Layout\PreloadTrue3
Fn
OPEN_KEY\REGISTRY\USER\S-1-5-18\Keyboard Layout\Preload\Keyboard Layout\PreloadTrue1
Fn
OPEN_KEY\REGISTRY\USER\S-1-5-18\Keyboard Layout\SubstitutesTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\IdsTrue1
Fn
OPEN_KEY\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDllsFalse1
Fn
OPEN_KEY\Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySideTrue2
Fn
OPEN_KEY\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\OptionFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versionsvalue_name = 406899844400True1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNamevalue_name = ComputerNameTrue4
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = OOBEInProgressFalse1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = SystemSetupInProgressTrue1
Fn
READ_VALUEFalse11
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = NV HostnameFalse1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = NV DomainFalse1
Fn
READ_VALUETrue17
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = RespecializeTrue1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = SetupTypeTrue1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = DisableLockWorkstationFalse1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = ProfileImagePathTrue2
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = PublicTrue2
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = ProgramDataTrue2
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = MaxRpcSizeFalse1
Fn
READ_VALUEvalue_name = IdleTimerWindowFalse1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initializevalue_name = DisableMetaFilesFalse1
Fn
READ_VALUEvalue_name = LoadAppInit_DLLsTrue2
Fn
READ_VALUEvalue_name = RespecializeTrue1
Fn
READ_VALUEvalue_name = SetupTypeTrue1
Fn
READ_VALUEKeyboard Layout\Preloadvalue_name = 1True1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Keyboard Layouts\00000409value_name = Layout FileTrue2
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Keyboard Layouts\00000409value_name = AttributesFalse2
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRvalue_name = DisableTrue1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR\Control Panel\InternationalFalse1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR\Control Panel\InternationalTrue1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR\Control Panel\Internationalvalue_name = sCurrencyOverrideFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocalevalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocalevalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Localevalue_name = 00000409True1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Language Groupsvalue_name = 1True1
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000010value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000010value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000010value_name = Target IMETrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000011value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000011value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000011value_name = Target IMETrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000012value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000012value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000012value_name = Target IMETrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000070value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000070value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000070value_name = Target IMETrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000071value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000071value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000071value_name = Target IMETrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000072value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000072value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000072value_name = Target IMETrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000104value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000104value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000104value_name = Target IMETrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000200value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000200value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000200value_name = Target IMETrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000201value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000201value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000201value_name = Target IMETrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000202value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000202value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000202value_name = Target IMETrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000203value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000203value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000203value_name = Target IMETrue2
Fn
READ_VALUE\REGISTRY\USER\S-1-5-18\Keyboard Layout\Preloadvalue_name = 1False1
Fn
READ_VALUE\REGISTRY\USER\S-1-5-18\Keyboard Layout\Preloadvalue_name = 1True1
Fn
READ_VALUE\REGISTRY\USER\S-1-5-18\Keyboard Layout\Preloadvalue_name = 2False2
Fn
READ_VALUE\REGISTRY\USER\S-1-5-18\Keyboard Layout\Preload\Keyboard Layout\Preloadvalue_name = 1True1
Fn
READ_VALUE\REGISTRY\USER\S-1-5-18\Keyboard Layout\Substitutesvalue_name = 00000409False1
Fn
READ_VALUEvalue_name = SecureBootFalse1
Fn
READ_VALUE\REGISTRY\USER\S-1-5-18\Keyboard Layout\Preloadvalue_name = DisableShutdownNamedPipeFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versionsvalue_name = 000602xxTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Idsvalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Idsvalue_name = enFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNamevalue_name = ProgramFilesDirTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNamevalue_name = CommonFilesDirTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNamevalue_name = ProgramFilesDir (x86)True1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNamevalue_name = CommonFilesDir (x86)True1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNamevalue_name = ProgramW6432DirTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNamevalue_name = CommonW6432DirTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNamevalue_name = DontWatchSysProcsFalse1
Fn
READ_VALUE\Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySidevalue_name = PreferExternalManifestFalse2
Fn
READ_VALUEvalue_name = ShutdownEventPendingFalse1
Fn
READ_VALUEvalue_name = ShutdownStateSnapshotFalse1
Fn
READ_VALUEvalue_name = RunasPPLFalse1
Fn
READ_VALUEvalue_name = RunasPPLTestFalse1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = 140717948767312False1
Fn
READ_VALUEvalue_name = DisableRemoteShutdownRPCInterfaceFalse1
Fn
READ_VALUE\Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySidevalue_name = SQMServiceListTrue1
Fn
READ_VALUE\Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySidevalue_name = WinSock_Registry_VersionTrue2
Fn
READ_VALUEvalue_name = AppFullPathTrue2
Fn
READ_VALUEvalue_name = PermittedLspCategoriesTrue1
Fn
READ_VALUE\Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySidevalue_name = NameSpace_CalloutTrue2
Fn
READ_VALUEvalue_name = Serial_Access_NumTrue4
Fn
READ_VALUEvalue_name = Next_Catalog_Entry_IDTrue1
Fn
READ_VALUEvalue_name = Num_Catalog_Entries64True2
Fn
READ_VALUEvalue_name = LibraryPathTrue2
Fn
READ_VALUEvalue_name = DisplayStringTrue4
Fn
READ_VALUEvalue_name = ProviderIdTrue1
Fn
READ_VALUEvalue_name = AddressFamilyFalse1
Fn
READ_VALUEvalue_name = SupportedNameSpaceTrue1
Fn
READ_VALUEvalue_name = EnabledTrue1
Fn
READ_VALUEvalue_name = VersionTrue1
Fn
READ_VALUEvalue_name = StoresServiceClassInfoTrue1
Fn
READ_VALUEvalue_name = ProviderInfoTrue2
Fn
READ_VALUE\Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySidevalue_name = Ws2_32NumHandleBucketsFalse1
Fn
Driver (1)
+
OperationDriverAdditional InformationSuccessAmountLogfile
CONTROLControl Panel\Input Method\Hot Keyscontrol_code = 0x110008False1
Fn
System (19)
+
OperationInformationSuccessAmountLogfile
CREATE_DESKTOPTrue2
Fn
SWITCH_DESKTOPTrue1
Fn
SLEEPTrue3
Fn
SLEEPduration = 406902929056 milliseconds (406902929.056 seconds)False1
Fn
SLEEPduration = 406902403200 milliseconds (406902403.200 seconds)False1
Fn
SLEEPTrue1
Fn
SLEEPduration = 406902929136 milliseconds (406902929.136 seconds)True1
Fn
SLEEPduration = 406902929168 milliseconds (406902929.168 seconds)False1
Fn
GET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
GET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue5
Fn
GET_INFOTrue1
Fn
GET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
Process #8: csrss.exe
(Host: 590, Network: 0)
+
InformationValue
ID / OS PID#8 / 0x16c
OS Parent PID0x15c (c:\windows\winstore\wshost.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe
Command Line%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
MonitorStart Time: 00:01:33, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:34
OS Thread IDs
#51
0x170
#52
0x174
#53
0x178
#54
0x17C
#55
0x180
#56
0x184
#81
0x1E8
#84
0x1F8
#85
0x1FC
#88
0x204
#113
0x268
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x000000d9c9ed00000xd9c9ed00000xd9c9eeffffPrivate MemoryReadable, WritableTrue
private_0x000000d9c9ed00000xd9c9ed00000xd9c9ed6fffPrivate MemoryReadable, WritableTrue
csrss.exe.mui0xd9c9ee00000xd9c9ee0fffMemory Mapped FileReadableFalse
pagefile_0x000000d9c9ef00000xd9c9ef00000xd9c9efefffPagefile Backed FileReadableTrue
private_0x000000d9c9f000000xd9c9f000000xd9c9f3ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000d9c9f000000xd9c9f000000xd9c9f0ffffPagefile Backed FileReadable, WritableTrue
MARLETT.TTF0xd9c9f100000xd9c9f16fffMemory Mapped FileReadableFalse
pagefile_0x000000d9c9f200000xd9c9f200000xd9c9f37fffPagefile Backed FileReadableTrue
locale.nls0xd9c9f400000xd9c9fbdfffMemory Mapped FileReadableFalse
winsrv.DLL.mui0xd9c9fc00000xd9c9fc1fffMemory Mapped FileReadableFalse
private_0x000000d9c9fd00000xd9c9fd00000xd9c9fd0fffPrivate MemoryReadable, WritableTrue
private_0x000000d9c9fe00000xd9c9fe00000xd9c9fe0fffPrivate MemoryReadable, WritableTrue
private_0x000000d9c9ff00000xd9c9ff00000xd9c9ff0fffPrivate MemoryReadable, WritableTrue
private_0x000000d9ca0000000xd9ca0000000xd9ca000fffPrivate MemoryReadable, WritableTrue
VGASYS.FON0xd9ca0100000xd9ca011fffMemory Mapped FileReadableFalse
private_0x000000d9ca0200000xd9ca0200000xd9ca05ffffPrivate MemoryReadable, WritableTrue
private_0x000000d9ca0600000xd9ca0600000xd9ca060fffPrivate MemoryReadable, WritableTrue
private_0x000000d9ca0700000xd9ca0700000xd9ca070fffPrivate MemoryReadable, WritableTrue
private_0x000000d9ca0800000xd9ca0800000xd9ca080fffPrivate MemoryReadable, WritableTrue
private_0x000000d9ca0900000xd9ca0900000xd9ca18ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000d9ca1900000xd9ca1900000xd9ca310fffPagefile Backed FileReadableTrue
pagefile_0x000000d9ca3200000xd9ca3200000xd9ca61ffffPagefile Backed FileReadable, WritableTrue
private_0x000000d9ca6200000xd9ca6200000xd9ca65ffffPrivate MemoryReadable, WritableTrue
private_0x000000d9ca6600000xd9ca6600000xd9ca69ffffPrivate MemoryReadable, WritableTrue
private_0x000000d9ca6a00000xd9ca6a00000xd9ca6dffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000d9ca6e00000xd9ca6e00000xd9ca867fffPagefile Backed FileReadableTrue
private_0x000000d9ca8700000xd9ca8700000xd9ca8affffPrivate MemoryReadable, WritableTrue
private_0x000000d9ca8b00000xd9ca8b00000xd9ca8effffPrivate MemoryReadable, WritableTrue
private_0x000000d9ca8f00000xd9ca8f00000xd9ca92ffffPrivate MemoryReadable, WritableTrue
TAHOMABD.TTF0xd9ca9300000xd9ca9d9fffMemory Mapped FileReadableFalse
TAHOMA.TTF0xd9ca9e00000xd9caa96fffMemory Mapped FileReadableFalse
pagefile_0x000000d9caaa00000xd9caaa00000xd9caacffffPagefile Backed FileReadableTrue
pagefile_0x000000d9caad00000xd9caad00000xd9cbecffffPagefile Backed FileReadableTrue
private_0x000000d9cbed00000xd9cbed00000xd9cbf0ffffPrivate MemoryReadable, WritableTrue
private_0x000000d9cbf100000xd9cbf100000xd9cbf4ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000d9cbf500000xd9cbf500000xd9cbf5ffffPagefile Backed FileReadable, WritableTrue
private_0x00007ff6196e80000x7ff6196e80000x7ff6196e9fffPrivate MemoryReadable, WritableTrue
private_0x00007ff6196ea0000x7ff6196ea0000x7ff6196ebfffPrivate MemoryReadable, WritableTrue
private_0x00007ff6196ec0000x7ff6196ec0000x7ff6196edfffPrivate MemoryReadable, WritableTrue
private_0x00007ff6196ee0000x7ff6196ee0000x7ff6196effffPrivate MemoryReadable, WritableTrue
pagefile_0x00007ff6196f00000x7ff6196f00000x7ff6197effffPagefile Backed FileReadable, WritableTrue
pagefile_0x00007ff6197f00000x7ff6197f00000x7ff619812fffPagefile Backed FileReadableTrue
private_0x00007ff6198140000x7ff6198140000x7ff619815fffPrivate MemoryReadable, WritableTrue
private_0x00007ff6198160000x7ff6198160000x7ff619817fffPrivate MemoryReadable, WritableTrue
private_0x00007ff6198180000x7ff6198180000x7ff619819fffPrivate MemoryReadable, WritableTrue
private_0x00007ff61981a0000x7ff61981a0000x7ff61981afffPrivate MemoryReadable, WritableTrue
private_0x00007ff61981c0000x7ff61981c0000x7ff61981dfffPrivate MemoryReadable, WritableTrue
private_0x00007ff61981e0000x7ff61981e0000x7ff61981ffffPrivate MemoryReadable, WritableTrue
private_0x00007ff61981e0000x7ff61981e0000x7ff61981ffffPrivate MemoryReadable, WritableTrue
csrss.exe0x7ff61a1000000x7ff61a106fffMemory Mapped FileReadable, Writable, ExecutableFalse
bcryptPrimitives.dll0x7ffb715800000x7ffb715e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTBASE.dll0x7ffb715f00000x7ffb715fafffMemory Mapped FileReadable, Writable, ExecutableFalse
sxs.dll0x7ffb716000000x7ffb71698fffMemory Mapped FileReadable, Writable, ExecutableFalse
sxssrv.DLL0x7ffb716d00000x7ffb716dcfffMemory Mapped FileReadable, Writable, ExecutableFalse
winsrv.DLL0x7ffb716e00000x7ffb71713fffMemory Mapped FileReadable, Writable, ExecutableFalse
basesrv.DLL0x7ffb717200000x7ffb71732fffMemory Mapped FileReadable, Writable, ExecutableFalse
CSRSRV.dll0x7ffb717400000x7ffb71755fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
gdi32.dll0x7ffb71ad00000x7ffb71c20fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
user32.dll0x7ffb73e900000x7ffb74006fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Host Behavior
File (157)
+
OperationFilenameAdditional InformationSuccessAmountLogfile
CREATETrue32
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.systemcompatible_6595b64144ccf1df_6.0.9600.16384_none_69e3a25fa94e130a.manifestdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.isolationautomation_6595b64144ccf1df_1.0.0.0_none_ee2620cf57bc84de.manifestdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.17415_none_932b3b5547500489.manifestdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52.manifestdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_1.0.9600.17415_none_bd4349237a1100f7.manifestdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.9600.16384_en-us_4ab3da74c23648d7.manifestdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifestdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True10
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifestdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True10
Fn
READTrue47
Fn
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.systemcompatible_6595b64144ccf1df_6.0.9600.16384_none_69e3a25fa94e130a.manifestsize = 4095True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.systemcompatible_6595b64144ccf1df_6.0.9600.16384_none_69e3a25fa94e130a.manifestsize = 8180False1
Fn
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.isolationautomation_6595b64144ccf1df_1.0.0.0_none_ee2620cf57bc84de.manifestsize = 2True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.isolationautomation_6595b64144ccf1df_1.0.0.0_none_ee2620cf57bc84de.manifestsize = 4095True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.isolationautomation_6595b64144ccf1df_1.0.0.0_none_ee2620cf57bc84de.manifestsize = 8180False1
Fn
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.17415_none_932b3b5547500489.manifestsize = 2True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.17415_none_932b3b5547500489.manifestsize = 4095True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.17415_none_932b3b5547500489.manifestsize = 8180False1
Fn
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52.manifestsize = 2True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52.manifestsize = 4095True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52.manifestsize = 8180False1
Fn
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_1.0.9600.17415_none_bd4349237a1100f7.manifestsize = 2True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_1.0.9600.17415_none_bd4349237a1100f7.manifestsize = 4095True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_1.0.9600.17415_none_bd4349237a1100f7.manifestsize = 8180False1
Fn
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.9600.16384_en-us_4ab3da74c23648d7.manifestsize = 2True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.9600.16384_en-us_4ab3da74c23648d7.manifestsize = 4095True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.9600.16384_en-us_4ab3da74c23648d7.manifestsize = 8180False1
Fn
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifestsize = 2True5
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifestsize = 4095True5
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifestsize = 8180False5
Fn
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifestsize = 2True5
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifestsize = 4095True5
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifestsize = 8180False5
Fn
Process (28)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True7
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True21
Fn
Module (31)
+
OperationModuleAdditional InformationSuccessAmountLogfile
GET_HANDLEcsrsrv.dllTrue1
Fn
CREATE_MAPPINGNameless FileMappingTrue6
Fn
CREATE_MAPPINGNameless FileMappingmaximum_size = 935406004048, protection = PAGE_READWRITETrue1
Fn
CREATE_MAPPINGNameless FileMappingmaximum_size = 935406005712, protection = PAGE_READWRITETrue2
Fn
CREATE_MAPPINGNameless FileMappingmaximum_size = 935406004592, protection = PAGE_READWRITETrue1
Fn
CREATE_MAPPINGNameless FileMappingmaximum_size = 935403842240, protection = PAGE_READWRITETrue1
Fn
CREATE_MAPPINGNameless FileMappingmaximum_size = 935403843360, protection = PAGE_READWRITETrue1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x16c, address = 0xd9cbf50000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xd9cbf50000True1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x16c, address = 0xd9cbf60000True3
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xd9cbf60000True2
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xd9cbf60000True1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x16c, address = 0xd9cbf80000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xd9cbf80000True1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x16c, address = 0xd9cbf90000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xd9cbf90000True1
Fn
UNMAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x16cTrue6
Fn
Registry (325)
+
OperationKeyAdditional InformationSuccessAmountLogfile
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Terminal ServerTrue1
Fn
OPEN_KEY\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_InitializeTrue1
Fn
OPEN_KEYTrue164
Fn
OPEN_KEYFalse108
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Terminal Servervalue_name = TSAppCompatFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Terminal Servervalue_name = TSUserEnabledFalse1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initializevalue_name = DisableMetaFilesFalse1
Fn
READ_VALUETrue24
Fn
READ_VALUEvalue_name = 935406002472True1
Fn
READ_VALUEvalue_name = 935405999592True5
Fn
READ_VALUEvalue_name = 935406001256True4
Fn
READ_VALUEvalue_name = targetNamespaceTrue4
Fn
READ_VALUEvalue_name = dpiAwareTrue4
Fn
READ_VALUEvalue_name = 935406000136True2
Fn
READ_VALUEvalue_name = 935403837784True2
Fn
READ_VALUEvalue_name = 935403838904True2
Fn
Driver (2)
+
OperationDriverAdditional InformationSuccessAmountLogfile
CONTROLTrue1
Fn
CONTROLcontrol_code = 0x390008True1
Fn
System (46)
+
OperationInformationSuccessAmountLogfile
GET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
GET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue24
Fn
GET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue21
Fn
Mutex (1)
+
OperationNameAdditional InformationSuccessAmountLogfile
CREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
Process #9: winlogon.exe
(Host: 604, Network: 0)
+
InformationValue
ID / OS PID#9 / 0x194
OS Parent PID0x15c (c:\windows\winstore\wshost.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe
Command Linewinlogon.exe
MonitorStart Time: 00:01:34, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:33
OS Thread IDs
#67
0x198
#82
0x1EC
#83
0x1F4
#114
0x270
#115
0x274
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x0000009f3e8a00000x9f3e8a00000x9f3e8bffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000009f3e8a00000x9f3e8a00000x9f3e8affffPagefile Backed FileReadable, WritableTrue
private_0x0000009f3e8b00000x9f3e8b00000x9f3e8b6fffPrivate MemoryReadable, WritableTrue
pagefile_0x0000009f3e8c00000x9f3e8c00000x9f3e8cefffPagefile Backed FileReadableTrue
private_0x0000009f3e8d00000x9f3e8d00000x9f3e94ffffPrivate MemoryReadable, WritableTrue
locale.nls0x9f3e9500000x9f3e9cdfffMemory Mapped FileReadableFalse
private_0x0000009f3e9d00000x9f3e9d00000x9f3e9d6fffPrivate MemoryReadable, WritableTrue
winlogon.exe.mui0x9f3e9e00000x9f3e9e5fffMemory Mapped FileReadableFalse
USER32.dll.mui0x9f3e9e00000x9f3e9e4fffMemory Mapped FileReadableFalse
private_0x0000009f3e9f00000x9f3e9f00000x9f3e9f0fffPrivate MemoryReadable, WritableTrue
private_0x0000009f3ea000000x9f3ea000000x9f3ea00fffPrivate MemoryReadable, WritableTrue
private_0x0000009f3ea100000x9f3ea100000x9f3ea16fffPrivate MemoryReadable, WritableTrue
USER32.dll.mui0x9f3ea200000x9f3ea24fffMemory Mapped FileReadableFalse
Aero.msstyles.mui0x9f3ea200000x9f3ea20fffMemory Mapped FileReadableFalse
private_0x0000009f3ea300000x9f3ea300000x9f3ea30fffPrivate MemoryReadable, WritableTrue
pagefile_0x0000009f3ea400000x9f3ea400000x9f3ea40fffPagefile Backed FileReadable, WritableTrue
private_0x0000009f3ea500000x9f3ea500000x9f3eb4ffffPrivate MemoryReadable, WritableTrue
private_0x0000009f3eb500000x9f3eb500000x9f3ebcffffPrivate MemoryReadable, WritableTrue
private_0x0000009f3ebd00000x9f3ebd00000x9f3ec4ffffPrivate MemoryReadable, WritableTrue
private_0x0000009f3ebd00000x9f3ebd00000x9f3ec4ffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000009f3ec500000x9f3ec500000x9f3ec7ffffPagefile Backed FileReadableTrue
private_0x0000009f3ec800000x9f3ec800000x9f3ec8ffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000009f3ec900000x9f3ec900000x9f3ee17fffPagefile Backed FileReadableTrue
pagefile_0x0000009f3ee200000x9f3ee200000x9f3efa0fffPagefile Backed FileReadableTrue
sortdefault.nls0x9f3efb00000x9f3f284fffMemory Mapped FileReadableFalse
private_0x0000009f3f3000000x9f3f3000000x9f3f30ffffPrivate MemoryReadable, WritableTrue
Aero.msstyles0x9f3f3100000x9f3f418fffMemory Mapped FileReadableFalse
private_0x0000009f3f3900000x9f3f3900000x9f3f40ffffPrivate MemoryReadable, WritableTrue
private_0x0000009f3f4200000x9f3f4200000x9f3fe1ffffPrivate MemoryReadable, WritableTrue
private_0x0000009f3fe200000x9f3fe200000x9f3ff1ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007df5ff3e00000x7df5ff3e00000x7ff5ff3dffffPagefile Backed File-True
pagefile_0x00007df5ff3e00000x7df5ff3e00000x7ff5ff3dffffPagefile Backed File-True
pagefile_0x00007ff7f65200000x7ff7f65200000x7ff7f661ffffPagefile Backed FileReadableTrue
pagefile_0x00007ff7f66200000x7ff7f66200000x7ff7f6642fffPagefile Backed FileReadableTrue
private_0x00007ff7f66440000x7ff7f66440000x7ff7f6645fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7f66480000x7ff7f66480000x7ff7f6649fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7f664a0000x7ff7f664a0000x7ff7f664bfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7f664c0000x7ff7f664c0000x7ff7f664cfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7f664c0000x7ff7f664c0000x7ff7f664cfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7f664e0000x7ff7f664e0000x7ff7f664ffffPrivate MemoryReadable, WritableTrue
winlogon.exe0x7ff7f6bc00000x7ff7f6c52fffMemory Mapped FileReadable, Writable, ExecutableFalse
WindowsCodecs.dll0x7ffb702d00000x7ffb7047dfffMemory Mapped FileReadable, Writable, ExecutableFalse
UxTheme.dll0x7ffb704800000x7ffb705a8fffMemory Mapped FileReadable, Writable, ExecutableFalse
uxinit.dll0x7ffb705e00000x7ffb705f6fffMemory Mapped FileReadable, Writable, ExecutableFalse
winsta.dll0x7ffb709400000x7ffb70999fffMemory Mapped FileReadable, Writable, ExecutableFalse
KBDUS.DLL0x7ffb709900000x7ffb70993fffMemory Mapped FileReadable, Writable, ExecutableFalse
KBDUS.DLL0x7ffb70a200000x7ffb70a23fffMemory Mapped FileReadable, Writable, ExecutableFalse
winlogonext.dll0x7ffb70a300000x7ffb70a48fffMemory Mapped FileReadable, Writable, ExecutableFalse
rsaenh.dll0x7ffb70b000000x7ffb70b35fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTSP.dll0x7ffb710400000x7ffb7105ffffMemory Mapped FileReadable, Writable, ExecutableFalse
bcrypt.dll0x7ffb712600000x7ffb71285fffMemory Mapped FileReadable, Writable, ExecutableFalse
powrprof.dll0x7ffb715300000x7ffb71575fffMemory Mapped FileReadable, Writable, ExecutableFalse
bcryptPrimitives.dll0x7ffb715800000x7ffb715e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTBASE.dll0x7ffb715f00000x7ffb715fafffMemory Mapped FileReadable, Writable, ExecutableFalse
profapi.dll0x7ffb716b00000x7ffb716c4fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
gdi32.dll0x7ffb71ad00000x7ffb71c20fffMemory Mapped FileReadable, Writable, ExecutableTrue
sechost.dll0x7ffb733c00000x7ffb73418fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
advapi32.dll0x7ffb736900000x7ffb73739fffMemory Mapped FileReadable, Writable, ExecutableTrue
combase.dll0x7ffb737400000x7ffb73950fffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSCTF.dll0x7ffb73b800000x7ffb73cd2fffMemory Mapped FileReadable, Writable, ExecutableTrue
user32.dll0x7ffb73e900000x7ffb74006fffMemory Mapped FileReadable, Writable, ExecutableTrue
IMM32.dll0x7ffb740100000x7ffb74045fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSVCRT.dll0x7ffb740500000x7ffb740f9fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Host Behavior
File (20)
+
OperationFilenameAdditional InformationSuccessAmountLogfile
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\kbdus.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nlsdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATEFalse1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\vscache\aero.msstyles_1033_96.mssdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATETrue2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\aero.msstylesdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\aero.msstylesdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exedesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exedesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\segoeuib.ttfdesired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, open_options = FILE_SYNCHRONOUS_IO_NONALERTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\segoeui.ttfdesired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, open_options = FILE_SYNCHRONOUS_IO_NONALERTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\tahoma.ttfdesired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, open_options = FILE_SYNCHRONOUS_IO_NONALERTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\micross.ttfdesired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, open_options = FILE_SYNCHRONOUS_IO_NONALERTTrue1
Fn
READTrue2
Fn
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\aero.msstylessize = 16True1
Fn
Data
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\aero.msstylessize = 128True1
Fn
Data
Process (105)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
CREATETrue1
Fn
CREATEdesired_access = MAXIMUM_ALLOWED, creation_flags = CREATE_NEW_PROCESS_GROUPTrue1
Fn
OPEN_TOKENTrue4
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True4
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True5
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True85
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFOTrue1
Fn
Memory (3)
+
OperationAddressAdditional InformationSuccessAmountLogfile
ALLOC0x9f3e94dc78process_name = , size = 683949743576, allocation_type = MEM_COMMIT, protection = PAGE_READWRITETrue1
Fn
WRITE0xa3b7d40000process_name = , size = 4704True1
Fn
Data
WRITE0x7ff74d8ca2d8process_name = , size = 8True1
Fn
Data
Thread (2)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, proc_address = 0x7ff7f6bcf270, desired_access = THREAD_ALL_ACCESSTrue1
Fn
RESUMETrue1
Fn
Module (79)
+
OperationModuleAdditional InformationSuccessAmountLogfile
LOADX:\windows\system32\IMM32.DLLbase_address = 0x0True1
Fn
LOADrpcrt4.dllbase_address = 0x0True1
Fn
LOADKBDUS.DLLbase_address = 0x0True2
Fn
LOADkernel32.dllbase_address = 0x0True1
Fn
LOADbase_address = 0x9f3f310001True1
Fn
LOADbase_address = 0x7ffb70b00000True1
Fn
LOADX:\windows\system32\rsaenh.dllbase_address = 0x0True1
Fn
LOADbase_address = 0x7ffb71580000True1
Fn
LOADX:\windows\system32\bcryptprimitives.dllbase_address = 0x0True1
Fn
LOADbase_address = 0x0False1
Fn
LOADoobe\WinLGDep.dllbase_address = 0xc0000135False1
Fn
GET_HANDLE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exeTrue2
Fn
GET_HANDLEX:\windows\system32\IMM32.DLLFalse1
Fn
GET_HANDLEX:\windows\system32\IMM32.DLLTrue2
Fn
GET_HANDLEIMM32.DLLTrue1
Fn
GET_HANDLEuser32.dllTrue1
Fn
GET_HANDLErpcrt4.dllTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\segoeuib.ttf, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\segoeui.ttf, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\tahoma.ttf, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\micross.ttf, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\aero.msstyles, maximum_size = 0, protection = PAGE_READONLYTrue2
Fn
CREATE_MAPPINGNameless FileMappingTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x9f3efb0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x9f3efb0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x9f3efb0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x9f3efb0000True1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exeos_pid = 0x194, address = 0x9f3ea10000True2
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, address = 0x9f3ea10000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x9f3efb0000True1
Fn
MAPSoftware\Microsoft\Windows\CurrentVersion\ThemeManagerprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x9f3ea10000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x9f3f310000True1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exeos_pid = 0x194, address = 0x9f3f420000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x9f3f420000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x9f3f410000False1
Fn
UNMAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, base_address = 0x9f3efb0000True4
Fn
UNMAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exeos_pid = 0x194True3
Fn
UNMAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, base_address = 0x9f3f310000True1
Fn
UNMAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, base_address = 0x9f3f410000True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb73e94c30True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b01570True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b01080True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b06090True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b1e1d0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b02ce0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b0af70True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b03880True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b03a30True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b03260True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b06be0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b04ea0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b027d0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b02b00True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b1d8d0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b024f0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b06830True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b03c50True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b01030True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b05bb0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b0f290True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b0f750True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b03f50True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b02630True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b0d330True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b1d6e0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb715848b0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb7159b3d0True1
Fn
Service (4)
+
OperationServiceAdditional InformationSuccessAmountLogfile
OPEN_MGRSERVICES_ACTIVE_DATABASEhost = LocalhostTrue2
Fn
OPENFalse2
Fn
Registry (370)
+
OperationKeyAdditional InformationSuccessAmountLogfile
CREATE_KEY\REGISTRY\MACHINE\SOFTWARE\CLASSESTrue1
Fn
CREATE_KEY\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
CREATE_KEYTrue2
Fn
CREATE_KEYSoftware\Microsoft\Windows\CurrentVersion\ThemeManagerTrue2
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\VersionsTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Error Message Instrument\False1
Fn
OPEN_KEY\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_InitializeTrue1
Fn
OPEN_KEYTrue38
Fn
OPEN_KEYFalse4
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\ComputerNameTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameFalse1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNameTrue1
Fn
OPEN_KEY\Registry\Machine\System\SetupTrue5
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
OPEN_KEYKeyboard Layout\PreloadTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Keyboard Layouts\00000409True2
Fn
OPEN_KEY\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRTrue1
Fn
OPEN_KEY\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR\Control Panel\InternationalTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocaleTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocaleTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\LocaleTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Locale\Alternate SortsTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Language GroupsTrue1
Fn
OPEN_KEYControl Panel\Input Method\Hot KeysTrue2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000010True2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000011True2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000012True2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000070True2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000071True2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000072True2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000104True2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000200True2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000201True2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000202True2
Fn
OPEN_KEYControl Panel\Input Method\Hot Keys\00000203True2
Fn
OPEN_KEY\REGISTRY\USER\S-1-5-18True4
Fn
OPEN_KEY\REGISTRY\USER\S-1-5-18\Keyboard Layout\PreloadTrue3
Fn
OPEN_KEY\REGISTRY\USER\S-1-5-18\Keyboard Layout\Preload\Keyboard Layout\PreloadTrue1
Fn
OPEN_KEY\REGISTRY\USER\S-1-5-18\Keyboard Layout\SubstitutesTrue1
Fn
OPEN_KEYHKEY_CURRENT_USERFalse10
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\IdsTrue1
Fn
OPEN_KEY\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDllsFalse1
Fn
OPEN_KEY\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\OptionFalse1
Fn
OPEN_KEY\Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySideTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versionsvalue_name = 683949743520True1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initializevalue_name = DisableMetaFilesFalse1
Fn
READ_VALUEvalue_name = LoadAppInit_DLLsTrue1
Fn
READ_VALUEFalse11
Fn
READ_VALUEvalue_name = TracingControlLevelFalse1
Fn
READ_VALUEvalue_name = SimulateDebugSessionFalse1
Fn
READ_VALUETrue44
Fn
READ_VALUEvalue_name = RespecializeTrue1
Fn
READ_VALUEvalue_name = SetupTypeTrue1
Fn
READ_VALUEvalue_name = NoDebugThreadFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNamevalue_name = ComputerNameTrue1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = OOBEInProgressFalse2
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = SystemSetupInProgressTrue2
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = ProfileImagePathTrue2
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = PublicTrue2
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = ProgramDataTrue2
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = ProgramFilesDirTrue1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = CommonFilesDirTrue1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = ProgramFilesDir (x86)True1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = CommonFilesDir (x86)True1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = ProgramW6432DirTrue1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = CommonW6432DirTrue1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = AllowBlockingAppsAtShutdownFalse1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = MaxRpcSizeFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNamevalue_name = ComputerNameTrue1
Fn
READ_VALUEvalue_name = IdleTimerWindowFalse1
Fn
READ_VALUEKeyboard Layout\Preloadvalue_name = 1True1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Keyboard Layouts\00000409value_name = Layout FileTrue2
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Keyboard Layouts\00000409value_name = AttributesFalse2
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRvalue_name = DisableTrue1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR\Control Panel\InternationalFalse1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR\Control Panel\InternationalTrue1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR\Control Panel\Internationalvalue_name = sCurrencyOverrideFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocalevalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocalevalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Localevalue_name = 00000409True1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Language Groupsvalue_name = 1True1
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000010value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000010value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000010value_name = Target IMETrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000011value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000011value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000011value_name = Target IMETrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000012value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000012value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000012value_name = Target IMETrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000070value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000070value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000070value_name = Target IMETrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000071value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000071value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000071value_name = Target IMETrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000072value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000072value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000072value_name = Target IMETrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000104value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000104value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000104value_name = Target IMETrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000200value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000200value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000200value_name = Target IMETrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000201value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000201value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000201value_name = Target IMETrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000202value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000202value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000202value_name = Target IMETrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000203value_name = Virtual KeyTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000203value_name = Key ModifiersTrue2
Fn
READ_VALUEControl Panel\Input Method\Hot Keys\00000203value_name = Target IMETrue2
Fn
READ_VALUE\REGISTRY\USER\S-1-5-18\Keyboard Layout\Preloadvalue_name = 1False1
Fn
READ_VALUE\REGISTRY\USER\S-1-5-18\Keyboard Layout\Preloadvalue_name = 1True1
Fn
READ_VALUE\REGISTRY\USER\S-1-5-18\Keyboard Layout\Preloadvalue_name = 2False2
Fn
READ_VALUE\REGISTRY\USER\S-1-5-18\Keyboard Layout\Preload\Keyboard Layout\Preloadvalue_name = 1True1
Fn
READ_VALUE\REGISTRY\USER\S-1-5-18\Keyboard Layout\Substitutesvalue_name = 00000409False1
Fn
READ_VALUEControl Panel\Input Method\Hot Keysvalue_name = SecureBootTrue1
Fn
READ_VALUEvalue_name = LMVersionTrue2
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\ThemeManagervalue_name = LMVersionFalse1
Fn
READ_VALUEvalue_name = LMOverRideTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versionsvalue_name = 000602xxTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Idsvalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Idsvalue_name = enFalse1
Fn
READ_VALUEvalue_name = LoadedBeforeTrue1
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\ThemeManagervalue_name = LMVersionTrue3
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\ThemeManagervalue_name = LoadedBeforeTrue2
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\ThemeManagervalue_name = DllNameTrue1
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\ThemeManagervalue_name = ColorNameFalse1
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\ThemeManagervalue_name = SizeNameFalse1
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\ThemeManagervalue_name = LastUserLangIDFalse1
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\ThemeManagervalue_name = LastLoadedDPIFalse1
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\ThemeManagervalue_name = LastLoadedPPIFalse1
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\ThemeManagervalue_name = PageAllocatorUseSystemHeapFalse1
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\ThemeManagervalue_name = PageAllocatorSystemHeapIsPrivateFalse1
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\ThemeManagervalue_name = AggressiveMTATestingFalse1
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\aero.msstylesvalue_name = NameTrue4
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\aero.msstylesvalue_name = TypeTrue1
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\aero.msstylesvalue_name = Image PathTrue4
Fn
READ_VALUEvalue_name = MachineGuidTrue4
Fn
READ_VALUEvalue_name = ProgramFilesDirTrue1
Fn
READ_VALUEvalue_name = CommonFilesDirTrue1
Fn
READ_VALUEvalue_name = ProgramFilesDir (x86)True1
Fn
READ_VALUEvalue_name = CommonFilesDir (x86)True1
Fn
READ_VALUEvalue_name = ProgramW6432DirTrue1
Fn
READ_VALUEvalue_name = CommonW6432DirTrue1
Fn
READ_VALUEvalue_name = UserinitTrue4
Fn
READ_VALUEvalue_name = userinitTrue1
Fn
READ_VALUEvalue_name = SystemFalse1
Fn
READ_VALUEvalue_name = CmdlineTrue1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = 140717948767312False1
Fn
READ_VALUE\Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySidevalue_name = PreferExternalManifestFalse1
Fn
WRITE_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNamevalue_name = ComputerName, data = MINWINPCTrue1
Fn
WRITE_VALUETrue10
Fn
WRITE_VALUESoftware\Microsoft\Windows\CurrentVersion\ThemeManagervalue_name = LMVersion, data = 105True2
Fn
WRITE_VALUESoftware\Microsoft\Windows\CurrentVersion\ThemeManagervalue_name = DllName, data = %SystemRoot%\resources\themes\Aero\Aero.msstylesTrue1
Fn
WRITE_VALUESoftware\Microsoft\Windows\CurrentVersion\ThemeManagervalue_name = ThemeActive, data = 1True1
Fn
WRITE_VALUESoftware\Microsoft\Windows\CurrentVersion\ThemeManagervalue_name = LoadedBefore, data = 0True2
Fn
WRITE_VALUEvalue_name = LoadedBefore, data = 1True1
Fn
WRITE_VALUEvalue_name = Userinit, data = True1
Fn
WRITE_VALUEvalue_name = Userinit, data = X:\windows\system32\userinit.exe,True1
Fn
WRITE_VALUEvalue_name = SetupType, data = 0True1
Fn
DELETE_VALUEFalse6
Fn
DELETE_VALUEvalue_name = InstallThemeFalse1
Fn
DELETE_VALUEvalue_name = SetVisualStyleFalse1
Fn
DELETE_VALUEvalue_name = InstallVisualStyleFalse1
Fn
DELETE_VALUESoftware\Microsoft\Windows\CurrentVersion\ThemeManagervalue_name = ColorNameFalse1
Fn
DELETE_VALUESoftware\Microsoft\Windows\CurrentVersion\ThemeManagervalue_name = SizeNameFalse1
Fn
DELETE_VALUEvalue_name = AutoAdminLogonFalse1
Fn
Driver (2)
+
OperationDriverAdditional InformationSuccessAmountLogfile
CONTROLTrue1
Fn
CONTROLcontrol_code = 0x390008True1
Fn
Keyboard (2)
+
OperationVirtual Key CodeAdditional InformationSuccessAmountLogfile
READresult_out = 0True2
Fn
System (17)
+
OperationInformationSuccessAmountLogfile
CREATE_DESKTOPTrue2
Fn
SWITCH_DESKTOPTrue2
Fn
GET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
GET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue8
Fn
GET_INFOTrue1
Fn
GET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue3
Fn
Process #10: services.exe
(Host: 10677, Network: 0)
+
InformationValue
ID / OS PID#10 / 0x1ac
OS Parent PID0x164 (c:\windows\system32\csrss.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe
Command LineX:\windows\system32\services.exe -setup
MonitorStart Time: 00:01:35, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:32
OS Thread IDs
#68
0x1B0
#90
0x208
#91
0x20C
#97
0x224
#111
0x260
#134
0x2D4
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x00000094cfe900000x94cfe900000x94cfeaffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000094cfe900000x94cfe900000x94cfe9ffffPagefile Backed FileReadable, WritableTrue
private_0x00000094cfea00000x94cfea00000x94cfea6fffPrivate MemoryReadable, WritableTrue
pagefile_0x00000094cfeb00000x94cfeb00000x94cfebefffPagefile Backed FileReadableTrue
private_0x00000094cfec00000x94cfec00000x94cff3ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000094cff400000x94cff400000x94cff43fffPagefile Backed FileReadableTrue
pagefile_0x00000094cff500000x94cff500000x94cff50fffPagefile Backed FileReadableTrue
locale.nls0x94cff600000x94cffddfffMemory Mapped FileReadableFalse
private_0x00000094cffe00000x94cffe00000x94cffe6fffPrivate MemoryReadable, WritableTrue
pagefile_0x00000094cfff00000x94cfff00000x94cfff2fffPagefile Backed FileReadable, WritableTrue
services.exe.mui0x94d00000000x94d0004fffMemory Mapped FileReadableFalse
private_0x00000094d00400000x94d00400000x94d004ffffPrivate MemoryReadable, WritableTrue
private_0x00000094d00c00000x94d00c00000x94d01bffffPrivate MemoryReadable, WritableTrue
sortdefault.nls0x94d01c00000x94d0494fffMemory Mapped FileReadableFalse
private_0x00000094d04a00000x94d04a00000x94d059ffffPrivate MemoryReadable, WritableTrue
private_0x00000094d05a00000x94d05a00000x94d079ffffPrivate MemoryReadable, WritableTrue
private_0x00000094d07a00000x94d07a00000x94d081ffffPrivate MemoryReadable, WritableTrue
private_0x00000094d08200000x94d08200000x94d089ffffPrivate MemoryReadable, WritableTrue
private_0x00000094d08a00000x94d08a00000x94d091ffffPrivate MemoryReadable, WritableTrue
private_0x00000094d09200000x94d09200000x94d099ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007df5fff400000x7df5fff400000x7ff5fff3ffffPagefile Backed File-True
pagefile_0x00007df5fff400000x7df5fff400000x7ff5fff3ffffPagefile Backed File-True
pagefile_0x00007df5fff400000x7df5fff400000x7ff5fff3ffffPagefile Backed File-True
pagefile_0x00007ff6727700000x7ff6727700000x7ff67286ffffPagefile Backed FileReadableTrue
pagefile_0x00007ff6728700000x7ff6728700000x7ff672892fffPagefile Backed FileReadableTrue
private_0x00007ff6728930000x7ff6728930000x7ff672893fffPrivate MemoryReadable, WritableTrue
private_0x00007ff6728960000x7ff6728960000x7ff672897fffPrivate MemoryReadable, WritableTrue
private_0x00007ff6728980000x7ff6728980000x7ff672899fffPrivate MemoryReadable, WritableTrue
private_0x00007ff67289a0000x7ff67289a0000x7ff67289bfffPrivate MemoryReadable, WritableTrue
private_0x00007ff67289c0000x7ff67289c0000x7ff67289dfffPrivate MemoryReadable, WritableTrue
private_0x00007ff67289e0000x7ff67289e0000x7ff67289ffffPrivate MemoryReadable, WritableTrue
services.exe0x7ff6730600000x7ff6730c5fffMemory Mapped FileReadable, Writable, ExecutableFalse
AUTHZ.dll0x7ffb708600000x7ffb708a7fffMemory Mapped FileReadable, Writable, ExecutableFalse
scesrv.dll0x7ffb708b00000x7ffb70939fffMemory Mapped FileReadable, Writable, ExecutableFalse
spinf.dll0x7ffb709a00000x7ffb709bdfffMemory Mapped FileReadable, Writable, ExecutableFalse
srvcli.dll0x7ffb709c00000x7ffb709e5fffMemory Mapped FileReadable, Writable, ExecutableFalse
EventAggregation.dll0x7ffb709f00000x7ffb709fafffMemory Mapped FileReadable, Writable, ExecutableFalse
DABAPI.dll0x7ffb70a000000x7ffb70a07fffMemory Mapped FileReadable, Writable, ExecutableFalse
scext.dll0x7ffb70a100000x7ffb70a20fffMemory Mapped FileReadable, Writable, ExecutableFalse
SspiCli.dll0x7ffb715000000x7ffb7152dfffMemory Mapped FileReadable, Writable, ExecutableFalse
bcryptPrimitives.dll0x7ffb715800000x7ffb715e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTBASE.dll0x7ffb715f00000x7ffb715fafffMemory Mapped FileReadable, Writable, ExecutableFalse
profapi.dll0x7ffb716b00000x7ffb716c4fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
sechost.dll0x7ffb733c00000x7ffb73418fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSVCRT.dll0x7ffb740500000x7ffb740f9fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Injection Information
+
Injection TypeSource ProcessSource Os Thread IDInjection InfoSuccessAmountLogfile
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188address = 0x4584630000, size = 16384True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188address = 0x4584630000, size = 4096True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188No corresponding api call detected. Probably injected code via shellcode.True1
Created or Modified Files
+
FilenameFile SizeHash Values
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbxhci.pnf 11.26 KB (11528 bytes)MD5: 72a7d52c829219fe574e86638fb6a23b
SHA1: e59da7ae2aab26f70663f39adf91efcb191aad2c
SHA256: ffff12546c87da3388192d28602e3fdaa9a1aaf30d43335b17e5af27867b97ce
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hdaudbus.pnf 9.04 KB (9256 bytes)MD5: cae8133113b0fa8eb45181f9c5d6dbdb
SHA1: ec18aa17bdc203b0d550c8fd8c6300b3df857b6f
SHA256: 76ab1f207f5c4c1bbac23e93fac1526804230fb8b3b2bb5c2d67396d8088111d
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat 256.00 KB (262144 bytes)MD5: 2aa9bd6793f83cef98d5d7fd60ab405b
SHA1: 21c2f6d19d1b0bacbc3f77e3d65e268de288a4e4
SHA256: 5c082b5c231e8b2543ae6add7a80da48de09b3a17f67e79bdd465be59b3a3d84
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat 256.00 KB (262144 bytes)MD5: 2aa9bd6793f83cef98d5d7fd60ab405b
SHA1: 21c2f6d19d1b0bacbc3f77e3d65e268de288a4e4
SHA256: 5c082b5c231e8b2543ae6add7a80da48de09b3a17f67e79bdd465be59b3a3d84
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msmouse.pnf 90.35 KB (92520 bytes)MD5: 348c682409045af377e6a1dca770dc90
SHA1: 2bae29b156217f52678974af1c94aca774a28736
SHA256: 7f4f7089b57310b37eab34376b7dfc2950630a7f1b4aeec32fe397b543142d2c
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\errdev.pnf 8.43 KB (8628 bytes)MD5: 913f6bc3d9c97be46972c278ba84e164
SHA1: 7a40bf25292697394f6a5e3fe0e27e1b31da778c
SHA256: 3bcfc47aa85bda59cebebb0f950d97a3f3c6fd5fb144c4a90e4514416d69a9cb
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cdrom.pnf 13.08 KB (13396 bytes)MD5: ea8c9d9fd77d6fa9d3fe8cadf4b15d99
SHA1: a3318b388daf7c943d3d3f0dab70187fa450568e
SHA256: 060a3c11e01858498e7867135d78acb5126cad3167590a5dbe8d08e063e47bf0
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000001.regtrans-ms 512.00 KB (524288 bytes)MD5: 61bb82ecefdac3b60b11441cc6c780b0
SHA1: da763f11762558805d9b32096c8e47bd03132b5e
SHA256: ca0e01a9ed63401c0d0458a315adbc586e19d7638272aafb5ecadd4817efc5c7
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000001.regtrans-ms 512.00 KB (524288 bytes)MD5: 61bb82ecefdac3b60b11441cc6c780b0
SHA1: da763f11762558805d9b32096c8e47bd03132b5e
SHA256: ca0e01a9ed63401c0d0458a315adbc586e19d7638272aafb5ecadd4817efc5c7
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\qlfcoei.pnf 10.95 KB (11216 bytes)MD5: 62816a91b4b87f7dc7f57f2503502325
SHA1: bd3fdee1b75f0674723f66cee4f0b2ea0bd33ce4
SHA256: cc07c110eaf6a978c3a67642c58f5230d1188cab4766578e68e604dc1ea9f275
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cht4vx64.pnf 25.11 KB (25708 bytes)MD5: 60222a0f4c6c8de63f3d768f74aa73e4
SHA1: 2061d813df910a2fbd525928eaf0eead093ee607
SHA256: 1e04432c12cfcf7ac033fb0ebf1267e23a48686942b8b10ea29fc3391c8b3fac
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxois.pnf 17.07 KB (17480 bytes)MD5: b8cf94487fa53de1e07885eb5a03b13c
SHA1: a29d0433472bea0bd0245674bfad3d0d6d5a42e0
SHA256: cec39cf75e876d284ce5eb58df6e5eb9844c7b841b550606fe9e7959ffcf7662
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\agp.pnf 15.05 KB (15408 bytes)MD5: b91108bbe0218f1c933f540dcfcd4559
SHA1: bfa39b3a402fd707f07ecb2ce223fc35ed86bc97
SHA256: dad053eab78fd20eb15e06525b54349c9bdf0a0988d023132faaf3cdfa64a16f
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usb.pnf 71.04 KB (72748 bytes)MD5: 0ea6f3c600dd9b540faf720d418be41d
SHA1: d639d62e21e966c50d4fb5b434d68c0fcd950e90
SHA256: 31ac1218f82d67a4ff37423ed037776fd9fef2d5ff5b12040696fc2d812f61a8
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programs\system tools\command prompt.lnk 1.12 KB (1142 bytes)MD5: 9c82e435db86860edb5ced5f369bdfb3
SHA1: a63c6007e8679aac89632ff7ac88b29df4a11b9e
SHA256: 23db6dd5bb4644850d5afe83f1126d582238162ab480479fb12a6b9998a82511
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programs\system tools\command prompt.lnk 1.12 KB (1142 bytes)MD5: 9c82e435db86860edb5ced5f369bdfb3
SHA1: a63c6007e8679aac89632ff7ac88b29df4a11b9e
SHA256: 23db6dd5bb4644850d5afe83f1126d582238162ab480479fb12a6b9998a82511
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mssmbios.pnf 7.59 KB (7768 bytes)MD5: 47bc949bb6ff56c1cd36c2c0350bc4c6
SHA1: 4610333269123f7eeb62a9995ea8511c2cd3bfa6
SHA256: 4156895c97ab1ebd9f9ca34944eace2f79909ba88929c42e29ee61ca4aa358e9
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tm.blf 64.00 KB (65536 bytes)MD5: f05bb5e3d62100de94995032e40318cd
SHA1: 316e1aa45ca7d1026ce8243c34ee9adb32939923
SHA256: 29ca52555753d55ac9d1940ad746ad540d6beaac8209fddadfb7d74f37ec3e90
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tm.blf 64.00 KB (65536 bytes)MD5: f05bb5e3d62100de94995032e40318cd
SHA1: 316e1aa45ca7d1026ce8243c34ee9adb32939923
SHA256: 29ca52555753d55ac9d1940ad746ad540d6beaac8209fddadfb7d74f37ec3e90
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tm.blf 64.00 KB (65536 bytes)MD5: 287d4d682e1c88640cbeebe11fac2f85
SHA1: d5a3b04c46d5ff20170d8c63ca6996b575100475
SHA256: 22db3ce0e70a6b5975906794e5c2c3459d7f7353890638e4c25598d02fe5b824
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tm.blf 64.00 KB (65536 bytes)MD5: 287d4d682e1c88640cbeebe11fac2f85
SHA1: d5a3b04c46d5ff20170d8c63ca6996b575100475
SHA256: 22db3ce0e70a6b5975906794e5c2c3459d7f7353890638e4c25598d02fe5b824
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf 59.45 KB (60880 bytes)MD5: a2a4e415e53c25caa790c4178227df85
SHA1: d7a41ad4470f3f6794428ed87e2361f013c479e9
SHA256: a87689bf630dfe0a52fdbedc428242cf97c8c0c620a7cd8361670dc8417def9b
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorav.pnf 11.79 KB (12068 bytes)MD5: 105c62370e5c9f9126893cb464701bb9
SHA1: 53126901723d0bd87095a00c3b8212ef3908d1d9
SHA256: 4d20985fc88f173cdba2e141a2041ca535cd19469200ffa52cceaa03fe5678aa
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf 6.66 KB (6820 bytes)MD5: 4a6bf9c2a829cf4d1b96a66e42e88632
SHA1: cb1fe3699f00a3b27280432283006797177ed9be
SHA256: 369d0b0a8076207617c5fb414e434f98281b41a597d8bda7ae1781b2c7e7ebe8
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iscsi.pnf 10.80 KB (11056 bytes)MD5: aff57dbe66f472508a675099d19ea93f
SHA1: b941f03eeb507efee9bd9d076a5ad7b1995cd203
SHA256: 09a00b446c358f759e70ed188f0cc0755405cf2449cb09f7d2983e58c63bb155
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\stornvme.pnf 10.67 KB (10928 bytes)MD5: 9f32d460d749e4622855bb0a37d4383a
SHA1: c9289529f91964d50b01d1d8cd55eebbbd0d6bb3
SHA256: e419cb3d2e6cdf80af892e376cb7621f59fcfe556b8b083b2d7d78984f265b27
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mlx4_bus.pnf 42.48 KB (43500 bytes)MD5: 944671ca7c6b2f500b8d22be8bb3d3b4
SHA1: c4682261d5ccee536d15761b9e1a9e0d73af2d7c
SHA256: 6c77e42da8c288ffe671b5bbd89e86ab559d48e3d6d9d0e3696cc7c7e77d6484
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf 6.85 KB (7012 bytes)MD5: 395fac9d715c0fcdb4bd67f5f35b8139
SHA1: ea1935ec1ef0cc542b431b224d588f57af303c3f
SHA256: 088f67825e30087fb14c060945c700cd444c6c2d03c35e7da253a48f0c9dd99c
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hiddigi.pnf 8.23 KB (8424 bytes)MD5: d13ec5c97793dd65f4f736c218c96978
SHA1: 14089394e9628bb62e5561f343a5fae7f8d76711
SHA256: dbe5d2cadb841aee93e69ef91674e64445e72ededdc5e8026ce03a6814a7b625
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\wmiacpi.pnf 8.42 KB (8620 bytes)MD5: 77604f04a353eb260633e7bbe855f674
SHA1: 540d62060faade559c4a4d52880855e5ce7f1992
SHA256: e70208995a288adda18e57b38c17c77d707e7486b172056cc53f75d27ab9ff8d
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf 7.26 KB (7436 bytes)MD5: a5b48c42f2e98e2607edf30231cb6023
SHA1: 3fba6e9464fdc544351d9ffb694767d945be7a60
SHA256: eb2ad0f6616dd07e96f7665cf2b86c88063f749efc81ae182bdf86e5c224c43c
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat.log1 40.00 KB (40960 bytes)MD5: 639b969e8dd1c282e9825028177b18ff
SHA1: b550008e1b974ee1d7a7d2ba7b1ed5554a2b7275
SHA256: 032103171a4ce9388e2791d63055101b2034c7440be8a5e1849049ba906dbaf5
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat.log1 40.00 KB (40960 bytes)MD5: 639b969e8dd1c282e9825028177b18ff
SHA1: b550008e1b974ee1d7a7d2ba7b1ed5554a2b7275
SHA256: 032103171a4ce9388e2791d63055101b2034c7440be8a5e1849049ba906dbaf5
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uaspstor.pnf 8.01 KB (8204 bytes)MD5: 8cb26037632d2b7ff36c9ac526ebff16
SHA1: c1f3b2c9d7ecf4f6fef1481f85fb29d50a67341a
SHA256: 056e165a7a876d15a6a5bc5538e6f418185ca1a7e017414f8ebef90ae7c31cb3
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_i2c.pnf 8.52 KB (8720 bytes)MD5: 8ba2ca105e90b447660af73f12d6fda5
SHA1: 56e7d2985a9c71e3c9bbeb3b46583fb3a870a1ec
SHA256: 30373ae81ecc7e3425036718fbb9aaa5b5184fcdf8e10f9e0c98a21057384bc4
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\keyboard.pnf 119.92 KB (122800 bytes)MD5: 6c6312b24a1d82a99745754ad75a7407
SHA1: a264405060499c7a6093e02371aef6cf5809811c
SHA256: 32afc799fbc8f4351cedc36783bd1c107e084037de1babec75928d541be3376b
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sbp2.pnf 7.39 KB (7572 bytes)MD5: e8fb4e90af26ce8b6f6ab0feadeb89eb
SHA1: 1d012a60cd34f2519d9c1b59d04d90be527c7d62
SHA256: 3f0c39717c726f19a063b131ca629d35d7aa7a97f0b17e3fc91e4242ef75b031
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000002.regtrans-ms 512.00 KB (524288 bytes)MD5: 59071590099d21dd439896592338bf95
SHA1: 6a521e1d2a632c26e53b83d2cc4b0edecfc1e68c
SHA256: 07854d2fef297a06ba81685e660c332de36d5d18d546927d30daad6d7fda1541
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000002.regtrans-ms 512.00 KB (524288 bytes)MD5: 59071590099d21dd439896592338bf95
SHA1: 6a521e1d2a632c26e53b83d2cc4b0edecfc1e68c
SHA256: 07854d2fef297a06ba81685e660c332de36d5d18d546927d30daad6d7fda1541
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000002.regtrans-ms 512.00 KB (524288 bytes)MD5: 59071590099d21dd439896592338bf95
SHA1: 6a521e1d2a632c26e53b83d2cc4b0edecfc1e68c
SHA256: 07854d2fef297a06ba81685e660c332de36d5d18d546927d30daad6d7fda1541
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000002.regtrans-ms 512.00 KB (524288 bytes)MD5: 59071590099d21dd439896592338bf95
SHA1: 6a521e1d2a632c26e53b83d2cc4b0edecfc1e68c
SHA256: 07854d2fef297a06ba81685e660c332de36d5d18d546927d30daad6d7fda1541
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programs\accessories\desktop.ini 0.08 KB (79 bytes)MD5: 52b31354ef1082f6a5a2490dc80aabcd
SHA1: 571db4c0054bed9444336667556d81edbf3a9af8
SHA256: ede4a40a65f7e13e841d682880af3f1ca9263b4a25ba3f838aac7432092715a8
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programs\accessories\desktop.ini 0.08 KB (79 bytes)MD5: 52b31354ef1082f6a5a2490dc80aabcd
SHA1: 571db4c0054bed9444336667556d81edbf3a9af8
SHA256: ede4a40a65f7e13e841d682880af3f1ca9263b4a25ba3f838aac7432092715a8
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidbatt.pnf 7.17 KB (7344 bytes)MD5: 1500cba16750cb4d2fa78cb6e00d1008
SHA1: dd65f8795cc656196169b2a43e77a5f4c387c1d0
SHA256: 0e5e82ddc46e5a338a9e9cb575030db90d08e521ba2e58cf362389a6ed8d0587
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uefi.pnf 8.15 KB (8348 bytes)MD5: 3432928245eac49ed9a6036c1c71bb5c
SHA1: 281065c2954be6e68b8d53e389ebb729adaed868
SHA256: bf633c814b1f3ffc8ea2fbe0974a16d98825ab9d2c50889c7f4ff4e00c8e229f
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\vdrvroot.pnf 7.38 KB (7556 bytes)MD5: ca21e9ffd1c74354929e5c27f05a0c18
SHA1: 056ae20a7f3513137c1bc4c9c8901f1ea97dc5b2
SHA256: 99e4316f2ef81afbf4a7d61ee485d19c230edd50af63177fd113181b28a8c013
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programs\accessories\notepad.lnk 1.13 KB (1158 bytes)MD5: ee27db3652032a3498c54a12407b0cb5
SHA1: c4d29c8a67c81c1ada0323ac7c857b113cf5271b
SHA256: 5e7a26e2d64f644e159a6bd5bceb5736c5c71fefe3d648425338b22dc840cbc2
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programs\accessories\notepad.lnk 1.13 KB (1158 bytes)MD5: ee27db3652032a3498c54a12407b0cb5
SHA1: c4d29c8a67c81c1ada0323ac7c857b113cf5271b
SHA256: 5e7a26e2d64f644e159a6bd5bceb5736c5c71fefe3d648425338b22dc840cbc2
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programs\system tools\desktop.ini 0.08 KB (86 bytes)MD5: 68fa444f95dda594dac226f7f13d7e95
SHA1: bc136a7b4bcb9b59c0f51b23c4df7e183cbd02f4
SHA256: 68b6dec0ef20bc8c955650b420432458d808c24dcc4c5126b33618bbf30152a6
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programs\system tools\desktop.ini 0.08 KB (86 bytes)MD5: 68fa444f95dda594dac226f7f13d7e95
SHA1: bc136a7b4bcb9b59c0f51b23c4df7e183cbd02f4
SHA256: 68b6dec0ef20bc8c955650b420432458d808c24dcc4c5126b33618bbf30152a6
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf 26.42 KB (27052 bytes)MD5: 6ab6fdc53b047c790294ae9ba40c8692
SHA1: 41c97e16204dacc9994244c9a82632099975ce71
SHA256: 6ac37fa9a68a1bbc40178bba0f783ed30b243f03f0673cf7cf31674f169f59c3
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sdstor.pnf 9.31 KB (9532 bytes)MD5: 07ab5f7222e3f030ab9bec198bbc3f9f
SHA1: 13fd6c63a60c32ad7d4e6626b71e3197178494ce
SHA256: 7d611c389cd4941bc6f31dec27a2bead46ed5271dc2e1d6e3f72ace0d616bc20
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\flpydisk.pnf 9.44 KB (9668 bytes)MD5: 174b470c234bed33613e1a0c499e62d9
SHA1: 952c0d6b42dfdfa76bf3db186cc6cf7fcaed0c17
SHA256: 8a25902fdd4ef7a743eb6af1aca4a1aaee4d2befe4e5651ea4f72400b6149230
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\volmgr.pnf 8.20 KB (8396 bytes)MD5: 2570146c184248ae2a7bf41327c74fc7
SHA1: 8333c9a15ad7b8a79237b924df9005812b0b27ec
SHA256: b53b5e4323877a2a243df43b3f3b5eeb02748ee80e0d9f010a0e9585f35e1271
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql40xx2i.pnf 9.68 KB (9908 bytes)MD5: 58e98db83fbfeb7301792321db60ebe5
SHA1: c4ef56ad20d1f9392c50e77ede58e13157cbaad9
SHA256: a3f29b82117dfd1893da2c52ee90f1a9d1ae6228bcc3e98b06e3e5a33568fb9f
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cmbatt.pnf 9.41 KB (9636 bytes)MD5: 72d5f7706d946face710b3384a3bd5fe
SHA1: 2ad1d13ad664bb106c4dde8a14533a337f1dcb69
SHA256: 0bf020671615d7909e5ca709c4e3a14bcf8db949a354629736380bfd5e5b9477
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\input.pnf 142.47 KB (145892 bytes)MD5: ceea6a3a28e766277dcc2c754c3da7a9
SHA1: 02ffa9f41834ffe4f9f369c20ff194b7e784c392
SHA256: 10e62a39d7413a87eddc1805832f4336aa2eb5879d22370913995f00d797b861
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000001.regtrans-ms 512.00 KB (524288 bytes)MD5: 78bb580446808b4e17992b29c68d308d
SHA1: cf8877eba13b2790149871abec5411acb89d0a56
SHA256: 5d0af58700c3ee7d81d98e13b19010c31933b2cdcedf4465ad53e89d98017597
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000001.regtrans-ms 512.00 KB (524288 bytes)MD5: 78bb580446808b4e17992b29c68d308d
SHA1: cf8877eba13b2790149871abec5411acb89d0a56
SHA256: 5d0af58700c3ee7d81d98e13b19010c31933b2cdcedf4465ad53e89d98017597
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umbus.pnf 9.67 KB (9904 bytes)MD5: 810010be4ec7fdf9cd46350e4b278355
SHA1: 9dca7edecd59ec388b0e3b9dbd2bc1def1113c37
SHA256: cbd177ca1695dda5bbfa8082fae78491ced69a9001cf6939be2468c9ee03480e
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf 12.30 KB (12596 bytes)MD5: a085f574aa7085b8cf7d1d13fc24f14d
SHA1: b5ebb92c5d30912ed9f7383a8235c4c79c346d9e
SHA256: 535b410d5d758acbea71f9780449757a6fd2ed1be045912a1f63d8113e711057
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbhub3.pnf 17.40 KB (17816 bytes)MD5: fa88958f77c7b06b94b903b0c167c826
SHA1: 74dbdcbdd769e9c6ab528045e1d6f2b8ecd2680e
SHA256: 4d8771840b44e8c79074508d539ceee708e34e71ae66bafa05138565ad458419
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ehstortcgdrv.pnf 7.59 KB (7768 bytes)MD5: ec0e144c257d1818500e7860a5eb6e53
SHA1: 1ad8c2bdf7df6eb7a84261d2c02760ca15cc36fe
SHA256: 00ea279d6c049fc4a5a4876fdea0ac4b7cd21f08e3117ffaa40ca614308fac72
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql2300.pnf 11.91 KB (12200 bytes)MD5: 0c1c17ad4c67889a3cd3f0d9ba124a63
SHA1: 6e4884d2b91266a68891646cc03f3bf2d67eba00
SHA256: 3fb0c9bd9f291dab031551f8dfefc33c09e626ffa6b06a3789fcd86832013152
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbstor.pnf 56.27 KB (57620 bytes)MD5: fa256ba8288fdd9d4fd8162ca35e1204
SHA1: df575db7846bf2f26caffb9c7c875f47897aef9e
SHA256: 356c923cf7b4f53881c981754712302cba73fcd7889f0ffce77a02b190015b16
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\volume.pnf 6.19 KB (6336 bytes)MD5: 0661cf512d8bc38ca3ddb2edffa4a3af
SHA1: 9e871f12040f831051bd83112aa571db63575ba8
SHA256: 2f5c1b56f232e564a8aedc000a07c168c806ddd241e8c2428ca11080fe916c4c
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\tpm.pnf 14.66 KB (15008 bytes)MD5: b3ddd68f33b4fc84e4e6e00c4c4977e3
SHA1: 12393985de8a52706bed6ad17f2d276a12bcde4f
SHA256: a4564d3defb32c11f9d621821de8a1734f9ce79f22c4e2583a0c59db5a2714a8
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msports.pnf 36.00 KB (36860 bytes)MD5: 4649eaec14108d770fcde9a63d470a03
SHA1: d486645998ac9896cd311f0a24e7cb9e04bcf36c
SHA256: c4003a02d27d896b0efa8134d32a58038e6fd2354f2521ca9f06beffdc95ae1d
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbport.pnf 136.06 KB (139324 bytes)MD5: 4c5f2d79ccadbcc6dc5ec96b8a9785e1
SHA1: a6692d6622b1e37017201de04229ead3ef27e403
SHA256: 969db08d55563962e5226e57d0ae9188b013c8ab8bfe2f5661c83507ca23ad9d
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\vstxraid.pnf 10.34 KB (10592 bytes)MD5: 7304944d73f7bab4df1ea31e198dc2c6
SHA1: 5175936c0b57e82939a6d740470a65badb8944eb
SHA256: 5383cab81ccdf2a0e5c010bfb95f1f73fee5aa206f28b547656f4cd2ab278f86
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf 9.90 KB (10140 bytes)MD5: b88aafdf5775449a5b6b77e3f56c737b
SHA1: feec758c3539200971e8429d803cf6af5d9070d7
SHA256: 9c017cdcdb3974f749f2c8b07a175823b06cf57e8e3f78d6b021e237a4fc535f
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf 67.99 KB (69624 bytes)MD5: dfd0ed3867d3a43ebcd24849386913d1
SHA1: 66b965c6d3be21c9edc769cbee8b330cd6206289
SHA256: 7b4b6012c373fc102c2b3943de0b4e13bdad3481d61b8213a57efb8925fa4366
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf 18.35 KB (18792 bytes)MD5: adc6b6528b885ff957911839db69cbe2
SHA1: bdb7044b54158b005129b9b10486079c4e060955
SHA256: b8f065a0894707522da3b497e90c7e3bf57501afcf16c1e1c96e26a4b1cce06e
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf 894.85 KB (916324 bytes)MD5: 61dc874f6580aae1b40dd05679045d62
SHA1: c3672715f73e246f087b57208783da4036df96ca
SHA256: c72d05f60617277399eac46647904a80da6b3b9c7151767809e2f88c2b699335
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mtconfig.pnf 7.45 KB (7632 bytes)MD5: 41a00f76e25ec68f62f260919889f87b
SHA1: eb6dffff887bda06ff7545a4521898773ba03590
SHA256: 5c8b8a82091220df55fff7836baeb9a11ea2eb18e8e76438324e03b1bc929b52
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorv.pnf 15.80 KB (16180 bytes)MD5: 71803429cd83bf1324dbdf64d09cfc64
SHA1: 8b2c2fc6c0ca8dd27dddb4f5efe5dfb16c9539cd
SHA256: 08902ee95a4fc39d1ba16c798b43f0e63ab8e82b3b1425e758c3cac61d725b02
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\fdc.pnf 6.00 KB (6148 bytes)MD5: f296bb6a6d5c830d0e3a9e3f7b26a4b9
SHA1: 760704b53ef2642cbfae94693ae02dc4f9786396
SHA256: 9bccfeb66d7b2428138b43aa3a72543f51a54ba304af0688ba5e1ae666098a02
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_gpio.pnf 7.89 KB (8084 bytes)MD5: 5e62f93fcc24f65c987a687dc9c32f9f
SHA1: d0bae0b2bade8584b1f47f0746381a735aaf1db9
SHA256: 899d4ae378e16e445cd2911fdc27e4de554675d6362e291397f701fe1072e355
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umpass.pnf 6.11 KB (6252 bytes)MD5: 6724aff7377facac08c967bbc98d5b6a
SHA1: e87187f06fe172334709c73f5b176d58edec6092
SHA256: 99c63cd3dd78bd79255978303989ecabaa2267f365d5fbcc2413978c0950fe1f
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxfcoe.pnf 11.47 KB (11744 bytes)MD5: 24407f7a809b08200bc3856b6ead38f2
SHA1: b7c973701240542f039a04b9d23c7b47f5e0e0f0
SHA256: 6a1bbfe839df2553b8a5c907a51bbf8c1875695604600642f903f9bbbd842f29
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\swenum.pnf 7.34 KB (7520 bytes)MD5: 4a40c5a21aaa9570778e2100f05905a4
SHA1: 7ba6ff6944dd2f74c198186aaf0e0878392ed03a
SHA256: bc3e973d1bf0dafefd9e3bfb71c363dd9b674b80efeeb04cba0ea688fbb0a1ef
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\disk.pnf 16.29 KB (16680 bytes)MD5: 1250eea5907f483d94f504b50e92b78c
SHA1: e7de6c9341f50037d763ff0b5368fdb9bfb3c5dd
SHA256: 3958a558ecaffb60ccadaad7cab012c262c4754bb5965451f00c62b5afec0154
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netevbda.pnf 119.88 KB (122760 bytes)MD5: 5e1a3bd4845a9ccbe630838693db7587
SHA1: 4dc87fc04ea071f7bece13d22acb6c22c3f050a2
SHA256: ff1794ea19970060dd75f59401d7ab738276f5f7d43504b19107e247a68eff65
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\spaceport.pnf 7.19 KB (7360 bytes)MD5: df62091305a3e5c5d244203a18a89dca
SHA1: 506ab944fb7e751cf9cfff7239dd487b63738a03
SHA256: 16f77bbb478f02db1c973df558a2b4fe6232adeb4a408d9035da99734998cd9c
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidi2c.pnf 8.84 KB (9048 bytes)MD5: d399e897be0e66932326f9740aa8807d
SHA1: 84e7e8cd02ad22b3c9cd32811770197a3afeeae9
SHA256: 6e6b0daf89cc03960a8f8f6f02c2f2dda57ee12e4008ccb5be1d70cfc9c073ba
Host Behavior
File (6743)
+
OperationFilenameAdditional InformationSuccessAmountLogfile
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\logfiles\scm\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTFalse1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTFalse1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue84
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue83
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\security\logs\scecomp.logdesired_access = FILE_READ_ATTRIBUTES, DELETE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_NON_DIRECTORY_FILE, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTFalse1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\security\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.datdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat.log1desired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat.log2desired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tm.blfdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000001.regtrans-msdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000002.regtrans-msdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tm.blfdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000001.regtrans-msdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000002.regtrans-msdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdatadesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\localdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\local\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\local\microsoftdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\local\microsoft\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\local\microsoft\windowsdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\local\microsoft\windows\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\gameexplorerdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\local\microsoft\windows\gameexplorer\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\historydesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\local\microsoft\windows\history\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\inetcachedesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\local\microsoft\windows\inetcache\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\inetcookiesdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\local\microsoft\windows\inetcookies\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\local\tempdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\local\temp\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roamingdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoftdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\microsoft\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windowsdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\microsoft\windows\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\network shortcutsdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\microsoft\windows\network shortcuts\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\recentdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\microsoft\windows\recent\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\sendtodesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\microsoft\windows\sendto\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menudesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\microsoft\windows\start menu\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programsdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\microsoft\windows\start menu\programs\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programs\accessoriesdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programs\accessories\desktop.inidesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programs\accessories\notepad.lnkdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programs\system toolsdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\microsoft\windows\start menu\programs\system tools\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programs\system tools\command prompt.lnkdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programs\system tools\desktop.inidesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\templatesdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\microsoft\windows\templates\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\desktopdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\desktop\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\documentsdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\documents\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\downloadsdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\downloads\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\favoritesdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\favorites\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\linksdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\links\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\musicdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\music\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\picturesdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\pictures\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\saved gamesdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\saved games\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\videosdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\videos\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue4
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue4
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.datdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat.log1desired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat.log2desired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tm.blfdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000001.regtrans-msdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000002.regtrans-msdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tm.blfdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000001.regtrans-msdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000002.regtrans-msdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdatadesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\localdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\local\microsoftdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\local\microsoft\windowsdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\gameexplorerdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\historydesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\inetcachedesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\inetcookiesdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\local\tempdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roamingdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoftdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windowsdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\network shortcutsdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\recentdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\sendtodesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menudesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programsdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programs\accessoriesdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programs\accessories\desktop.inidesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programs\accessories\notepad.lnkdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programs\system toolsdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programs\system tools\command prompt.lnkdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programs\system tools\desktop.inidesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\templatesdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\desktopdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\documentsdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\downloadsdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\favoritesdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\linksdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\musicdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\picturesdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\saved gamesdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\videosdesired_access = FILE_WRITE_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTTrue1
Fn
CREATE_DIRFalse3
Fn
CREATE_DIRTrue62
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\logfilesdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\logfiles\scm\desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATEFalse61
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATETrue254
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\1394.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nlsdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\acpi.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\acpipagr.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\acpitime.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\afd.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\machine.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\cpu.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True4
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\arcsas.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\mshdc.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\netbvbda.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\bcmfn2.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\bfe.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxfcoe.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxfcoe.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\bxfcoe.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxfcoe.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxois.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxois.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\bxois.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxois.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cdrom.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cdrom.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\cdrom.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cdrom.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cht4vx64.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cht4vx64.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\cht4vx64.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cht4vx64.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\clfs.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cmbatt.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cmbatt.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\cmbatt.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cmbatt.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\cryptsvc.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\combase.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\defragsvc.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\umpnpmgr.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wkssvc.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True6
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\dhcpcore.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\disk.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\disk.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\disk.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\disk.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\dnsapi.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\eapsvc.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netevbda.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netevbda.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\netevbda.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netevbda.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\efssvc.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\ehstorclass.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ehstortcgdrv.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ehstortcgdrv.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\ehstortcgdrv.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ehstortcgdrv.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\errdev.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\errdev.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\errdev.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\errdev.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wevtsvc.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\fdc.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\fdc.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\fdc.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\fdc.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\fileinfo.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\filetrace.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\flpydisk.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\flpydisk.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\flpydisk.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\flpydisk.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\fltmgr.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\fsdepends.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\fvevol.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\agp.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\agp.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\agp.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\agp.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\gpapi.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hdaudbus.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hdaudbus.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\hdaudbus.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hdaudbus.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidbatt.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidbatt.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\hidbatt.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidbatt.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidi2c.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidi2c.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\hidi2c.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidi2c.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\hidserv.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\input.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\input.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\input.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\input.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msmouse.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msmouse.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\msmouse.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msmouse.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_gpio.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_gpio.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\ialpssi_gpio.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_gpio.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_i2c.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_i2c.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\ialpssi_i2c.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_i2c.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorav.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorav.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\iastorav.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorav.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorv.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorv.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\iastorv.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorv.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mlx4_bus.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mlx4_bus.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\mlx4_bus.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mlx4_bus.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\ikeext.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iscsi.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iscsi.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\iscsi.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iscsi.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\keyboard.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\keyboard.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\keyboard.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\keyboard.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\keyboard.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\keyiso.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\srvsvc.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True3
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lmhsvc.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsm.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mlx4_bus.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True4
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msmouse.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True3
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\mountmgr.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\firewallapi.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\mshidkmdf.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\iscsidsc.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mssmbios.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mssmbios.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\mssmbios.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mssmbios.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mtconfig.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mtconfig.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\mtconfig.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mtconfig.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\mup.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\ndis.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\ndisvirtualbus.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\netbt.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\netlogon.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\netman.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\nlasvc.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\nsisvc.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\nsiproxy.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True3
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msports.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msports.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\msports.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msports.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\partmgr.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\pdc.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\polstore.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\umpo.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\profsvc.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql2300.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql2300.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\ql2300.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql2300.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql40xx2i.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql40xx2i.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\ql40xx2i.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql40xx2i.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\qlfcoei.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\qlfcoei.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\qlfcoei.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\qlfcoei.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\rasauto.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\rasmans.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\rpcepmap.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\sacsvr.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\samsrv.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sbp2.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sbp2.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\sbp2.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sbp2.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sdstor.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sdstor.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\sdstor.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sdstor.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msports.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\flpydisk.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\smphost.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\spaceport.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\spaceport.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\spaceport.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\spaceport.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\sstpsvc.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\stornvme.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\stornvme.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\stornvme.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\stornvme.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svsvc.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\swenum.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\swenum.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\swenum.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\swenum.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\swprv.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\systemeventsbrokerserver.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\tcpip.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\tpm.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\tpm.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\tpm.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\tpm.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\servicing\trustedinstaller.exedesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\agp.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uaspstor.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uaspstor.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\uaspstor.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uaspstor.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uefi.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uefi.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\uefi.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uefi.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umbus.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umbus.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\umbus.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umbus.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umpass.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umpass.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\umpass.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umpass.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usb.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usb.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\usb.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usb.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbport.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbport.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\usbport.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbport.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbport.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True3
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbhub3.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbhub3.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\usbhub3.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbhub3.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbstor.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbstor.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\usbstor.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbstor.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbxhci.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbxhci.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\usbxhci.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbxhci.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\vdrvroot.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\vdrvroot.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\vdrvroot.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\vdrvroot.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\vds.exedesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\verifierext.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\vmbusres.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\volmgr.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\volmgr.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\volmgr.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\volmgr.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\volmgrx.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\volume.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\volume.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\volume.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\volume.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\vssvc.exedesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\vstxraid.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\vstxraid.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\vstxraid.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\vstxraid.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\w32time.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hiddigi.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hiddigi.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\hiddigi.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hiddigi.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wbengine.exedesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\wdf01000.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winhttp.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wbem\wmisvc.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\wmiacpi.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\wmiacpi.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\wmiacpi.inf_locdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\wmiacpi.pnfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wbem\wmiapsrv.exedesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\ws2ifsl.sysdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\security\logs\scecomp.logdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\security\logs\scecomp.logdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservicedesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windowsdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofilesdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservicedesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\ntuser.datdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.datdesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\ntuser.dat.log1desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat.log1desired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\ntuser.dat.log2desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat.log2desired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tm.blfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tm.blfdesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000001.regtrans-msdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000001.regtrans-msdesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000002.regtrans-msdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000002.regtrans-msdesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tm.blfdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tm.blfdesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000001.regtrans-msdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000001.regtrans-msdesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000002.regtrans-msdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000002.regtrans-msdesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdatadesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\localdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\local\microsoftdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\local\microsoft\windowsdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\gameexplorerdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\historydesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\inetcachedesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\inetcookiesdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\local\tempdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roamingdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoftdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windowsdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\network shortcutsdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\recentdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\sendtodesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menudesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programsdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programs\accessoriesdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\desktop.inidesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programs\accessories\desktop.inidesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\notepad.lnkdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programs\accessories\notepad.lnkdesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programs\system toolsdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\microsoft\windows\start menu\programs\system tools\command prompt.lnkdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programs\system tools\command prompt.lnkdesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\microsoft\windows\start menu\programs\system tools\desktop.inidesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programs\system tools\desktop.inidesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\templatesdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\desktopdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\documentsdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\downloadsdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\favoritesdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\linksdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\musicdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\picturesdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\saved gamesdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\videosdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservicedesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.datdesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat.log1desired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat.log2desired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tm.blfdesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000001.regtrans-msdesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000002.regtrans-msdesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tm.blfdesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000001.regtrans-msdesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000002.regtrans-msdesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdatadesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\localdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\local\microsoftdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\local\microsoft\windowsdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\gameexplorerdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\historydesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\inetcachedesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\inetcookiesdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\local\tempdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roamingdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoftdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windowsdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\network shortcutsdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\recentdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\sendtodesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menudesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programsdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programs\accessoriesdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programs\accessories\desktop.inidesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programs\accessories\notepad.lnkdesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programs\system toolsdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programs\system tools\command prompt.lnkdesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programs\system tools\desktop.inidesired_access = FILE_READ_DATA, FILE_WRITE_DATA, FILE_APPEND_DATA, FILE_READ_EA, FILE_WRITE_EA, FILE_EXECUTE, FILE_DELETE_CHILD, FILE_READ_ATTRIBUTES, FILE_WRITE_ATTRIBUTES, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\templatesdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\desktopdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\documentsdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\downloadsdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\favoritesdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\linksdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\musicdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\picturesdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\saved gamesdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\videosdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
WRITETrue2134
Fn
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnfsize = 1True12
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnfsize = 14192True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnfsize = 246True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnfsize = 400True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnfsize = 1188True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnfsize = 1312True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnfsize = 1True20
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnfsize = 12True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnfsize = 7056True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnfsize = 250True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnfsize = 304True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnfsize = 744True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnfsize = 812True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnfsize = 1True24
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnfsize = 4972True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnfsize = 250True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnfsize = 208True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnfsize = 396True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnfsize = 420True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnfsize = 1True20
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnfsize = 5448True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnfsize = 250True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnfsize = 208True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnfsize = 444True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnfsize = 468True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnfsize = 1True24
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnfsize = 741276True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnfsize = 250True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnfsize = 2176True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnfsize = 53292True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnfsize = 59588True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnfsize = 1True14
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnfsize = 17988True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnfsize = 256True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnfsize = 848True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnfsize = 2304True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnfsize = 2756True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnfsize = 1True10
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnfsize = 43384True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnfsize = 256True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnfsize = 368True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnfsize = 5052True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnfsize = 5840True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnfsize = 1True14
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnfsize = 48332True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnfsize = 244True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnfsize = 1312True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnfsize = 5736True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnfsize = 6928True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnfsize = 1True24
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnfsize = 8044True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnfsize = 250True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnfsize = 544True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnfsize = 1068True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnfsize = 1268True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnfsize = 1True20
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnfsize = 5004True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnfsize = 250True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnfsize = 208True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnfsize = 432True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnfsize = 484True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxfcoe.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxfcoe.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxfcoe.pnfsize = 1True10
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxfcoe.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxfcoe.pnfsize = 8264True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxfcoe.pnfsize = 260True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxfcoe.pnfsize = 304True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxfcoe.pnfsize = 840True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxfcoe.pnfsize = 968True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxois.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxois.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxois.pnfsize = 1True14
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxois.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxois.pnfsize = 12292True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxois.pnfsize = 260True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxois.pnfsize = 304True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxois.pnfsize = 1344True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxois.pnfsize = 1568True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cdrom.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cdrom.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cdrom.pnfsize = 1True14
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cdrom.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cdrom.pnfsize = 9164True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cdrom.pnfsize = 248True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cdrom.pnfsize = 496True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cdrom.pnfsize = 936True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cdrom.pnfsize = 1204True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cht4vx64.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cht4vx64.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cht4vx64.pnfsize = 1True20
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cht4vx64.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cht4vx64.pnfsize = 15776True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cht4vx64.pnfsize = 250True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cht4vx64.pnfsize = 592True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cht4vx64.pnfsize = 2388True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cht4vx64.pnfsize = 3276True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cmbatt.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cmbatt.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cmbatt.pnfsize = 1True18
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cmbatt.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cmbatt.pnfsize = 6720True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cmbatt.pnfsize = 252True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cmbatt.pnfsize = 304True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cmbatt.pnfsize = 684True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cmbatt.pnfsize = 764True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\disk.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\disk.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\disk.pnfsize = 1True6
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\disk.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\disk.pnfsize = 11832True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\disk.pnfsize = 256True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\disk.pnfsize = 544True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\disk.pnfsize = 1128True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\disk.pnfsize = 1392True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netevbda.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netevbda.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netevbda.pnfsize = 1True16
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netevbda.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netevbda.pnfsize = 68172True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netevbda.pnfsize = 250True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netevbda.pnfsize = 7296True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netevbda.pnfsize = 14016True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netevbda.pnfsize = 16440True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ehstortcgdrv.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ehstortcgdrv.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ehstortcgdrv.pnfsize = 1True16
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ehstortcgdrv.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ehstortcgdrv.pnfsize = 5660True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ehstortcgdrv.pnfsize = 286True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ehstortcgdrv.pnfsize = 224True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ehstortcgdrv.pnfsize = 444True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ehstortcgdrv.pnfsize = 504True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\errdev.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\errdev.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\errdev.pnfsize = 1True16
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\errdev.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\errdev.pnfsize = 6096True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\errdev.pnfsize = 250True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\errdev.pnfsize = 208True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\errdev.pnfsize = 624True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\errdev.pnfsize = 652True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\fdc.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\fdc.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\fdc.pnfsize = 1True18
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\fdc.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\fdc.pnfsize = 4528True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\fdc.pnfsize = 244True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\fdc.pnfsize = 208True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\fdc.pnfsize = 324True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\fdc.pnfsize = 348True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\flpydisk.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\flpydisk.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\flpydisk.pnfsize = 1True20
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\flpydisk.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\flpydisk.pnfsize = 6460True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\flpydisk.pnfsize = 258True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\flpydisk.pnfsize = 320True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\flpydisk.pnfsize = 744True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\flpydisk.pnfsize = 868True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\agp.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\agp.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\agp.pnfsize = 1True12
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\agp.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\agp.pnfsize = 10448True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\agp.pnfsize = 250True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\agp.pnfsize = 336True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\agp.pnfsize = 1224True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\agp.pnfsize = 1504True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hdaudbus.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hdaudbus.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hdaudbus.pnfsize = 1True16
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hdaudbus.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hdaudbus.pnfsize = 6628True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hdaudbus.pnfsize = 278True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hdaudbus.pnfsize = 288True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hdaudbus.pnfsize = 588True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hdaudbus.pnfsize = 664True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidbatt.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidbatt.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidbatt.pnfsize = 1True10
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidbatt.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidbatt.pnfsize = 5400True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidbatt.pnfsize = 252True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidbatt.pnfsize = 208True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidbatt.pnfsize = 432True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidbatt.pnfsize = 456True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidi2c.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidi2c.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidi2c.pnfsize = 1True12
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidi2c.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidi2c.pnfsize = 6580True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidi2c.pnfsize = 254True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidi2c.pnfsize = 288True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidi2c.pnfsize = 552True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidi2c.pnfsize = 616True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\input.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\input.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\input.pnfsize = 1True16
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\input.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\input.pnfsize = 110836True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\input.pnfsize = 254True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\input.pnfsize = 1552True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\input.pnfsize = 9816True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\input.pnfsize = 11644True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msmouse.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msmouse.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msmouse.pnfsize = 1True14
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msmouse.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msmouse.pnfsize = 66548True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msmouse.pnfsize = 248True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msmouse.pnfsize = 1520True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msmouse.pnfsize = 7020True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msmouse.pnfsize = 8520True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_gpio.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_gpio.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_gpio.pnfsize = 1True20
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_gpio.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_gpio.pnfsize = 6008True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_gpio.pnfsize = 266True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_gpio.pnfsize = 256True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_gpio.pnfsize = 420True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_gpio.pnfsize = 492True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_i2c.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_i2c.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_i2c.pnfsize = 1True16
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_i2c.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_i2c.pnfsize = 6496True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_i2c.pnfsize = 266True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_i2c.pnfsize = 256True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_i2c.pnfsize = 468True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_i2c.pnfsize = 544True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorav.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorav.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorav.pnfsize = 1True18
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorav.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorav.pnfsize = 8832True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorav.pnfsize = 276True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorav.pnfsize = 304True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorav.pnfsize = 756True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorav.pnfsize = 876True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorv.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorv.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorv.pnfsize = 1True22
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorv.pnfsize = 12True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorv.pnfsize = 9896True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorv.pnfsize = 252True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorv.pnfsize = 432True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorv.pnfsize = 1524True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorv.pnfsize = 1956True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mlx4_bus.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mlx4_bus.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mlx4_bus.pnfsize = 1True24
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mlx4_bus.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mlx4_bus.pnfsize = 31284True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mlx4_bus.pnfsize = 250True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mlx4_bus.pnfsize = 400True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mlx4_bus.pnfsize = 3324True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mlx4_bus.pnfsize = 4044True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iscsi.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iscsi.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iscsi.pnfsize = 1True10
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iscsi.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iscsi.pnfsize = 7312True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iscsi.pnfsize = 260True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iscsi.pnfsize = 288True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iscsi.pnfsize = 864True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iscsi.pnfsize = 1096True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\keyboard.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\keyboard.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\keyboard.pnfsize = 1True8
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\keyboard.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\keyboard.pnfsize = 88768True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\keyboard.pnfsize = 254True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\keyboard.pnfsize = 2064True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\keyboard.pnfsize = 9192True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\keyboard.pnfsize = 11192True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mssmbios.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mssmbios.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mssmbios.pnfsize = 1True16
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mssmbios.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mssmbios.pnfsize = 5676True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mssmbios.pnfsize = 250True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mssmbios.pnfsize = 208True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mssmbios.pnfsize = 480True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mssmbios.pnfsize = 504True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mtconfig.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mtconfig.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mtconfig.pnfsize = 1True20
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mtconfig.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mtconfig.pnfsize = 5620True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mtconfig.pnfsize = 282True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mtconfig.pnfsize = 272True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mtconfig.pnfsize = 396True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mtconfig.pnfsize = 456True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msports.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msports.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msports.pnfsize = 1True10
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msports.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msports.pnfsize = 21872True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msports.pnfsize = 248True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msports.pnfsize = 1360True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msports.pnfsize = 3648True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msports.pnfsize = 4796True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql2300.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql2300.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql2300.pnfsize = 1True12
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql2300.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql2300.pnfsize = 8332True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql2300.pnfsize = 254True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql2300.pnfsize = 432True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql2300.pnfsize = 912True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql2300.pnfsize = 1064True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql40xx2i.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql40xx2i.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql40xx2i.pnfsize = 1True16
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql40xx2i.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql40xx2i.pnfsize = 7104True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql40xx2i.pnfsize = 254True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql40xx2i.pnfsize = 320True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql40xx2i.pnfsize = 636True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql40xx2i.pnfsize = 724True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\qlfcoei.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\qlfcoei.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\qlfcoei.pnfsize = 1True12
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\qlfcoei.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\qlfcoei.pnfsize = 7740True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\qlfcoei.pnfsize = 254True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\qlfcoei.pnfsize = 384True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\qlfcoei.pnfsize = 792True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\qlfcoei.pnfsize = 952True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sbp2.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sbp2.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sbp2.pnfsize = 1True16
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sbp2.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sbp2.pnfsize = 5672True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sbp2.pnfsize = 274True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sbp2.pnfsize = 240True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sbp2.pnfsize = 384True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sbp2.pnfsize = 428True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sdstor.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sdstor.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sdstor.pnfsize = 1True16
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sdstor.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sdstor.pnfsize = 6592True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sdstor.pnfsize = 290True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sdstor.pnfsize = 320True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sdstor.pnfsize = 528True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sdstor.pnfsize = 828True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\spaceport.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\spaceport.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\spaceport.pnfsize = 1True10
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\spaceport.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\spaceport.pnfsize = 5408True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\spaceport.pnfsize = 260True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\spaceport.pnfsize = 272True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\spaceport.pnfsize = 384True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\spaceport.pnfsize = 448True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\stornvme.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\stornvme.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\stornvme.pnfsize = 1True6
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\stornvme.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\stornvme.pnfsize = 7552True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\stornvme.pnfsize = 288True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\stornvme.pnfsize = 304True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\stornvme.pnfsize = 792True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\stornvme.pnfsize = 928True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\swenum.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\swenum.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\swenum.pnfsize = 1True16
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\swenum.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\swenum.pnfsize = 5460True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\swenum.pnfsize = 250True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\swenum.pnfsize = 288True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\swenum.pnfsize = 432True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\swenum.pnfsize = 472True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\tpm.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\tpm.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\tpm.pnfsize = 1True6
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\tpm.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\tpm.pnfsize = 9704True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\tpm.pnfsize = 296True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\tpm.pnfsize = 720True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\tpm.pnfsize = 1200True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\tpm.pnfsize = 1464True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\tpm.pnfsize = 24True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uaspstor.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uaspstor.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uaspstor.pnfsize = 1True18
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uaspstor.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uaspstor.pnfsize = 6000True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uaspstor.pnfsize = 260True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uaspstor.pnfsize = 304True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uaspstor.pnfsize = 444True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uaspstor.pnfsize = 524True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uefi.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uefi.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uefi.pnfsize = 1True16
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uefi.pnfsize = 12True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uefi.pnfsize = 5992True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uefi.pnfsize = 250True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uefi.pnfsize = 240True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uefi.pnfsize = 540True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uefi.pnfsize = 584True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umbus.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umbus.pnfsize = 22True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umbus.pnfsize = 1True16
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umbus.pnfsize = 12True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umbus.pnfsize = 7204True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umbus.pnfsize = 278True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umbus.pnfsize = 352True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umbus.pnfsize = 564True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umbus.pnfsize = 680True2
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umpass.pnfsize = 96True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umpass.pnfsize = 22True1
Fn
Data
For performance reasons, the remaining 159 entries are omitted.
Click to download all 1159 entries as text file (0.85 MB).
Process (381)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
CREATETrue3
Fn
CREATEdesired_access = MAXIMUM_ALLOWEDTrue3
Fn
OPEN_TOKENTrue4
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True357
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFOTrue6
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFOTrue1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySideTrue2
Fn
Memory (9)
+
OperationAddressAdditional InformationSuccessAmountLogfile
ALLOC0x94cff3ebf8process_name = , size = 639144029528, allocation_type = MEM_COMMIT, protection = PAGE_READWRITETrue1
Fn
ALLOC0x94cff3ec38process_name = , size = 639144029592, allocation_type = MEM_COMMIT, protection = PAGE_READWRITETrue2
Fn
WRITE0xaee6a50000process_name = , size = 4704True1
Fn
Data
WRITE0x7ff7c98a62d8process_name = , size = 8True1
Fn
Data
WRITE0xf0520d0000process_name = , size = 4704True1
Fn
Data
WRITE0x7ff7ca3032d8process_name = , size = 8True1
Fn
Data
WRITE0x2060980000process_name = , size = 4704True1
Fn
Data
WRITE0x7ff7c99e92d8process_name = , size = 8True1
Fn
Data
Thread (3)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
RESUMETrue3
Fn
Module (993)
+
OperationModuleAdditional InformationSuccessAmountLogfile
LOADbase_address = 0x7ffb70a10000True1
Fn
LOADX:\windows\system32\scext.dllFalse1
Fn
LOADkernel32.dllbase_address = 0x0True1
Fn
LOADrpcrt4.dllbase_address = 0x0True1
Fn
LOADsspicli.dllbase_address = 0x0True2
Fn
LOADbase_address = 0x7ffb71500000True1
Fn
GET_HANDLE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exeTrue13
Fn
GET_HANDLErpcrt4.dllTrue2
Fn
GET_HANDLEkernelbase.dllTrue1
Fn
GET_HANDLEntdll.dllTrue2
Fn
CREATE_MAPPINGNameless FileMappingTrue145
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\1394.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\acpi.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\acpipagr.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\acpitime.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\afd.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\machine.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\cpu.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, maximum_size = 639144024192, protection = PAGE_READONLYTrue4
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\arcsas.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\mshdc.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\netbvbda.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\bcmfn2.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\bfe.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxfcoe.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\bxfcoe.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxois.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\bxois.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cdrom.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\cdrom.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cht4vx64.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\cht4vx64.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\clfs.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cmbatt.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\cmbatt.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\cryptsvc.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\combase.dll, maximum_size = 0, protection = PAGE_READONLYTrue2
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\defragsvc.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\umpnpmgr.dll, maximum_size = 0, protection = PAGE_READONLYTrue2
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wkssvc.dll, maximum_size = 0, protection = PAGE_READONLYTrue6
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\dhcpcore.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\disk.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\disk.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\dnsapi.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\eapsvc.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netevbda.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\netevbda.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\efssvc.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\ehstorclass.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ehstortcgdrv.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\ehstortcgdrv.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\errdev.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\errdev.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wevtsvc.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\fdc.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\fdc.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\fileinfo.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\filetrace.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\flpydisk.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\flpydisk.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\fltmgr.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\fsdepends.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\fvevol.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\agp.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\agp.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\gpapi.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hdaudbus.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\hdaudbus.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidbatt.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\hidbatt.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidi2c.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\hidi2c.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\hidserv.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\input.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\input.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msmouse.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\msmouse.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_gpio.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\ialpssi_gpio.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_i2c.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\ialpssi_i2c.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorav.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\iastorav.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorv.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\iastorv.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mlx4_bus.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\mlx4_bus.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\ikeext.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iscsi.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\iscsi.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\keyboard.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\keyboard.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\keyboard.pnf, maximum_size = 639144024192, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\keyiso.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\srvsvc.dll, maximum_size = 0, protection = PAGE_READONLYTrue3
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lmhsvc.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsm.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mlx4_bus.pnf, maximum_size = 639144024192, protection = PAGE_READONLYTrue4
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msmouse.pnf, maximum_size = 639144024192, protection = PAGE_READONLYTrue3
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\mountmgr.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\firewallapi.dll, maximum_size = 0, protection = PAGE_READONLYTrue2
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\mshidkmdf.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\iscsidsc.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mssmbios.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\mssmbios.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mtconfig.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\mtconfig.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\mup.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\ndis.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\ndisvirtualbus.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\netbt.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\netlogon.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\netman.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\nlasvc.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\nsisvc.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\nsiproxy.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, maximum_size = 639144024192, protection = PAGE_READONLYTrue3
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msports.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\msports.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\partmgr.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\pdc.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\polstore.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\umpo.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\profsvc.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql2300.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\ql2300.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql40xx2i.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\ql40xx2i.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\qlfcoei.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\qlfcoei.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\rasauto.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\rasmans.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\rpcepmap.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\sacsvr.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\samsrv.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sbp2.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\sbp2.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sdstor.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\sdstor.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msports.pnf, maximum_size = 639144024192, protection = PAGE_READONLYTrue2
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\flpydisk.pnf, maximum_size = 639144024192, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\smphost.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\spaceport.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\spaceport.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\sstpsvc.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, maximum_size = 639144024192, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\stornvme.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\stornvme.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svsvc.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\swenum.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\swenum.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\swprv.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\systemeventsbrokerserver.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\tcpip.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\tpm.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\tpm.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\servicing\trustedinstaller.exe, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\agp.pnf, maximum_size = 639144024192, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uaspstor.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\uaspstor.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uefi.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\uefi.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umbus.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\umbus.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umpass.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\umpass.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usb.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\usb.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbport.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\usbport.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbport.pnf, maximum_size = 639144024192, protection = PAGE_READONLYTrue3
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbhub3.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\usbhub3.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbstor.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\usbstor.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbxhci.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\usbxhci.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\vdrvroot.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\vdrvroot.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\vds.exe, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\verifierext.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\vmbusres.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\volmgr.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\volmgr.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\volmgrx.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\volume.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\volume.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\vssvc.exe, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\vstxraid.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\vstxraid.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\w32time.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hiddigi.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\hiddigi.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wbengine.exe, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\wdf01000.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winhttp.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wbem\wmisvc.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\wmiacpi.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\wmiacpi.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wbem\wmiapsrv.exe, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\ws2ifsl.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exeos_pid = 0x1ac, address = 0x94cfff0000True141
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True13
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True66
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d01c0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True19
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xfe90000False1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exeos_pid = 0x1ac, address = 0x94d04a0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d04a0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True3
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True5
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True2
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d07a0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xfe90000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d07a0000False2
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d07a0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False3
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False6
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d0050000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True6
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d07a0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xfe90000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d07a0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xfe90000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xfe90000False2
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xfe90000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xfe90000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xfe90000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True3
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d07a0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d0050000False3
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d07a0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True5
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True3
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xfe90000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d07a0000False2
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xfe90000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xfe90000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xfe90000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xfe90000False2
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xfe90000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d07a0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d0050000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exeos_pid = 0x1ac, address = 0x94d07a0000True3
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d07a0000True3
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True4
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xfe90000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xfe90000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d0050000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False2
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d07a0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d07a0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False2
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d07a0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xfe90000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True3
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d07a0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xfe90000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xfe90000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d07a0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d0050000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d07a0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xfe90000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d07a0000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000False1
Fn
UNMAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exeos_pid = 0x1acTrue145
Fn
UNMAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, base_address = 0xfe90000True22
Fn
UNMAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, base_address = 0x94d07a0000True18
Fn
UNMAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, base_address = 0x94cfff0000True31
Fn
UNMAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, base_address = 0x94d0050000True7
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70a14450True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb73af9360True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb73a7f1a0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb7177b660True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb7415d1b0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb7416bc00True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb74174670True1
Fn
Service (6)
+
OperationServiceAdditional InformationSuccessAmountLogfile
OPEN_MGRSERVICES_ACTIVE_DATABASEhost = LocalhostTrue1
Fn
OPENTrue1
Fn
GET_INFOtype = StatusTrue4
Fn
Registry (1380)
+
OperationKeyAdditional InformationSuccessAmountLogfile
CREATE_KEY\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7EFalse1
Fn
CREATE_KEY\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1True1
Fn
CREATE_KEY\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\Software\Classes\Local Settings\MuiCache\1\52C64B7ETrue1
Fn
CREATE_KEYTrue4
Fn
CREATE_KEYSoftware\Microsoft\SystemCertificatesTrue2
Fn
CREATE_KEYSoftware\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20True1
Fn
CREATE_KEYSoftware\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19True1
Fn
OPEN_KEYFalse26
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue10
Fn
OPEN_KEY\Registry\Machine\System\SetupTrue5
Fn
OPEN_KEYTrue435
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\VersionsTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocaleTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocaleTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\IdsTrue1
Fn
OPEN_KEY\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettingsTrue79
Fn
OPEN_KEY\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7EFalse1
Fn
OPEN_KEY\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCacheTrue1
Fn
OPEN_KEY\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\Software\Classes\Local Settings\MuiCache\1\52C64B7EFalse1
Fn
OPEN_KEYControl Panel\InternationalTrue1
Fn
OPEN_KEY\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7ETrue78
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\LocaleTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Locale\Alternate SortsTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Language GroupsTrue1
Fn
OPEN_KEY\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDllsFalse1
Fn
OPEN_KEY\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\OptionFalse1
Fn
OPEN_KEY\Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySideTrue3
Fn
OPEN_KEY\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNamevalue_name = ComputerNameTrue10
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = OOBEInProgressFalse1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = SystemSetupInProgressTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versionsvalue_name = 639144026960True1
Fn
READ_VALUEFalse15
Fn
READ_VALUEvalue_name = RpcCacheTimeoutFalse1
Fn
READ_VALUEvalue_name = EnableTakeOwnershipEventFalse1
Fn
READ_VALUEvalue_name = RpcOverTcpKeepAliveTimesFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocalevalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocalevalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versionsvalue_name = 000602xxTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Idsvalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Idsvalue_name = enFalse1
Fn
READ_VALUETrue165
Fn
READ_VALUEvalue_name = DisplayNameTrue79
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettingsvalue_name = StringCacheGenerationTrue79
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\drivers\afd.sys,-1000False1
Fn
READ_VALUEControl Panel\InternationalFalse1
Fn
READ_VALUEControl Panel\InternationalTrue1
Fn
READ_VALUEControl Panel\Internationalvalue_name = sCurrencyOverrideFalse1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\bfe.dll,-1001False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\clfs.sys,-100False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\cryptsvc.dll,-1001False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @combase.dll,-5012False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\defragsvc.dll,-101False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\umpnpmgr.dll,-100False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\wkssvc.dll,-1008False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\dhcpcore.dll,-100False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\System32\dnsapi.dll,-101False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\eapsvc.dll,-1False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\efssvc.dll,-100False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\EhStorClass.sys,-100False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\wevtsvc.dll,-200False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\fileinfo.sys,-100False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\filetrace.sys,-10001False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\fltmgr.sys,-10001False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\fsdepends.sys,-10001False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\fvevol.sys,-100False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @gpapi.dll,-112False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\System32\hidserv.dll,-101False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\ikeext.dll,-501False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @keyiso.dll,-100False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\srvsvc.dll,-100False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\wkssvc.dll,-100False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\lmhsvc.dll,-101False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%windir%\system32\lsm.dll,-1001False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\mountmgr.sys,-100False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\FirewallAPI.dll,-23092False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\FirewallAPI.dll,-23090False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\wkssvc.dll,-1002False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\wkssvc.dll,-1004False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\wkssvc.dll,-1006False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\mshidkmdf.sys,-100False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\iscsidsc.dll,-5000False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\drivers\mup.sys,-101False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\ndis.sys,-200False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\System32\drivers\NdisVirtualBus.sys,-200False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\netbt.sys,-2False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\System32\netlogon.dll,-102False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\netman.dll,-109False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\System32\nlasvc.dll,-1False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\nsisvc.dll,-200False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\nsiproxy.sys,-2False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\partmgr.sys,-100False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\pdc.sys,-100False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\umpnpmgr.dll,-200False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\System32\polstore.dll,-5010False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\umpo.dll,-100False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\profsvc.dll,-300False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%Systemroot%\system32\rasauto.dll,-200False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%Systemroot%\system32\rasmans.dll,-200False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\wkssvc.dll,-1000False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%windir%\system32\RpcEpMap.dll,-1001False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @combase.dll,-5010False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\sacsvr.dll,-500False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\samsrv.dll,-1False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\System32\smphost.dll,-102False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\srvsvc.dll,-102False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\srvsvc.dll,-104False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\sstpsvc.dll,-200False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\svsvc.dll,-101False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\System32\swprv.dll,-103False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%windir%\system32\SystemEventsBrokerServer.dll,-1001False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\tcpip.sys,-10001False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\servicing\TrustedInstaller.exe,-100False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\vds.exe,-100False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\VerifierExt.sys,-1000False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\vmbusres.dll,-1000False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\volmgrx.sys,-100False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\vssvc.exe,-102False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\w32time.dll,-200False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\wbengine.exe,-104False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\Wdf01000.sys,-1000False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\winhttp.dll,-100False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%Systemroot%\system32\wbem\wmisvc.dll,-205False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%Systemroot%\system32\wbem\wmiapsrv.exe,-110False1
Fn
READ_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\System32\drivers\ws2ifsl.sys,-1000False1
Fn
READ_VALUEvalue_name = MaxRpcSizeFalse1
Fn
READ_VALUEvalue_name = IdleTimerWindowFalse1
Fn
READ_VALUEvalue_name = ServicesPipeTimeoutFalse1
Fn
READ_VALUEvalue_name = HandlerTimeoutFalse1
Fn
READ_VALUEvalue_name = DisableRemoteScmEndpointsFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Localevalue_name = 00000409True1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Language Groupsvalue_name = 1True1
Fn
READ_VALUEvalue_name = PolicyDebugLevelFalse1
Fn
READ_VALUEvalue_name = PolicyLogSizeFalse1
Fn
READ_VALUEvalue_name = 10True1
Fn
READ_VALUEvalue_name = SecurityProvidersFalse1
Fn
READ_VALUEvalue_name = CopyFileBufferedSynchronousIoFalse1
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\security\value_name = FatNtfsConvertedDrivesFalse1
Fn
READ_VALUEvalue_name = ProgramDataTrue2
Fn
READ_VALUEvalue_name = PublicTrue2
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNamevalue_name = DefaultTrue6
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNamevalue_name = ProgramFilesDirTrue6
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNamevalue_name = CommonFilesDirTrue6
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNamevalue_name = ProgramFilesDir (x86)True6
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNamevalue_name = CommonFilesDir (x86)True6
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNamevalue_name = ProgramW6432DirTrue6
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNamevalue_name = CommonW6432DirTrue6
Fn
READ_VALUEvalue_name = ProfileImagePathTrue6
Fn
READ_VALUEvalue_name = AppDataTrue2
Fn
READ_VALUEvalue_name = Local AppDataTrue2
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = 140717948767312False1
Fn
READ_VALUE\Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySidevalue_name = PreferExternalManifestFalse3
Fn
READ_VALUEvalue_name = SQMServiceListTrue1
Fn
READ_VALUEvalue_name = ServiceStartTimeoutFalse1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRvalue_name = DisableTrue1
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservicevalue_name = DefaultTrue2
Fn
READ_VALUESoftware\Microsoft\SystemCertificatesvalue_name = ProgramDataTrue4
Fn
READ_VALUESoftware\Microsoft\SystemCertificatesvalue_name = PublicTrue4
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\value_name = ProfileImagePathTrue2
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\value_name = AppDataTrue2
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\microsoft\value_name = ProfileImagePathTrue4
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\microsoft\value_name = Local AppDataTrue2
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\microsoft\windows\value_name = ProfileImagePathTrue4
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = ShimEnableFalse2
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\microsoft\windows\start menu\programs\value_name = SystemUpdateOnBootFalse1
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservicevalue_name = DefaultTrue2
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\microsoft\value_name = AppDataTrue2
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\microsoft\windows\value_name = Local AppDataTrue2
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\users\default\appdata\roaming\microsoft\windows\templates\value_name = ProfileImagePathTrue2
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = LanguageList, data = en-USTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\drivers\afd.sys,-1000, data = Ancillary Function Driver for WinsockTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = LanguageList, data = en-USTrue78
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\bfe.dll,-1001, data = Base Filtering EngineTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\clfs.sys,-100, data = Common Log (CLFS)True1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\cryptsvc.dll,-1001, data = Cryptographic ServicesTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @combase.dll,-5012, data = DCOM Server Process LauncherTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\defragsvc.dll,-101, data = Optimize drivesTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\umpnpmgr.dll,-100, data = Device Install ServiceTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\wkssvc.dll,-1008, data = DFS Namespace Client DriverTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\dhcpcore.dll,-100, data = DHCP ClientTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\System32\dnsapi.dll,-101, data = DNS ClientTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\eapsvc.dll,-1, data = Extensible Authentication ProtocolTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\efssvc.dll,-100, data = Encrypting File System (EFS)True1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\EhStorClass.sys,-100, data = Enhanced Storage Filter DriverTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\wevtsvc.dll,-200, data = Windows Event LogTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\fileinfo.sys,-100, data = File Information FS MiniFilterTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\filetrace.sys,-10001, data = FileTraceTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\fltmgr.sys,-10001, data = FltMgrTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\fsdepends.sys,-10001, data = File System Dependency MinifilterTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\fvevol.sys,-100, data = BitLocker Drive Encryption Filter DriverTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @gpapi.dll,-112, data = Group Policy ClientTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\System32\hidserv.dll,-101, data = Human Interface Device ServiceTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\ikeext.dll,-501, data = IKE and AuthIP IPsec Keying ModulesTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @keyiso.dll,-100, data = CNG Key IsolationTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\srvsvc.dll,-100, data = ServerTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\wkssvc.dll,-100, data = WorkstationTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\lmhsvc.dll,-101, data = TCP/IP NetBIOS HelperTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%windir%\system32\lsm.dll,-1001, data = Local Session ManagerTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\mountmgr.sys,-100, data = Mount Point ManagerTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\FirewallAPI.dll,-23092, data = Windows Firewall Authorization DriverTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\FirewallAPI.dll,-23090, data = Windows FirewallTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\wkssvc.dll,-1002, data = SMB MiniRedirector Wrapper and EngineTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\wkssvc.dll,-1004, data = SMB 1.x MiniRedirectorTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\wkssvc.dll,-1006, data = SMB 2.0 MiniRedirectorTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\mshidkmdf.sys,-100, data = Pass-through HID to KMDF Filter DriverTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\iscsidsc.dll,-5000, data = Microsoft iSCSI Initiator ServiceTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\drivers\mup.sys,-101, data = MUPTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\ndis.sys,-200, data = NDIS System DriverTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\System32\drivers\NdisVirtualBus.sys,-200, data = Microsoft Virtual Network Adapter EnumeratorTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\netbt.sys,-2, data = NETBTTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\System32\netlogon.dll,-102, data = NetlogonTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\netman.dll,-109, data = Network ConnectionsTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\System32\nlasvc.dll,-1, data = Network Location AwarenessTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\nsisvc.dll,-200, data = Network Store Interface ServiceTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\nsiproxy.sys,-2, data = NSI Proxy Service DriverTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\partmgr.sys,-100, data = Partition ManagerTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\pdc.sys,-100, data = PDCTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\umpnpmgr.dll,-200, data = Plug and PlayTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\System32\polstore.dll,-5010, data = IPsec Policy AgentTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\umpo.dll,-100, data = PowerTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\profsvc.dll,-300, data = User Profile ServiceTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%Systemroot%\system32\rasauto.dll,-200, data = Remote Access Auto Connection ManagerTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%Systemroot%\system32\rasmans.dll,-200, data = Remote Access Connection ManagerTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\wkssvc.dll,-1000, data = Redirected Buffering Sub SystemTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%windir%\system32\RpcEpMap.dll,-1001, data = RPC Endpoint MapperTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @combase.dll,-5010, data = Remote Procedure Call (RPC)True1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\sacsvr.dll,-500, data = Special Administration Console HelperTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\samsrv.dll,-1, data = Security Accounts ManagerTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\System32\smphost.dll,-102, data = Microsoft Storage Spaces SMPTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\srvsvc.dll,-102, data = Server SMB 1.xxx DriverTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\srvsvc.dll,-104, data = Server SMB 2.xxx DriverTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\sstpsvc.dll,-200, data = Secure Socket Tunneling Protocol ServiceTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\svsvc.dll,-101, data = Spot VerifierTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\System32\swprv.dll,-103, data = Microsoft Software Shadow Copy ProviderTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%windir%\system32\SystemEventsBrokerServer.dll,-1001, data = System Events BrokerTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\tcpip.sys,-10001, data = TCP/IP Protocol DriverTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\servicing\TrustedInstaller.exe,-100, data = Windows Modules InstallerTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\vds.exe,-100, data = Virtual DiskTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\vmbusres.dll,-1000, data = Virtual Machine BusTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\volmgrx.sys,-100, data = Dynamic Volume ManagerTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\vssvc.exe,-102, data = Volume Shadow CopyTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\w32time.dll,-200, data = Windows TimeTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\system32\wbengine.exe,-104, data = Block Level Backup Engine ServiceTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\drivers\Wdf01000.sys,-1000, data = Kernel Mode Driver Frameworks serviceTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%SystemRoot%\system32\winhttp.dll,-100, data = WinHTTP Web Proxy Auto-Discovery ServiceTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%Systemroot%\system32\wbem\wmisvc.dll,-205, data = Windows Management InstrumentationTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%Systemroot%\system32\wbem\wmiapsrv.exe,-110, data = WMI Performance AdapterTrue1
Fn
WRITE_VALUE\Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7Evalue_name = @%systemroot%\System32\drivers\ws2ifsl.sys,-1000, data = Winsock IFS DriverTrue1
Fn
WRITE_VALUETrue6
Fn
WRITE_VALUESoftware\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20value_name = ProfileImagePath, data = X:\windows\ServiceProfiles\NetworkServiceTrue1
Fn
WRITE_VALUESoftware\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20value_name = Flags, data = 0True1
Fn
WRITE_VALUESoftware\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20value_name = State, data = 0True1
Fn
WRITE_VALUESoftware\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19value_name = ProfileImagePath, data = X:\windows\ServiceProfiles\LocalServiceTrue1
Fn
WRITE_VALUESoftware\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19value_name = Flags, data = 0True1
Fn
WRITE_VALUESoftware\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19value_name = State, data = 0True1
Fn
Driver (4)
+
OperationDriverAdditional InformationSuccessAmountLogfile
CONTROLTrue1
Fn
CONTROLcontrol_code = 0x390008True1
Fn
CONTROLcontrol_code = 0x110008False2
Fn
User (3)
+
OperationUser/Group/ServerAdditional InformationSuccessAmountLogfile
SET_PRIVILEGELocalhostTrue3
Fn
System (735)
+
OperationInformationSuccessAmountLogfile
SLEEPTrue363
Fn
SLEEPduration = 1 milliseconds (0.001 seconds)True359
Fn
SLEEPduration = 639153338176 milliseconds (639153338.176 seconds)True2
Fn
SLEEPduration = 639153338176 milliseconds (639153338.176 seconds)False2
Fn
SLEEPFalse1
Fn
SLEEPduration = 1 milliseconds (0.001 seconds)False1
Fn
GET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
GET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue4
Fn
GET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
GET_INFOTrue1
Fn
Mutex (420)
+
OperationNameAdditional InformationSuccessAmountLogfile
CREATETrue84
Fn
CREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue84
Fn
RELEASETrue252
Fn
Process #11: lsass.exe
(Host: 1720, Network: 0)
+
InformationValue
ID / OS PID#11 / 0x1b4
OS Parent PID0x164 (c:\windows\system32\csrss.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe
Command LineX:\windows\system32\lsass.exe -setup
MonitorStart Time: 00:01:36, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:31
OS Thread IDs
#69
0x1B8
#71
0x1C0
#72
0x1C4
#73
0x1C8
#74
0x1CC
#75
0x1D0
#76
0x1D4
#77
0x1D8
#78
0x1DC
#79
0x1E0
#80
0x1E4
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x0000006b29a300000x6b29a300000x6b29a4ffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000006b29a300000x6b29a300000x6b29a3ffffPagefile Backed FileReadable, WritableTrue
pagefile_0x0000006b29a400000x6b29a400000x6b29a40fffPagefile Backed FileReadable, WritableTrue
pagefile_0x0000006b29a500000x6b29a500000x6b29a5efffPagefile Backed FileReadableTrue
private_0x0000006b29a600000x6b29a600000x6b29adffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000006b29ae00000x6b29ae00000x6b29ae3fffPagefile Backed FileReadableTrue
pagefile_0x0000006b29af00000x6b29af00000x6b29af0fffPagefile Backed FileReadableTrue
private_0x0000006b29b000000x6b29b000000x6b29b01fffPrivate MemoryReadable, WritableTrue
private_0x0000006b29b100000x6b29b100000x6b29c0ffffPrivate MemoryReadable, WritableTrue
locale.nls0x6b29c100000x6b29c8dfffMemory Mapped FileReadableFalse
private_0x0000006b29c900000x6b29c900000x6b29d0ffffPrivate MemoryReadable, WritableTrue
private_0x0000006b29d100000x6b29d100000x6b29d16fffPrivate MemoryReadable, WritableTrue
private_0x0000006b29d200000x6b29d200000x6b29d2ffffPrivate MemoryReadable, WritableTrue
private_0x0000006b29d300000x6b29d300000x6b29d36fffPrivate MemoryReadable, WritableTrue
private_0x0000006b29d400000x6b29d400000x6b29dbffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000006b29dc00000x6b29dc00000x6b29dcffffPagefile Backed FileReadable, WritableTrue
pagefile_0x0000006b29dd00000x6b29dd00000x6b29ddffffPagefile Backed FileReadable, WritableTrue
private_0x0000006b29de00000x6b29de00000x6b29e5ffffPrivate MemoryReadable, WritableTrue
private_0x0000006b29e600000x6b29e600000x6b29edffffPrivate MemoryReadable, WritableTrue
lsasrv.dll.mui0x6b29ee00000x6b29eeafffMemory Mapped FileReadableFalse
pagefile_0x0000006b29ef00000x6b29ef00000x6b29efffffPagefile Backed FileReadable, WritableTrue
sortdefault.nls0x6b29f000000x6b2a1d4fffMemory Mapped FileReadableFalse
c_28591.nls0x6b2a1e00000x6b2a1f0fffMemory Mapped FileReadableFalse
private_0x0000006b2a2000000x6b2a2000000x6b2a200fffPrivate MemoryReadable, WritableTrue
private_0x0000006b2a2100000x6b2a2100000x6b2a28ffffPrivate MemoryReadable, WritableTrue
private_0x0000006b2a2900000x6b2a2900000x6b2a290fffPrivate MemoryReadable, WritableTrue
private_0x0000006b2a2a00000x6b2a2a00000x6b2a2a0fffPrivate MemoryReadable, WritableTrue
private_0x0000006b2a2b00000x6b2a2b00000x6b2a2b0fffPrivate MemoryReadable, WritableTrue
private_0x0000006b2a2c00000x6b2a2c00000x6b2a2c0fffPrivate MemoryReadable, WritableTrue
private_0x0000006b2a2d00000x6b2a2d00000x6b2a2d0fffPrivate MemoryReadable, WritableTrue
private_0x0000006b2a2e00000x6b2a2e00000x6b2a35ffffPrivate MemoryReadable, WritableTrue
private_0x0000006b2a3600000x6b2a3600000x6b2a3dffffPrivate MemoryReadable, WritableTrue
private_0x0000006b2a3e00000x6b2a3e00000x6b2a3e0fffPrivate MemoryReadable, WritableTrue
private_0x0000006b2a3e00000x6b2a3e00000x6b2a45ffffPrivate MemoryReadable, WritableTrue
samsrv.dll.mui0x6b2a4600000x6b2a471fffMemory Mapped FileReadableFalse
private_0x0000006b2a4800000x6b2a4800000x6b2a4fffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007df5ff8c00000x7df5ff8c00000x7ff5ff8bffffPagefile Backed File-True
private_0x00007ff6769f80000x7ff6769f80000x7ff6769f9fffPrivate MemoryReadable, WritableTrue
private_0x00007ff6769fa0000x7ff6769fa0000x7ff6769fbfffPrivate MemoryReadable, WritableTrue
private_0x00007ff6769fc0000x7ff6769fc0000x7ff6769fdfffPrivate MemoryReadable, WritableTrue
private_0x00007ff6769fe0000x7ff6769fe0000x7ff6769fffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007ff676a000000x7ff676a000000x7ff676afffffPagefile Backed FileReadableTrue
pagefile_0x00007ff676b000000x7ff676b000000x7ff676b22fffPagefile Backed FileReadableTrue
private_0x00007ff676b230000x7ff676b230000x7ff676b24fffPrivate MemoryReadable, WritableTrue
private_0x00007ff676b250000x7ff676b250000x7ff676b26fffPrivate MemoryReadable, WritableTrue
private_0x00007ff676b270000x7ff676b270000x7ff676b27fffPrivate MemoryReadable, WritableTrue
private_0x00007ff676b280000x7ff676b280000x7ff676b29fffPrivate MemoryReadable, WritableTrue
private_0x00007ff676b2a0000x7ff676b2a0000x7ff676b2bfffPrivate MemoryReadable, WritableTrue
private_0x00007ff676b2c0000x7ff676b2c0000x7ff676b2dfffPrivate MemoryReadable, WritableTrue
private_0x00007ff676b2e0000x7ff676b2e0000x7ff676b2ffffPrivate MemoryReadable, WritableTrue
lsass.exe0x7ff6775e00000x7ff6775edfffMemory Mapped FileReadable, Writable, ExecutableFalse
winsta.dll0x7ffb709400000x7ffb70999fffMemory Mapped FileReadable, Writable, ExecutableFalse
dsrole.dll0x7ffb70a400000x7ffb70a49fffMemory Mapped FileReadable, Writable, ExecutableFalse
scecli.DLL0x7ffb70a500000x7ffb70a97fffMemory Mapped FileReadable, Writable, ExecutableFalse
dpapisrv.dll0x7ffb70aa00000x7ffb70ad2fffMemory Mapped FileReadable, Writable, ExecutableFalse
efslsaext.dll0x7ffb70ae00000x7ffb70af2fffMemory Mapped FileReadable, Writable, ExecutableFalse
rsaenh.dll0x7ffb70b000000x7ffb70b35fffMemory Mapped FileReadable, Writable, ExecutableFalse
wdigest.DLL0x7ffb70b400000x7ffb70b7bfffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPT32.dll0x7ffb70b800000x7ffb70d5efffMemory Mapped FileReadable, Writable, ExecutableFalse
schannel.DLL0x7ffb70d600000x7ffb70dccfffMemory Mapped FileReadable, Writable, ExecutableFalse
USERENV.dll0x7ffb70dd00000x7ffb70df0fffMemory Mapped FileReadable, Writable, ExecutableFalse
logoncli.dll0x7ffb70e000000x7ffb70e3efffMemory Mapped FileReadable, Writable, ExecutableFalse
DNSAPI.dll0x7ffb70e400000x7ffb70ee3fffMemory Mapped FileReadable, Writable, ExecutableFalse
netlogon.DLL0x7ffb70ef00000x7ffb70fc0fffMemory Mapped FileReadable, Writable, ExecutableFalse
msv1_0.DLL0x7ffb70fd00000x7ffb7103bfffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTSP.dll0x7ffb710400000x7ffb7105ffffMemory Mapped FileReadable, Writable, ExecutableFalse
cryptdll.dll0x7ffb710600000x7ffb71079fffMemory Mapped FileReadable, Writable, ExecutableFalse
kerberos.DLL0x7ffb710800000x7ffb71172fffMemory Mapped FileReadable, Writable, ExecutableFalse
netjoin.dll0x7ffb711800000x7ffb711d0fffMemory Mapped FileReadable, Writable, ExecutableFalse
msprivs.DLL0x7ffb711e00000x7ffb711e1fffMemory Mapped FileReadable, Writable, ExecutableFalse
NTASN1.dll0x7ffb711f00000x7ffb71226fffMemory Mapped FileReadable, Writable, ExecutableFalse
ncrypt.dll0x7ffb712300000x7ffb71254fffMemory Mapped FileReadable, Writable, ExecutableFalse
bcrypt.dll0x7ffb712600000x7ffb71285fffMemory Mapped FileReadable, Writable, ExecutableFalse
samsrv.dll0x7ffb712900000x7ffb7135ffffMemory Mapped FileReadable, Writable, ExecutableFalse
MSASN1.dll0x7ffb713600000x7ffb71370fffMemory Mapped FileReadable, Writable, ExecutableFalse
lsasrv.dll0x7ffb713800000x7ffb714e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
SspiSrv.dll0x7ffb714f00000x7ffb714fafffMemory Mapped FileReadable, Writable, ExecutableFalse
SspiCli.dll0x7ffb715000000x7ffb7152dfffMemory Mapped FileReadable, Writable, ExecutableFalse
powrprof.dll0x7ffb715300000x7ffb71575fffMemory Mapped FileReadable, Writable, ExecutableFalse
bcryptPrimitives.dll0x7ffb715800000x7ffb715e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTBASE.dll0x7ffb715f00000x7ffb715fafffMemory Mapped FileReadable, Writable, ExecutableFalse
profapi.dll0x7ffb716b00000x7ffb716c4fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
CFGMGR32.dll0x7ffb718800000x7ffb718cefffMemory Mapped FileReadable, Writable, ExecutableTrue
WS2_32.dll0x7ffb733600000x7ffb733b9fffMemory Mapped FileReadable, Writable, ExecutableTrue
sechost.dll0x7ffb733c00000x7ffb73418fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
advapi32.dll0x7ffb736900000x7ffb73739fffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
NSI.dll0x7ffb73e800000x7ffb73e88fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSVCRT.dll0x7ffb740500000x7ffb740f9fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Injection Information
+
Injection TypeSource ProcessSource Os Thread IDInjection InfoSuccessAmountLogfile
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wininit.exe0x168address = 0x6b29b00000, size = 4704True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wininit.exe0x168address = 0x7ff676b272d8, size = 8True1
Fn
Data
Created or Modified Files
+
FilenameFile SizeHash Values
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\microsoft\protect\s-1-5-18\user\968b739e-d207-46ed-a53d-aed260dbc1d6 0.46 KB (468 bytes)MD5: d04b3035912004a5cb295bcb9530453e
SHA1: 7303d29121a871487d9aa10620829061b29d7a3b
SHA256: 8a93024371ca325399b2e2d3793194779dd4e10aecc2d7dfbc4f8cd21748381b
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\microsoft\protect\s-1-5-18\user\preferred 0.02 KB (24 bytes)MD5: 0f0b3948f429deda2ed5b504c705b9e7
SHA1: 29def00392c60f70f7102aeab134f79241ff01a0
SHA256: 0b1a1c7eb3734a03ee8f58bed7ef11b6fc98909f7c5c480a05ab3d879a617a8d
Host Behavior
File (40)
+
OperationFilenameAdditional InformationSuccessAmountLogfile
CREATE\device\deviceapi\cmapidesired_access = GENERIC_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATEFalse3
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\debug\passwd.logdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nlsdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\microsoft\protect\s-1-5-18\user\preferreddesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_HIDDEN, FILE_ATTRIBUTE_SYSTEM, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False2
Fn
CREATE\device\namedpipe\lsarpcdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATETrue2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\microsoft\protect\s-1-5-18\user\968b739e-d207-46ed-a53d-aed260dbc1d6desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_HIDDEN, FILE_ATTRIBUTE_SYSTEM, create_disposition = FILE_OPEN_IF, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\microsoft\protect\s-1-5-18\user\preferreddesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_HIDDEN, FILE_ATTRIBUTE_SYSTEM, create_disposition = FILE_OPEN_IF, ea_buffer = 0, ea_length = 0True1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\win.inidesired_access = SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue8
Fn
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\win.inisize = 92True8
Fn
Data
READ\device\namedpipe\lsarpcsize = 1024True1
Fn
Data
READsize = 1024True2
Fn
Data
READsize = 1024False1
Fn
WRITE\device\namedpipe\lsarpcsize = 160, offset = 0True1
Fn
Data
WRITEsize = 116, offset = 0True1
Fn
Data
WRITEsize = 92, offset = 0True1
Fn
Data
WRITETrue2
Fn
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\microsoft\protect\s-1-5-18\user\968b739e-d207-46ed-a53d-aed260dbc1d6size = 468True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\microsoft\protect\s-1-5-18\user\preferredsize = 24True1
Fn
Data
Process (35)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
OPEN_TOKENTrue18
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True12
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
Thread (9)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, proc_address = 0x7ff6775e1250, desired_access = THREAD_ALL_ACCESSTrue1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, proc_address = 0x7ffb713f2020, desired_access = THREAD_ALL_ACCESSTrue1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, proc_address = 0x7ffb713f2d90, desired_access = THREAD_ALL_ACCESSTrue1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, proc_address = 0x7ffb713fa570, desired_access = THREAD_ALL_ACCESSTrue1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, proc_address = 0x7ffb712c7c30, desired_access = THREAD_ALL_ACCESSTrue1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, proc_address = 0x7ffb712ce590, desired_access = THREAD_ALL_ACCESSTrue1
Fn
CREATE_WORKITEMTrue3
Fn
Module (206)
+
OperationModuleAdditional InformationSuccessAmountLogfile
LOADbase_address = 0x7ffb71380000True2
Fn
LOADlsasrv.dllbase_address = 0x0True1
Fn
LOADrpcrt4.dllbase_address = 0x0True1
Fn
LOADLSASRV.DLLbase_address = 0x0True1
Fn
LOADbase_address = 0x0False2
Fn
LOADnegoextsbase_address = 0xc0000135False1
Fn
LOADbase_address = 0x7ffb71080000True2
Fn
LOADkerberosbase_address = 0x0True1
Fn
LOADbase_address = 0x7ffb70fd0000True3
Fn
LOADmsv1_0base_address = 0x0True2
Fn
LOADbase_address = 0x7ffb70ef0000True1
Fn
LOADnetlogonFalse1
Fn
LOADmsv1_0.dllbase_address = 0x0True1
Fn
LOADbase_address = 0x7ffb70d60000True1
Fn
LOADschannelbase_address = 0x0True1
Fn
LOADbase_address = 0x7ffb70b40000True1
Fn
LOADwdigestbase_address = 0x0True1
Fn
LOADbase_address = 0x7ffb70b00000True2
Fn
LOADX:\windows\system32\rsaenh.dllbase_address = 0x0True2
Fn
LOADkernel32.dllbase_address = 0x0True1
Fn
LOAD""base_address = 0xc0000135False1
Fn
LOADbase_address = 0x7ffb71580000True1
Fn
LOADX:\windows\system32\bcryptprimitives.dllbase_address = 0x0True1
Fn
LOADbase_address = 0x7ffb70ae0000True1
Fn
LOADefslsaext.dllbase_address = 0x0True1
Fn
LOADbase_address = 0x7ffb70aa0000True1
Fn
LOADdpapisrv.dllbase_address = 0x0True1
Fn
LOADbase_address = 0x7ffb71500000True1
Fn
LOADsspicli.dllbase_address = 0x0True2
Fn
LOADbase_address = 0x7ffb70a50000True1
Fn
LOADsceclibase_address = 0x0True1
Fn
LOADbase_address = 0x7ffb71290000True9
Fn
LOADSAMSRV.DLLbase_address = 0x0True9
Fn
LOADbase_address = 0x7ffb70a40000True1
Fn
LOADdsrole.dllbase_address = 0x0True1
Fn
LOADnetlogon.dllbase_address = 0x0True1
Fn
LOADX:\windows\system32\kerberos.DLLbase_address = 0x0True1
Fn
GET_HANDLE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeTrue20
Fn
GET_HANDLElsasrv.dllTrue3
Fn
GET_HANDLEkerberos.dllTrue2
Fn
GET_HANDLEmsv1_0.dllTrue3
Fn
GET_HANDLEschannel.dllTrue2
Fn
GET_HANDLEwdigest.dllTrue2
Fn
GET_HANDLEdpapisrv.dllTrue1
Fn
GET_HANDLEntdll.dllTrue3
Fn
GET_HANDLELSASRV.DLLTrue1
Fn
GET_HANDLESAMSRV.DLLTrue2
Fn
GET_HANDLEsamsrv.dllTrue1
Fn
CREATE_MAPPINGNameless FileMappingTrue2
Fn
CREATE_MAPPINGDebug.Memory.v2.1b4module_name = lsasrv.dll, maximum_size = 460260768064, protection = PAGE_READWRITETrue1
Fn
CREATE_MAPPINGDebug.Trace.Memory.1b4module_name = kerberos, maximum_size = 460260765872, protection = PAGE_READWRITETrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeos_pid = 0x1b4, address = 0x6b29dc0000True1
Fn
MAPDebug.Memory.v2.1b4process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x6b29dc0000True1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeos_pid = 0x1b4, address = 0x6b29ef0000True1
Fn
MAPDebug.Trace.Memory.1b4process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x6b29ef0000True1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeos_pid = 0x1b4, address = 0x6b29f00000True4
Fn
MAPCatalog_Entries64\00000001process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x6b29f00000True1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, address = 0x6b29f00000True3
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x6b29f00000True1
Fn
UNMAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeos_pid = 0x1b4True4
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb713f4880True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb713f6a00True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb710c5d28True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70ff78a0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70fe1120True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70d838c0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b45480True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b01570True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b01080True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b06090True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b1e1d0True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b02ce0True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b0af70True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b03880True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b03a30True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b03260True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b06be0True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b04ea0True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b027d0True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b02b00True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b1d8d0True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b024f0True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b06830True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b03c50True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b01030True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b05bb0True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b0f290True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b0f750True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b03f50True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b02630True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b0d330True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b1d6e0True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70ff56c0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70fe8a90True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70fdb500True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70fdb9f0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70fed400True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70fd10b0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x0False2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb71595b30True3
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb71584530True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70ae4980True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70aad6c0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70aadb40True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb741801b0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb715848b0True4
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb741b0fa0True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70a41550True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70a41530True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb710a8cc0True1
Fn
Service (6)
+
OperationServiceAdditional InformationSuccessAmountLogfile
OPEN_MGRSERVICES_ACTIVE_DATABASEhost = LocalhostTrue1
Fn
OPENTrue1
Fn
GET_INFOtype = ConfigFalse1
Fn
GET_INFOtype = ConfigTrue1
Fn
GET_INFOtype = StatusTrue2
Fn
Registry (1372)
+
OperationKeyAdditional InformationSuccessAmountLogfile
CREATE_KEYTrue15
Fn
CREATE_KEYJDTrue1
Fn
CREATE_KEYSkew1True1
Fn
CREATE_KEYGBGTrue1
Fn
CREATE_KEYDataTrue1
Fn
CREATE_KEYSystem\CurrentControlSet\Control\Lsa\AuditTrue2
Fn
CREATE_KEYSoftware\Microsoft\Windows\CurrentVersion\Policies\System\AuditTrue2
Fn
CREATE_KEYSystem\CurrentControlSet\Control\Lsa\Kerberos\DomainsTrue1
Fn
CREATE_KEY00000001True1
Fn
CREATE_KEYCatalog_Entries64True1
Fn
CREATE_KEYCatalog_Entries64\00000001True1
Fn
CREATE_KEYCatalog_Entries64\Catalog_Entries64True1
Fn
CREATE_KEYCatalog_Entries64\Catalog_Entries64\000000000001True1
Fn
CREATE_KEYSystem\CurrentControlSet\Control\SecurityProviders\WDigestTrue1
Fn
CREATE_KEYSoftware\Microsoft\CryptographyTrue1
Fn
CREATE_KEYSystem\CurrentControlSet\Control\Lsa\SspiCacheTrue1
Fn
CREATE_KEYSOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297ebFalse1
Fn
CREATE_KEYSOFTWARETrue1
Fn
CREATE_KEYSOFTWARE\MicrosoftTrue1
Fn
CREATE_KEYSOFTWARE\Microsoft\CryptographyTrue1
Fn
CREATE_KEYSOFTWARE\Microsoft\Cryptography\ProtectTrue1
Fn
CREATE_KEYSOFTWARE\Microsoft\Cryptography\Protect\ProvidersTrue1
Fn
CREATE_KEYSOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297ebTrue1
Fn
CREATE_KEYSystem\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\SystemTrue1
Fn
CREATE_KEYSystem\CurrentControlSet\Control\Lsa\Audit\AuditPolicyTrue1
Fn
OPEN_KEYTrue83
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\VersionsTrue1
Fn
OPEN_KEYFalse49
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameFalse11
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNameTrue11
Fn
OPEN_KEY\Registry\Machine\System\SetupTrue2
Fn
OPEN_KEY\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Services\Tcpip\ParametersTrue5
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\IdsTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue2
Fn
READ_VALUETrue70
Fn
READ_VALUEvalue_name = ExtensionsTrue2
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versionsvalue_name = 460260763712True1
Fn
READ_VALUEFalse451
Fn
READ_VALUEvalue_name = GeneralThreadLifespanFalse1
Fn
READ_VALUEvalue_name = DedicatedThreadLifespanFalse1
Fn
READ_VALUEvalue_name = HighPriorityFalse1
Fn
READ_VALUEvalue_name = CritSecSpinCountFalse1
Fn
READ_VALUEvalue_name = MaxRpcSizeFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNamevalue_name = ComputerNameTrue11
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = OOBEInProgressFalse1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = SystemSetupInProgressTrue1
Fn
READ_VALUEvalue_name = IdleTimerWindowFalse1
Fn
READ_VALUEvalue_name = DisableRestrictedAdminOutboundCredsFalse7
Fn
READ_VALUEvalue_name = DisableRestrictedAdminFalse7
Fn
READ_VALUEvalue_name = TokenLeakDetectDelaySecsFalse7
Fn
READ_VALUEvalue_name = IdCacheEntryLifeSpanFalse7
Fn
READ_VALUEvalue_name = SamWaitNoTimeoutFalse7
Fn
READ_VALUEvalue_name = SuppressExtendedProtectionFalse7
Fn
READ_VALUEvalue_name = LogToFileFalse7
Fn
READ_VALUEvalue_name = SendOptionalMechlistMICFalse7
Fn
READ_VALUEvalue_name = AcceptUnsafeUnprotectedNegotiationFalse7
Fn
READ_VALUEvalue_name = CrashOnAuditFailTrue7
Fn
READ_VALUEvalue_name = NegEventMaskFalse7
Fn
READ_VALUEvalue_name = SPMInfoLevelFalse7
Fn
READ_VALUEvalue_name = DisableCredManFalse7
Fn
READ_VALUEvalue_name = DisableDomainCredsFalse7
Fn
READ_VALUEvalue_name = HourlyLogLevelFalse7
Fn
READ_VALUEvalue_name = AuthenticateAnonymousOnlineIDsFalse7
Fn
READ_VALUEvalue_name = TurnOffAnonymousBlockFalse7
Fn
READ_VALUEvalue_name = EveryoneIncludesAnonymousFalse7
Fn
READ_VALUEvalue_name = DisableAutomaticRestartSignOnFalse3
Fn
READ_VALUEvalue_name = DisableConnectedNTLMPasswordFalse3
Fn
READ_VALUEvalue_name = NoConnectedUserFalse3
Fn
READ_VALUEvalue_name = ApplyPolicyToAnonymousLogonFalse3
Fn
READ_VALUEvalue_name = EnableLocalLogonSidFalse3
Fn
READ_VALUEvalue_name = EnableLinkedConnectionsFalse3
Fn
READ_VALUEvalue_name = FilterAdministratorTokenFalse3
Fn
READ_VALUEvalue_name = DisplayLastLogonInfoFalse3
Fn
READ_VALUEvalue_name = FilterNetworkAuthenticationTokensFalse3
Fn
READ_VALUEvalue_name = LocalAccountTokenFilterPolicyFalse3
Fn
READ_VALUEvalue_name = DisableRestrictionTraversalFalse3
Fn
READ_VALUEvalue_name = ScForceOptionFalse3
Fn
READ_VALUEvalue_name = EnableVirtualizationTrue3
Fn
READ_VALUEvalue_name = EnableDebugCheckFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNamevalue_name = PreferredFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNamevalue_name = Security PackagesTrue6
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNamevalue_name = Authentication PackagesTrue2
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRvalue_name = DisableTrue1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRvalue_name = lspdbginfolevelFalse1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRvalue_name = LsaDbExtPtFalse1
Fn
READ_VALUEvalue_name = lspdbginfolevelFalse7
Fn
READ_VALUESystem\CurrentControlSet\Control\Lsa\Auditvalue_name = SpecialGroupsFalse2
Fn
READ_VALUEvalue_name = KerbDebugLevelFalse2
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parametersvalue_name = HostnameFalse5
Fn
READ_VALUEvalue_name = KerbControlLevelFalse4
Fn
READ_VALUEvalue_name = SupportedEncryptionTypesFalse4
Fn
READ_VALUEvalue_name = MaxTokenSizeFalse4
Fn
READ_VALUEvalue_name = DHDomainParametersFalse4
Fn
READ_VALUEvalue_name = WinSock_Registry_VersionTrue2
Fn
READ_VALUEvalue_name = AppFullPathTrue2
Fn
READ_VALUEvalue_name = PermittedLspCategoriesTrue1
Fn
READ_VALUEvalue_name = NameSpace_CalloutTrue2
Fn
READ_VALUEvalue_name = Serial_Access_NumTrue6
Fn
READ_VALUEvalue_name = Next_Catalog_Entry_IDTrue3
Fn
READ_VALUEvalue_name = Num_Catalog_Entries64False1
Fn
READ_VALUEvalue_name = Num_Catalog_EntriesTrue1
Fn
READ_VALUECatalog_Entries64value_name = Serial_Access_NumTrue4
Fn
READ_VALUECatalog_Entries64value_name = Num_Catalog_Entries64False1
Fn
READ_VALUECatalog_Entries64value_name = Num_Catalog_EntriesTrue1
Fn
READ_VALUEvalue_name = LibraryPathTrue2
Fn
READ_VALUEvalue_name = DisplayStringTrue4
Fn
READ_VALUEvalue_name = ProviderIdTrue1
Fn
READ_VALUEvalue_name = AddressFamilyFalse1
Fn
READ_VALUEvalue_name = SupportedNameSpaceTrue1
Fn
READ_VALUEvalue_name = EnabledTrue1
Fn
READ_VALUEvalue_name = VersionTrue1
Fn
READ_VALUEvalue_name = StoresServiceClassInfoTrue1
Fn
READ_VALUEvalue_name = ProviderInfoFalse1
Fn
READ_VALUEvalue_name = Ws2_32NumHandleBucketsFalse1
Fn
READ_VALUEvalue_name = Num_Catalog_Entries64True2
Fn
READ_VALUECatalog_Entries64\Catalog_Entries64\000000000001value_name = NtLmInfoLevelFalse2
Fn
READ_VALUEvalue_name = LmCompatibilityLevelFalse3
Fn
READ_VALUEvalue_name = UseMachineIdFalse3
Fn
READ_VALUEvalue_name = ForceGuestFalse6
Fn
READ_VALUEvalue_name = DisallowMsvChapv2False3
Fn
READ_VALUEvalue_name = LimitBlankPasswordUseTrue6
Fn
READ_VALUEvalue_name = DisableLoopbackCheckFalse3
Fn
READ_VALUEvalue_name = DebugBreakIfDebuggedFalse3
Fn
READ_VALUEvalue_name = OldPasswordAllowedPeriodFalse3
Fn
READ_VALUEvalue_name = AllowLegacySrvCallFalse3
Fn
READ_VALUEvalue_name = SendNt2ResponseOnlyFalse3
Fn
READ_VALUEvalue_name = NtlmMinClientSecTrue3
Fn
READ_VALUEvalue_name = NtlmMinServerSecTrue3
Fn
READ_VALUEvalue_name = BackConnectionHostNamesFalse3
Fn
READ_VALUEvalue_name = RestrictSendingNTLMTrafficFalse3
Fn
READ_VALUEvalue_name = RestrictReceivingNTLMTrafficFalse3
Fn
READ_VALUEvalue_name = AuditReceivingNTLMTrafficFalse3
Fn
READ_VALUEvalue_name = ClientAllowedNTLMServersFalse3
Fn
READ_VALUEvalue_name = NTLMInfoEventFalse3
Fn
READ_VALUEvalue_name = allownullsessionfallbackFalse3
Fn
READ_VALUEvalue_name = AllowS4UForDomainUsersFalse3
Fn
READ_VALUEvalue_name = MappedDomainFalse1
Fn
READ_VALUEvalue_name = PreferredDomainFalse1
Fn
READ_VALUEvalue_name = IPAddressRefreshIntervalFalse1
Fn
READ_VALUEvalue_name = SystemSetupInProgressTrue1
Fn
READ_VALUEvalue_name = LogLevelFalse2
Fn
READ_VALUEvalue_name = DebuglevelTrue2
Fn
READ_VALUESystem\CurrentControlSet\Control\SecurityProviders\WDigestvalue_name = NegotiateTrue3
Fn
READ_VALUESystem\CurrentControlSet\Control\SecurityProviders\WDigestvalue_name = UTF8HTTPTrue3
Fn
READ_VALUESystem\CurrentControlSet\Control\SecurityProviders\WDigestvalue_name = UTF8SASLTrue3
Fn
READ_VALUESystem\CurrentControlSet\Control\SecurityProviders\WDigestvalue_name = ServerCompatFalse3
Fn
READ_VALUESystem\CurrentControlSet\Control\SecurityProviders\WDigestvalue_name = ClientCompatFalse3
Fn
READ_VALUESystem\CurrentControlSet\Control\SecurityProviders\WDigestvalue_name = DigestEncryptionAlgorithmsFalse1
Fn
READ_VALUESystem\CurrentControlSet\Control\SecurityProviders\WDigestvalue_name = UseLogonCredentialFalse3
Fn
READ_VALUESystem\CurrentControlSet\Control\SecurityProviders\WDigestvalue_name = DisableNameRealmValidationFalse3
Fn
READ_VALUESystem\CurrentControlSet\Control\SecurityProviders\WDigestvalue_name = DebuglevelTrue3
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNamevalue_name = NameTrue8
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNamevalue_name = TypeTrue2
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNamevalue_name = Image PathTrue8
Fn
READ_VALUEvalue_name = MachineGuidFalse1
Fn
READ_VALUESoftware\Microsoft\Cryptographyvalue_name = MachineGuidFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versionsvalue_name = 000602xxTrue1
Fn
READ_VALUENameless FileMappingvalue_name = MachineGuidTrue4
Fn
READ_VALUESystem\CurrentControlSet\Control\SecurityProviders\WDigestvalue_name = DigestEncryptionAlgorithmsTrue4
Fn
READ_VALUEvalue_name = MaxCredentialsSizeFalse1
Fn
READ_VALUEvalue_name = TargetInfoCacheSizeFalse1
Fn
READ_VALUEvalue_name = LsaLookupCacheRefreshTimeFalse4
Fn
READ_VALUEvalue_name = LsaLookupCacheExpireTimeFalse4
Fn
READ_VALUEvalue_name = LsaLookupCacheMaxSizeFalse4
Fn
READ_VALUEvalue_name = ExtensionTrue4
Fn
READ_VALUEvalue_name = SecurityProvidersFalse2
Fn
READ_VALUESOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297ebvalue_name = MasterKeyIterationCountFalse2
Fn
READ_VALUESOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297ebvalue_name = MasterKeyLegacyComplianceFalse2
Fn
READ_VALUESOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297ebvalue_name = MasterKeyLegacyNt4DomainFalse2
Fn
READ_VALUESOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297ebvalue_name = DistributeBackupKeyFalse2
Fn
READ_VALUESOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297ebvalue_name = ProtectionPolicyFalse2
Fn
READ_VALUESOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297ebvalue_name = Recovery VersionFalse2
Fn
READ_VALUESOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297ebvalue_name = Encr AlgFalse2
Fn
READ_VALUESOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297ebvalue_name = Encr Alg Key SizeFalse2
Fn
READ_VALUESOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297ebvalue_name = MAC AlgFalse2
Fn
READ_VALUESOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297ebvalue_name = MAC Alg Key SizeFalse2
Fn
READ_VALUEvalue_name = MiniSetupInProgressFalse1
Fn
READ_VALUESystem\CurrentControlSet\Control\Lsa\Audit\AuditPolicyvalue_name = AuditPolicySDFalse1
Fn
READ_VALUEvalue_name = LookupLogLevelFalse3
Fn
READ_VALUEvalue_name = LsaLookupReturnSidTypeDeletedFalse3
Fn
READ_VALUEvalue_name = LsaLookupRestrictIsolatedNameLevelFalse3
Fn
READ_VALUEvalue_name = LsarpcServerAllowRemotedSecretOperationsFalse3
Fn
READ_VALUEvalue_name = LsaAllowReturningUnencryptedSecretsFalse3
Fn
READ_VALUEvalue_name = NoLmHashTrue3
Fn
READ_VALUEvalue_name = SamReplicatePasswordsUrgentlyFalse3
Fn
READ_VALUEvalue_name = SamAccountLockoutTestModeFalse3
Fn
READ_VALUEvalue_name = SamDisableListenOnTCPFalse3
Fn
READ_VALUEvalue_name = IgnoreGCFailuresFalse3
Fn
READ_VALUEvalue_name = SamNoGcLogonEnforceKerberosIpCheckFalse3
Fn
READ_VALUEvalue_name = SamNoGcLogonEnforceNTLMCheckFalse3
Fn
READ_VALUEvalue_name = SamDisableSingleObjectReplFalse3
Fn
READ_VALUEvalue_name = SamDisableRSOOnPDCForwardFalse3
Fn
READ_VALUEvalue_name = SamDisableResetBadPwdCountForwardFalse3
Fn
READ_VALUEvalue_name = SamConnectedAccountsExistFalse3
Fn
READ_VALUEvalue_name = SamDisableOutboundRSOFalse3
Fn
READ_VALUEvalue_name = RestrictAnonymousFalse3
Fn
READ_VALUEvalue_name = RestrictAnonymousSamFalse3
Fn
READ_VALUEvalue_name = ExtendedSidEmulationModeFalse3
Fn
READ_VALUEvalue_name = SamLogSizeFalse3
Fn
READ_VALUEvalue_name = SamLogLevelFalse3
Fn
READ_VALUEvalue_name = SamRestrictOwfPasswordChangeFalse3
Fn
READ_VALUEvalue_name = MaxSamConnectionsFalse3
Fn
READ_VALUEvalue_name = dsrmAdminLogonBehaviorFalse3
Fn
READ_VALUEvalue_name = SamMaxQueueLengthForPDCForwardFalse3
Fn
READ_VALUEvalue_name = EnableClaimsTransformationEchoFalse3
Fn
READ_VALUEvalue_name = EnumerationCachePurgeIntervalFalse3
Fn
READ_VALUEvalue_name = EnumerationCacheEntryLifetimeFalse3
Fn
READ_VALUEvalue_name = DirectoryServiceExtPtFalse61
Fn
READ_VALUEvalue_name = PolicyFilterOffFalse1
Fn
READ_VALUEvalue_name = 9True1
Fn
READ_VALUEvalue_name = 68True1
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\Policies\System\Auditvalue_name = ProcessCreationIncludeCmdLine_EnabledFalse1
Fn
READ_VALUEvalue_name = SQMServiceListTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNamevalue_name = ComputerNameTrue2
Fn
WRITE_VALUETrue11
Fn
WRITE_VALUEvalue_name = LsaPid, data = 436True1
Fn
WRITE_VALUEJDvalue_name = LookupTrue1
Fn
Data
WRITE_VALUESkew1value_name = SkewMatrixTrue1
Fn
Data
WRITE_VALUEGBGvalue_name = GrafBlumGroupTrue1
Fn
Data
WRITE_VALUEDatavalue_name = PatternTrue1
Fn
Data
WRITE_VALUEvalue_name = SecureBoot, data = 1True1
Fn
WRITE_VALUEvalue_name = Num_Catalog_Entries64, data = 0True1
Fn
WRITE_VALUEvalue_name = Next_Catalog_Entry_ID, data = 1001True1
Fn
WRITE_VALUEvalue_name = Serial_Access_Num, data = 2True1
Fn
WRITE_VALUECatalog_Entries64\Catalog_Entries64\000000000001value_name = LibraryPath, data = X:\Windows\system32\mswsock.dllTrue1
Fn
WRITE_VALUECatalog_Entries64\Catalog_Entries64\000000000001value_name = DisplayString, data = TcpipTrue1
Fn
WRITE_VALUECatalog_Entries64\Catalog_Entries64\000000000001value_name = ProviderIdTrue1
Fn
Data
WRITE_VALUECatalog_Entries64\Catalog_Entries64\000000000001value_name = SupportedNameSpace, data = 12True1
Fn
WRITE_VALUECatalog_Entries64\Catalog_Entries64\000000000001value_name = Enabled, data = 1True1
Fn
WRITE_VALUECatalog_Entries64\Catalog_Entries64\000000000001value_name = Version, data = 0True1
Fn
WRITE_VALUECatalog_Entries64\Catalog_Entries64\000000000001value_name = StoresServiceClassInfo, data = 1True1
Fn
WRITE_VALUECatalog_Entries64\Catalog_Entries64\000000000001value_name = ProviderInfoTrue1
Fn
WRITE_VALUECatalog_Entries64value_name = Num_Catalog_Entries64, data = 1True1
Fn
WRITE_VALUECatalog_Entries64value_name = Serial_Access_Num, data = 2True1
Fn
WRITE_VALUEvalue_name = DigestEncryptionAlgorithms, data = 3des,rc4True1
Fn
WRITE_VALUESoftware\Microsoft\Cryptographyvalue_name = MachineGuid, data = 4510eeb9-2c9e-4e5e-bb64-8d8e190b646fTrue1
Fn
WRITE_VALUEvalue_name = RNGAuxiliarySeed, data = 1477820023True1
Fn
WRITE_VALUEvalue_name = ProductType, data = 1True1
Fn
WRITE_VALUESystem\CurrentControlSet\Control\Lsa\Audit\AuditPolicyvalue_name = AuditPolicySDTrue1
Fn
Data
DELETE_KEYTrue8
Fn
DELETE_KEYCatalog_Entries64True1
Fn
DELETE_KEYCatalog_Entries64\Catalog_Entries64True1
Fn
Driver (15)
+
OperationDriverAdditional InformationSuccessAmountLogfile
CONTROLTrue2
Fn
CONTROLcontrol_code = 0x390008True2
Fn
CONTROLcontrol_code = 0x110008False3
Fn
CONTROLcontrol_code = 0x110024True1
Fn
CONTROL\device\namedpipe\lsarpccontrol_code = 0x11c017False1
Fn
CONTROLcontrol_code = 0x11001cTrue5
Fn
CONTROLcontrol_code = 0x110004True1
Fn
System (25)
+
OperationInformationSuccessAmountLogfile
SLEEPTrue1
Fn
SLEEPduration = 460268828672 milliseconds (460268828.672 seconds)False1
Fn
GET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
GET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue12
Fn
GET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue9
Fn
GET_INFOTrue1
Fn
Ini (8)
+
OperationFilenameAdditional InformationSuccessAmountLogfile
READWin.iniFalse8
Fn
Debug (4)
+
OperationTypeAdditional InformationSuccessAmountLogfile
CHECK_FOR_PRESENCEDEBUGGERprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe, os_pid = 0x1b4True4
Fn
Process #12: svchost.exe
(Host: 27926, Network: 0)
+
InformationValue
ID / OS PID#12 / 0x210
OS Parent PID0x1ac (c:\windows\system32\csrss.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exe
Command LineX:\windows\system32\svchost.exe -k DcomLaunch
MonitorStart Time: 00:01:47, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:20
OS Thread IDs
#92
0x214
#93
0x218
#94
0x21C
#95
0x220
#98
0x228
#99
0x22C
#100
0x230
#101
0x234
#106
0x24C
#109
0x258
#110
0x25C
#117
0x280
#119
0x284
#120
0x288
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x000000aee69800000xaee69800000xaee699ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000aee69800000xaee69800000xaee698ffffPagefile Backed FileReadable, WritableTrue
private_0x000000aee69900000xaee69900000xaee6996fffPrivate MemoryReadable, WritableTrue
pagefile_0x000000aee69a00000xaee69a00000xaee69aefffPagefile Backed FileReadableTrue
private_0x000000aee69b00000xaee69b00000xaee6a2ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000aee6a300000xaee6a300000xaee6a33fffPagefile Backed FileReadableTrue
pagefile_0x000000aee6a400000xaee6a400000xaee6a40fffPagefile Backed FileReadableTrue
private_0x000000aee6a500000xaee6a500000xaee6a51fffPrivate MemoryReadable, WritableTrue
locale.nls0xaee6a600000xaee6addfffMemory Mapped FileReadableFalse
private_0x000000aee6ae00000xaee6ae00000xaee6b5ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee6b600000xaee6b600000xaee6b66fffPrivate MemoryReadable, WritableTrue
private_0x000000aee6b700000xaee6b700000xaee6c6ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee6c700000xaee6c700000xaee6ceffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000aee6c700000xaee6c700000xaee6c70fffPagefile Backed FileReadable, WritableTrue
pagefile_0x000000aee6c800000xaee6c800000xaee6c80fffPagefile Backed FileReadableTrue
pagefile_0x000000aee6c900000xaee6c900000xaee6c90fffPagefile Backed FileReadable, WritableTrue
private_0x000000aee6ca00000xaee6ca00000xaee6caffffPrivate MemoryReadable, WritableTrue
private_0x000000aee6cb00000xaee6cb00000xaee6cb0fffPrivate MemoryReadable, WritableTrue
sortdefault.nls0xaee6cf00000xaee6fc4fffMemory Mapped FileReadableFalse
private_0x000000aee6fd00000xaee6fd00000xaee704ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee6fd00000xaee6fd00000xaee704ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee6fd00000xaee6fd00000xaee704ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee70900000xaee70900000xaee709ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee70a00000xaee70a00000xaee711ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee71200000xaee71200000xaee719ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee71a00000xaee71a00000xaee721ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee72200000xaee72200000xaee729ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee72a00000xaee72a00000xaee731ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee72a00000xaee72a00000xaee731ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee73200000xaee73200000xaee741ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee74200000xaee74200000xaee749ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee75c00000xaee75c00000xaee75cffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007df5ffd400000x7df5ffd400000x7ff5ffd3ffffPagefile Backed File-True
private_0x00007ff7c97780000x7ff7c97780000x7ff7c9779fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c977a0000x7ff7c977a0000x7ff7c977bfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c977a0000x7ff7c977a0000x7ff7c977bfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c977c0000x7ff7c977c0000x7ff7c977dfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c977e0000x7ff7c977e0000x7ff7c977ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007ff7c97800000x7ff7c97800000x7ff7c987ffffPagefile Backed FileReadableTrue
pagefile_0x00007ff7c98800000x7ff7c98800000x7ff7c98a2fffPagefile Backed FileReadableTrue
private_0x00007ff7c98a40000x7ff7c98a40000x7ff7c98a5fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c98a60000x7ff7c98a60000x7ff7c98a6fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c98a80000x7ff7c98a80000x7ff7c98a9fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c98a80000x7ff7c98a80000x7ff7c98a9fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c98aa0000x7ff7c98aa0000x7ff7c98abfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c98aa0000x7ff7c98aa0000x7ff7c98abfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c98aa0000x7ff7c98aa0000x7ff7c98abfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c98ac0000x7ff7c98ac0000x7ff7c98adfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c98ae0000x7ff7c98ae0000x7ff7c98affffPrivate MemoryReadable, WritableTrue
svchost.exe0x7ff7ca8100000x7ff7ca81cfffMemory Mapped FileReadable, Writable, ExecutableFalse
DAB.dll0x7ffb701900000x7ffb701abfffMemory Mapped FileReadable, Writable, ExecutableFalse
SystemEventsBrokerServer.dll0x7ffb703000000x7ffb7034bfffMemory Mapped FileReadable, Writable, ExecutableFalse
DEVOBJ.dll0x7ffb705b00000x7ffb705d7fffMemory Mapped FileReadable, Writable, ExecutableFalse
pcwum.dll0x7ffb706000000x7ffb7060dfffMemory Mapped FileReadable, Writable, ExecutableFalse
WMsgAPI.dll0x7ffb706100000x7ffb70618fffMemory Mapped FileReadable, Writable, ExecutableFalse
SYSNTFY.dll0x7ffb706200000x7ffb7062bfffMemory Mapped FileReadable, Writable, ExecutableFalse
lsm.dll0x7ffb706300000x7ffb706f5fffMemory Mapped FileReadable, Writable, ExecutableFalse
rpcss.dll0x7ffb707400000x7ffb7080bfffMemory Mapped FileReadable, Writable, ExecutableFalse
umpo.dll0x7ffb708100000x7ffb70827fffMemory Mapped FileReadable, Writable, ExecutableFalse
umpnpmgr.dll0x7ffb708300000x7ffb70851fffMemory Mapped FileReadable, Writable, ExecutableFalse
USERENV.dll0x7ffb70dd00000x7ffb70df0fffMemory Mapped FileReadable, Writable, ExecutableFalse
SspiCli.dll0x7ffb715000000x7ffb7152dfffMemory Mapped FileReadable, Writable, ExecutableFalse
powrprof.dll0x7ffb715300000x7ffb71575fffMemory Mapped FileReadable, Writable, ExecutableFalse
bcryptPrimitives.dll0x7ffb715800000x7ffb715e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTBASE.dll0x7ffb715f00000x7ffb715fafffMemory Mapped FileReadable, Writable, ExecutableFalse
profapi.dll0x7ffb716b00000x7ffb716c4fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
CFGMGR32.dll0x7ffb718800000x7ffb718cefffMemory Mapped FileReadable, Writable, ExecutableTrue
sechost.dll0x7ffb733c00000x7ffb73418fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
combase.dll0x7ffb737400000x7ffb73950fffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSVCRT.dll0x7ffb740500000x7ffb740f9fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Injection Information
+
Injection TypeSource ProcessSource Os Thread IDInjection InfoSuccessAmountLogfile
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe0x1b0address = 0xaee6a50000, size = 4704True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe0x1b0address = 0x7ff7c98a62d8, size = 8True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Host Behavior
File (3)
+
OperationFilenameAdditional InformationSuccessAmountLogfile
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nlsdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\deviceapi\cmapidesired_access = GENERIC_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsm.dlldesired_access = FILE_READ_DATA, FILE_READ_EA, FILE_READ_ATTRIBUTES, READ_CONTROL, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
Process (50)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
OPENTrue6
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exeos_pid = 0x238, desired_access = PROCESS_ALL_ACCESSTrue1
Fn
OPENc:\windows\system32\csrss.exeos_pid = 0x164, desired_access = SYNCHRONIZETrue1
Fn
OPENc:\windows\system32\csrss.exeos_pid = 0x164, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, desired_access = PROCESS_QUERY_LIMITED_INFORMATION, SYNCHRONIZETrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exeos_pid = 0x194, desired_access = SYNCHRONIZETrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exeos_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONTrue4
Fn
OPENc:\windows\system32\wermgr.exeos_pid = 0x16c, desired_access = PROCESS_QUERY_LIMITED_INFORMATION, SYNCHRONIZETrue1
Fn
OPENc:\windows\system32\wermgr.exeos_pid = 0x16c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
OPENc:\windows\system32\wermgr.exeos_pid = 0x16c, desired_access = PROCESS_QUERY_LIMITED_INFORMATIONTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, desired_access = PROCESS_QUERY_LIMITED_INFORMATIONTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeos_pid = 0x1b4, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wallpaperhost.exeos_pid = 0x290, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exeos_pid = 0x2b0, desired_access = PROCESS_QUERY_LIMITED_INFORMATIONTrue1
Fn
OPEN_TOKENTrue1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True3
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFOTrue10
Fn
GET_INFOTrue4
Fn
GET_INFOSoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74dTrue1
Fn
GET_INFOSoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86True1
Fn
GET_INFOTrue1
Fn
Thread (6)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, proc_address = 0x7ffb733c7ef0, desired_access = THREAD_ALL_ACCESSTrue2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, proc_address = 0x7ffb733c7ef0, desired_access = THREAD_ALL_ACCESSTrue1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, proc_address = 0x7ffb733c7ef0, desired_access = THREAD_ALL_ACCESSTrue1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, proc_address = 0x7ffb733c7ef0, desired_access = THREAD_ALL_ACCESSTrue1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, proc_address = 0x7ffb701a1e00, desired_access = THREAD_ALL_ACCESSTrue1
Fn
Module (57)
+
OperationModuleAdditional InformationSuccessAmountLogfile
LOADrpcrt4.dllbase_address = 0x0True1
Fn
LOADkernel32.dllbase_address = 0x0True1
Fn
LOADbase_address = 0x7ffb70830000True1
Fn
LOADx:\windows\system32\umpnpmgr.dllbase_address = 0x0True1
Fn
LOADbase_address = 0x7ffb70810000True1
Fn
LOADx:\windows\system32\umpo.dllbase_address = 0x0True1
Fn
LOADbase_address = 0x7ffb70740000True1
Fn
LOADx:\windows\system32\rpcss.dllFalse1
Fn
LOADbase_address = 0x7ffb71500000True1
Fn
LOADsspicli.dllbase_address = 0x0True2
Fn
LOADbase_address = 0x7ffb70630000True1
Fn
LOADx:\windows\system32\lsm.dllbase_address = 0x0True1
Fn
LOADbase_address = 0x7ffb70dd0000True1
Fn
LOADX:\windows\System32\Userenv.dllbase_address = 0x0True1
Fn
LOADbase_address = 0x7ffb70300000True1
Fn
LOADx:\windows\system32\systemeventsbrokerserver.dllbase_address = 0x0True1
Fn
GET_HANDLErpcrt4.dllTrue1
Fn
GET_HANDLE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exeFalse1
Fn
GET_HANDLEadvapi32.dllFalse1
Fn
GET_HANDLE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exeTrue2
Fn
GET_HANDLEapi-ms-win-eventing-provider-l1-1-0.dllTrue1
Fn
GET_HANDLEntdll.dllTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingTrue3
Fn
CREATE_MAPPINGGlobal\__ComCatalogCache__module_name = sspicli.dll, maximum_size = 751200171792, protection = PAGE_READWRITETrue1
Fn
CREATE_MAPPINGGlobal\RotHintTablemodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exe, maximum_size = 751194992064, protection = PAGE_READWRITETrue1
Fn
CREATE_MAPPINGGlobal\{A64C7F33-DA35-459b-96CA-63B51FB0CDB9}module_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exe, maximum_size = 751194992320, protection = PAGE_READWRITETrue1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xaee6cf0000True1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exeos_pid = 0x210, address = 0xaee6c70000True1
Fn
MAPGlobal\__ComCatalogCache__process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xaee6c70000True1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exeos_pid = 0x210, address = 0xaee6c90000True1
Fn
MAPGlobal\RotHintTableprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xaee6c90000True1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exeos_pid = 0x210, address = 0xaee6cb0000True1
Fn
MAPGlobal\{A64C7F33-DA35-459b-96CA-63B51FB0CDB9}process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xaee6cb0000True1
Fn
UNMAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exeos_pid = 0x210True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb708390b0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb708310a0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb708170f0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x0False3
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb7078a100True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb741751c0True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb7413b300True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb7413c360True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb74175650True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70672ee0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70dd1d60True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb7030f080True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb7030ed50True1
Fn
Service (20)
+
OperationServiceAdditional InformationSuccessAmountLogfile
OPEN_MGRSERVICES_ACTIVE_DATABASEhost = LocalhostTrue7
Fn
OPENTrue1
Fn
OPENFalse6
Fn
GET_INFOtype = StatusTrue1
Fn
REGISTER_HANDLERTrue5
Fn
Registry (27244)
+
OperationKeyAdditional InformationSuccessAmountLogfile
CREATE_KEYTrue6
Fn
CREATE_KEYSystem\CurrentControlSet\Control\Power\SecurityDescriptorsTrue1
Fn
CREATE_KEYSoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\5c9a4cd7-ba75-45d2-9898-1773b3d1e5f1False1
Fn
CREATE_KEYSoftwareTrue1
Fn
CREATE_KEYSoftware\MicrosoftTrue1
Fn
CREATE_KEYSoftware\Microsoft\WindowsTrue1
Fn
CREATE_KEYSoftware\Microsoft\Windows\CurrentVersionTrue1
Fn
CREATE_KEYSoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggersTrue1
Fn
CREATE_KEYSoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\TriggersTrue1
Fn
CREATE_KEYSoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74dTrue1
Fn
CREATE_KEYSoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\5c9a4cd7-ba75-45d2-9898-1773b3d1e5f1True1
Fn
CREATE_KEYSoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076True1
Fn
CREATE_KEYSoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86True1
Fn
CREATE_KEYSoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\9B008953-F195-4BF9-BDE0-4471971E58EDTrue1
Fn
CREATE_KEYSoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemesTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\VersionsTrue1
Fn
OPEN_KEYTrue6019
Fn
OPEN_KEYFalse1078
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue2
Fn
OPEN_KEY\Registry\Machine\System\SetupTrue2
Fn
OPEN_KEYControl Panel\InternationalTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocaleTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocaleTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\IdsTrue1
Fn
OPEN_KEY\Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySideTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versionsvalue_name = 751193748928True1
Fn
READ_VALUETrue7513
Fn
READ_VALUEvalue_name = DcomLaunchTrue2
Fn
READ_VALUEvalue_name = MaxRpcSizeFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNamevalue_name = ComputerNameTrue2
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = OOBEInProgressFalse1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = SystemSetupInProgressTrue1
Fn
READ_VALUEvalue_name = IdleTimerWindowFalse1
Fn
READ_VALUEControl Panel\InternationalFalse5
Fn
READ_VALUEControl Panel\InternationalTrue5
Fn
READ_VALUEControl Panel\Internationalvalue_name = sCurrencyOverrideFalse5
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocalevalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocalevalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versionsvalue_name = 000602xxTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Idsvalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Idsvalue_name = enFalse1
Fn
READ_VALUEvalue_name = ServiceDllTrue5
Fn
READ_VALUEFalse2523
Fn
READ_VALUEvalue_name = ServiceManifestFalse5
Fn
READ_VALUEvalue_name = ServiceMainTrue4
Fn
READ_VALUEvalue_name = ServiceDllUnloadOnStopFalse4
Fn
READ_VALUEvalue_name = ActivePowerSchemeTrue6
Fn
READ_VALUEvalue_name = ValueMinFalse1568
Fn
READ_VALUEvalue_name = ACSettingIndexTrue952
Fn
READ_VALUEvalue_name = SettingValueTrue261
Fn
READ_VALUEvalue_name = DCSettingIndexTrue326
Fn
READ_VALUEvalue_name = ValueMinTrue1984
Fn
READ_VALUEvalue_name = ValueMaxTrue1984
Fn
READ_VALUEvalue_name = ValueIncrementTrue936
Fn
READ_VALUEvalue_name = ServiceMainFalse3
Fn
READ_VALUEvalue_name = PageAllocatorUseSystemHeapFalse1
Fn
READ_VALUEvalue_name = PageAllocatorSystemHeapIsPrivateFalse1
Fn
READ_VALUEvalue_name = AggressiveMTATestingFalse1
Fn
READ_VALUEvalue_name = ActivationFailureLoggingLevelFalse2
Fn
READ_VALUEvalue_name = CallFailureLoggingLevelFalse2
Fn
READ_VALUEvalue_name = InvalidSecurityDescriptorLoggingLevelFalse2
Fn
READ_VALUEvalue_name = DisableActivationSecurityCheckFalse2
Fn
READ_VALUEvalue_name = UseRunAsTokenCacheFalse2
Fn
READ_VALUEvalue_name = IssueActivationRpcAtIdentifyFalse2
Fn
READ_VALUEvalue_name = ResumeTimeoutFalse2
Fn
READ_VALUEvalue_name = DoNotAddAllApplicationPackagesToRestrictionsFalse2
Fn
READ_VALUEvalue_name = DefaultLaunchPermissionTrue6
Fn
READ_VALUEvalue_name = MachineLaunchRestrictionFalse6
Fn
READ_VALUEvalue_name = MachineLaunchRestrictionTrue3
Fn
READ_VALUEvalue_name = MachineAccessRestrictionFalse6
Fn
READ_VALUEvalue_name = MachineAccessRestrictionTrue3
Fn
READ_VALUEvalue_name = RemoteHandleCacheMaxSizeFalse1
Fn
READ_VALUEvalue_name = RemoteHandleCacheMaxLifetimeFalse1
Fn
READ_VALUEvalue_name = RemoteHandleCacheMaxIdleTimeoutFalse1
Fn
READ_VALUEvalue_name = StaleMidTimeoutFalse1
Fn
READ_VALUEvalue_name = SRPRunningObjectChecksFalse1
Fn
READ_VALUEvalue_name = SRPActivateAsActivatorChecksFalse1
Fn
READ_VALUEvalue_name = EnableSystemDynamicIPTrackingFalse1
Fn
READ_VALUEvalue_name = EnableEELoggingFalse2
Fn
READ_VALUEvalue_name = LogEEInfoAsNativeFalse2
Fn
READ_VALUEvalue_name = SecurityProvidersFalse1
Fn
READ_VALUEvalue_name = DCOM SecurityFalse2
Fn
READ_VALUEvalue_name = EnableDCOMTrue2
Fn
READ_VALUEvalue_name = OleModalLoopBehaviorFalse2
Fn
READ_VALUEvalue_name = DCOMSCMRemoteCallFlagsFalse2
Fn
READ_VALUEvalue_name = BreakOnUnexpectedActivationErrorsFalse2
Fn
READ_VALUEvalue_name = EnableDCOMHTTPFalse2
Fn
READ_VALUEvalue_name = IgnoreServerExceptionsFalse2
Fn
READ_VALUEvalue_name = BreakOnSilencedServerExceptionsFalse2
Fn
READ_VALUEvalue_name = LegacyAuthenticationServiceFalse2
Fn
READ_VALUEvalue_name = LegacyAuthenticationLevelFalse2
Fn
READ_VALUEvalue_name = LegacyImpersonationLevelTrue2
Fn
READ_VALUEvalue_name = LegacyMutualAuthenticationFalse2
Fn
READ_VALUEvalue_name = LegacySecureReferencesFalse2
Fn
READ_VALUEvalue_name = MaxActivationRetriesPerServerFalse2
Fn
READ_VALUEvalue_name = REGDBVersionFalse2
Fn
READ_VALUE\Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySidevalue_name = PreferExternalManifestFalse1
Fn
READ_VALUEvalue_name = DebuglsmFalse9
Fn
READ_VALUEvalue_name = DebugFalse81
Fn
READ_VALUEvalue_name = CaptureStackTraceFalse81
Fn
READ_VALUEvalue_name = DebuglsmFlagsFalse9
Fn
READ_VALUEvalue_name = DebugFlagsFalse81
Fn
READ_VALUEvalue_name = DebuglsmLevelFalse9
Fn
READ_VALUEvalue_name = DebugLevelFalse81
Fn
READ_VALUEvalue_name = DebuglsmToDebuggerFalse9
Fn
READ_VALUEvalue_name = DebugToDebuggerFalse81
Fn
READ_VALUEvalue_name = DebugtermsrvFalse9
Fn
READ_VALUEvalue_name = DebugtermsrvFlagsFalse9
Fn
READ_VALUEvalue_name = DebugtermsrvLevelFalse9
Fn
READ_VALUEvalue_name = DebugtermsrvToDebuggerFalse9
Fn
READ_VALUEvalue_name = DebugsdclientFalse9
Fn
READ_VALUEvalue_name = DebugsdclientFlagsFalse9
Fn
READ_VALUEvalue_name = DebugsdclientLevelFalse9
Fn
READ_VALUEvalue_name = DebugsdclientToDebuggerFalse9
Fn
READ_VALUEvalue_name = DebugwinstaFalse9
Fn
READ_VALUEvalue_name = DebugwinstaFlagsFalse9
Fn
READ_VALUEvalue_name = DebugwinstaLevelFalse9
Fn
READ_VALUEvalue_name = DebugwinstaToDebuggerFalse9
Fn
READ_VALUEvalue_name = DebugtsrpcFalse9
Fn
READ_VALUEvalue_name = DebugtsrpcFlagsFalse9
Fn
READ_VALUEvalue_name = DebugtsrpcLevelFalse9
Fn
READ_VALUEvalue_name = DebugtsrpcToDebuggerFalse9
Fn
READ_VALUEvalue_name = DebugsessionenvFalse9
Fn
READ_VALUEvalue_name = DebugsessionenvFlagsFalse9
Fn
READ_VALUEvalue_name = DebugsessionenvLevelFalse9
Fn
READ_VALUEvalue_name = DebugsessionenvToDebuggerFalse9
Fn
READ_VALUEvalue_name = DebugsessionmsgFalse9
Fn
READ_VALUEvalue_name = DebugsessionmsgFlagsFalse9
Fn
READ_VALUEvalue_name = DebugsessionmsgLevelFalse9
Fn
READ_VALUEvalue_name = DebugsessionmsgToDebuggerFalse9
Fn
READ_VALUEvalue_name = DebugTSVIPCliFalse9
Fn
READ_VALUEvalue_name = DebugTSVIPCliFlagsFalse9
Fn
READ_VALUEvalue_name = DebugTSVIPCliLevelFalse9
Fn
READ_VALUEvalue_name = DebugTSVIPCliToDebuggerFalse9
Fn
READ_VALUEvalue_name = DebugTSVIPSrvFalse9
Fn
READ_VALUEvalue_name = DebugTSVIPSrvFlagsFalse9
Fn
READ_VALUEvalue_name = DebugTSVIPSrvLevelFalse9
Fn
READ_VALUEvalue_name = DebugTSVIPSrvToDebuggerFalse9
Fn
READ_VALUEvalue_name = TSAppCompatFalse1
Fn
READ_VALUEvalue_name = DebugTSFalse1
Fn
READ_VALUEvalue_name = LSMBreakOnStartFalse1
Fn
READ_VALUEvalue_name = ConsoleSecurityFalse4
Fn
READ_VALUEvalue_name = ConsoleSecurityTrue2
Fn
READ_VALUEvalue_name = LSMGlobalSettingFalse1
Fn
READ_VALUEvalue_name = 9True1
Fn
READ_VALUEvalue_name = DelayReadyEventTimeoutFalse1
Fn
READ_VALUEvalue_name = TSServerDrainModeFalse1
Fn
READ_VALUEvalue_name = DelayConMgrTimeoutTrue1
Fn
READ_VALUEvalue_name = SystemSetupInProgressTrue6
Fn
READ_VALUEvalue_name = NoParamValidationFalse1
Fn
READ_VALUEvalue_name = RegisterPrivateEnabledFalse1
Fn
READ_VALUEvalue_name = ServiceDllUnloadOnStopTrue1
Fn
READ_VALUESystem\CurrentControlSet\Control\Power\SecurityDescriptorsvalue_name = ActivePowerSchemeFalse2
Fn
READ_VALUESystem\CurrentControlSet\Control\Power\SecurityDescriptorsvalue_name = DefaultFalse3
Fn
READ_VALUESystem\CurrentControlSet\Control\Power\SecurityDescriptorsvalue_name = DefaultTrue1
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemesvalue_name = ValueMinFalse85
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74dvalue_name = ACSettingIndexTrue34
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74dvalue_name = DCSettingIndexTrue10
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemesvalue_name = ACSettingIndexTrue62
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74dvalue_name = SettingValueTrue31
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74dvalue_name = ValueMinTrue67
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74dvalue_name = ValueMaxTrue67
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74dvalue_name = ValueIncrementTrue48
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74dvalue_name = ValueMinFalse59
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemesvalue_name = ValueMinTrue269
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemesvalue_name = ValueMaxTrue269
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemesvalue_name = ValueIncrementTrue144
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemesvalue_name = DCSettingIndexTrue4
Fn
READ_VALUESoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemesvalue_name = SettingValueTrue12
Fn
WRITE_VALUETrue4
Fn
WRITE_VALUEvalue_name = InstanceID, data = 4b2993a7-bd9a-4070-9e94-6969c10True1
Fn
WRITE_VALUEvalue_name = GlassSessionId, data = 1True1
Fn
WRITE_VALUEvalue_name = WinStationsDisabled, data = 0True1
Fn
WRITE_VALUESoftware\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemesvalue_name = ActivePowerScheme, data = 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635cTrue1
Fn
DELETE_TREETrue1
Fn
Driver (128)
+
OperationDriverAdditional InformationSuccessAmountLogfile
CONTROLTrue1
Fn
CONTROLcontrol_code = 0x390008True1
Fn
CONTROLcontrol_code = 0x110008False1
Fn
CONTROL\device\deviceapi\cmapicontrol_code = 0x470803True1
Fn
CONTROL\device\deviceapi\cmapicontrol_code = 0x470813True42
Fn
CONTROL\device\deviceapi\cmapicontrol_code = 0x47081bTrue82
Fn
System (282)
+
OperationInformationSuccessAmountLogfile
SLEEPTrue132
Fn
SLEEPduration = 1 milliseconds (0.001 seconds)True132
Fn
SLEEPFalse2
Fn
SLEEPduration = 1 milliseconds (0.001 seconds)False2
Fn
GET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
GET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue7
Fn
GET_INFOTrue1
Fn
GET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue4
Fn
GET_INFOtype = SYSTEM_TIME_OF_DAY_INFORMATIONTrue1
Fn
Mutex (136)
+
OperationNameAdditional InformationSuccessAmountLogfile
CREATETrue5
Fn
CREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue4
Fn
CREATEGlobal\{A3BD3259-3E4F-428a-84C8-F0463A9D3EB5}initial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
RELEASETrue126
Fn
Process #13: svchost.exe
(Host: 310, Network: 0)
+
InformationValue
ID / OS PID#13 / 0x238
OS Parent PID0x1ac (c:\windows\system32\csrss.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exe
Command LineX:\windows\system32\svchost.exe -k RPCSS
MonitorStart Time: 00:01:52, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:15
OS Thread IDs
#102
0x23C
#103
0x240
#104
0x244
#105
0x248
#107
0x250
#108
0x254
#112
0x264
#129
0x2C0
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x000000f0520000000xf0520000000xf05201ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000f0520000000xf0520000000xf05200ffffPagefile Backed FileReadable, WritableTrue
private_0x000000f0520100000xf0520100000xf052016fffPrivate MemoryReadable, WritableTrue
pagefile_0x000000f0520200000xf0520200000xf05202efffPagefile Backed FileReadableTrue
private_0x000000f0520300000xf0520300000xf0520affffPrivate MemoryReadable, WritableTrue
pagefile_0x000000f0520b00000xf0520b00000xf0520b3fffPagefile Backed FileReadableTrue
pagefile_0x000000f0520c00000xf0520c00000xf0520c0fffPagefile Backed FileReadableTrue
private_0x000000f0520d00000xf0520d00000xf0520d1fffPrivate MemoryReadable, WritableTrue
locale.nls0xf0520e00000xf05215dfffMemory Mapped FileReadableFalse
private_0x000000f0521600000xf0521600000xf05225ffffPrivate MemoryReadable, WritableTrue
private_0x000000f0522600000xf0522600000xf0522dffffPrivate MemoryReadable, WritableTrue
private_0x000000f0522e00000xf0522e00000xf05235ffffPrivate MemoryReadable, WritableTrue
private_0x000000f0522e00000xf0522e00000xf0522e6fffPrivate MemoryReadable, WritableTrue
sortdefault.nls0xf0523600000xf052634fffMemory Mapped FileReadableFalse
private_0x000000f0526400000xf0526400000xf0526bffffPrivate MemoryReadable, WritableTrue
private_0x000000f0526c00000xf0526c00000xf05273ffffPrivate MemoryReadable, WritableTrue
private_0x000000f0527c00000xf0527c00000xf0527cffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007df5ffd300000x7df5ffd300000x7ff5ffd2ffffPagefile Backed File-True
pagefile_0x00007ff7ca1e00000x7ff7ca1e00000x7ff7ca2dffffPagefile Backed FileReadableTrue
pagefile_0x00007ff7ca2e00000x7ff7ca2e00000x7ff7ca302fffPagefile Backed FileReadableTrue
private_0x00007ff7ca3030000x7ff7ca3030000x7ff7ca303fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7ca3080000x7ff7ca3080000x7ff7ca309fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7ca30a0000x7ff7ca30a0000x7ff7ca30bfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7ca30a0000x7ff7ca30a0000x7ff7ca30bfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7ca30c0000x7ff7ca30c0000x7ff7ca30dfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7ca30e0000x7ff7ca30e0000x7ff7ca30ffffPrivate MemoryReadable, WritableTrue
svchost.exe0x7ff7ca8100000x7ff7ca81cfffMemory Mapped FileReadable, Writable, ExecutableFalse
RpcRtRemote.dll0x7ffb707000000x7ffb70712fffMemory Mapped FileReadable, Writable, ExecutableFalse
RpcEpMap.dll0x7ffb707200000x7ffb70735fffMemory Mapped FileReadable, Writable, ExecutableFalse
rpcss.dll0x7ffb707400000x7ffb7080bfffMemory Mapped FileReadable, Writable, ExecutableFalse
rsaenh.dll0x7ffb70b000000x7ffb70b35fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTSP.dll0x7ffb710400000x7ffb7105ffffMemory Mapped FileReadable, Writable, ExecutableFalse
bcrypt.dll0x7ffb712600000x7ffb71285fffMemory Mapped FileReadable, Writable, ExecutableFalse
SspiCli.dll0x7ffb715000000x7ffb7152dfffMemory Mapped FileReadable, Writable, ExecutableFalse
powrprof.dll0x7ffb715300000x7ffb71575fffMemory Mapped FileReadable, Writable, ExecutableFalse
bcryptPrimitives.dll0x7ffb715800000x7ffb715e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTBASE.dll0x7ffb715f00000x7ffb715fafffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
WS2_32.dll0x7ffb733600000x7ffb733b9fffMemory Mapped FileReadable, Writable, ExecutableTrue
sechost.dll0x7ffb733c00000x7ffb73418fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
combase.dll0x7ffb737400000x7ffb73950fffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
NSI.dll0x7ffb73e800000x7ffb73e88fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSVCRT.dll0x7ffb740500000x7ffb740f9fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Injection Information
+
Injection TypeSource ProcessSource Os Thread IDInjection InfoSuccessAmountLogfile
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe0x1b0address = 0xf0520d0000, size = 4704True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe0x1b0address = 0x7ff7ca3032d8, size = 8True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Host Behavior
File (4)
+
OperationFilenameAdditional InformationSuccessAmountLogfile
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nlsdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATETrue1
Fn
CREATE\device\ndisdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
OPENc:\desired_access = SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_FREE_SPACE_QUERYTrue1
Fn
Process (13)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
OPEN_TOKENTrue3
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True2
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True2
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True5
Fn
Thread (2)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, proc_address = 0x7ffb733c7ef0, desired_access = THREAD_ALL_ACCESSTrue1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, proc_address = 0x7ffb733c7ef0, desired_access = THREAD_ALL_ACCESSTrue1
Fn
Module (51)
+
OperationModuleAdditional InformationSuccessAmountLogfile
LOADrpcrt4.dllbase_address = 0x0True1
Fn
LOADkernel32.dllbase_address = 0x0True1
Fn
LOADbase_address = 0x7ffb70720000True1
Fn
LOADx:\windows\system32\rpcepmap.dllbase_address = 0x0True1
Fn
LOADsspicli.dllbase_address = 0x0True2
Fn
LOADbase_address = 0x7ffb71500000True1
Fn
LOADbase_address = 0x7ffb70700000True1
Fn
LOADRpcRtRemote.dllbase_address = 0x0True1
Fn
LOADbase_address = 0x7ffb70740000True1
Fn
LOADx:\windows\system32\rpcss.dllbase_address = 0x0True1
Fn
LOADbase_address = 0x7ffb70b00000True1
Fn
LOADX:\windows\system32\rsaenh.dllbase_address = 0x0True1
Fn
GET_HANDLE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exeTrue1
Fn
GET_HANDLErpcrt4.dllTrue2
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xf052360000True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70727e90True1
Fn
GET_PROC_ADDRESSaddress_out = 0x0False2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb73ab8f70True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb73ab9000True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb73b07230True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70701860True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb7078a100True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b01570True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b01080True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b06090True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b1e1d0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b02ce0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b0af70True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b03880True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b03a30True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b03260True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b06be0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b04ea0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b027d0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b02b00True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b1d8d0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b024f0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b06830True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b03c50True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b01030True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b05bb0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b0f290True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b0f750True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b03f50True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b02630True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b0d330True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb70b1d6e0True1
Fn
Service (3)
+
OperationServiceAdditional InformationSuccessAmountLogfile
OPEN_MGRSERVICES_ACTIVE_DATABASEhost = LocalhostTrue1
Fn
REGISTER_HANDLERTrue2
Fn
Registry (216)
+
OperationKeyAdditional InformationSuccessAmountLogfile
CREATE_KEY\REGISTRY\MACHINE\SOFTWARE\CLASSESTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\VersionsTrue1
Fn
OPEN_KEYTrue27
Fn
OPEN_KEYFalse8
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue3
Fn
OPEN_KEY\Registry\Machine\System\SetupTrue2
Fn
OPEN_KEYControl Panel\InternationalTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocaleTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocaleTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\IdsTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versionsvalue_name = 1032168601360True1
Fn
READ_VALUETrue19
Fn
READ_VALUEvalue_name = RPCSSTrue2
Fn
READ_VALUEvalue_name = MaxRpcSizeFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNamevalue_name = ComputerNameTrue3
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = OOBEInProgressFalse1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = SystemSetupInProgressTrue1
Fn
READ_VALUEvalue_name = IdleTimerWindowFalse1
Fn
READ_VALUEControl Panel\InternationalFalse2
Fn
READ_VALUEControl Panel\InternationalTrue2
Fn
READ_VALUEControl Panel\Internationalvalue_name = sCurrencyOverrideFalse2
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocalevalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocalevalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versionsvalue_name = 000602xxTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Idsvalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Idsvalue_name = enFalse1
Fn
READ_VALUEvalue_name = ServiceDllTrue2
Fn
READ_VALUEFalse39
Fn
READ_VALUEvalue_name = ServiceManifestFalse2
Fn
READ_VALUEvalue_name = ServiceMainFalse2
Fn
READ_VALUEvalue_name = ListenOnInternetFalse1
Fn
READ_VALUEvalue_name = 9True1
Fn
READ_VALUEvalue_name = SecurityProvidersFalse1
Fn
READ_VALUEvalue_name = RemoteRpcDllTrue1
Fn
READ_VALUEvalue_name = ServiceDllUnloadOnStopFalse1
Fn
READ_VALUENameless FileMappingvalue_name = PageAllocatorUseSystemHeapFalse1
Fn
READ_VALUEvalue_name = PageAllocatorSystemHeapIsPrivateFalse1
Fn
READ_VALUENameless FileMappingvalue_name = AggressiveMTATestingFalse1
Fn
READ_VALUEvalue_name = ActivationFailureLoggingLevelFalse1
Fn
READ_VALUEvalue_name = CallFailureLoggingLevelFalse1
Fn
READ_VALUEvalue_name = InvalidSecurityDescriptorLoggingLevelFalse1
Fn
READ_VALUEvalue_name = DisableActivationSecurityCheckFalse1
Fn
READ_VALUEvalue_name = UseRunAsTokenCacheFalse1
Fn
READ_VALUEvalue_name = IssueActivationRpcAtIdentifyFalse1
Fn
READ_VALUEvalue_name = ResumeTimeoutFalse1
Fn
READ_VALUEvalue_name = DoNotAddAllApplicationPackagesToRestrictionsFalse1
Fn
READ_VALUEvalue_name = DefaultLaunchPermissionTrue2
Fn
READ_VALUEvalue_name = MachineLaunchRestrictionFalse2
Fn
READ_VALUEvalue_name = MachineLaunchRestrictionTrue1
Fn
READ_VALUEvalue_name = MachineAccessRestrictionFalse2
Fn
READ_VALUEvalue_name = MachineAccessRestrictionTrue1
Fn
READ_VALUEvalue_name = RemoteHandleCacheMaxSizeFalse1
Fn
READ_VALUEvalue_name = RemoteHandleCacheMaxLifetimeFalse1
Fn
READ_VALUEvalue_name = RemoteHandleCacheMaxIdleTimeoutFalse1
Fn
READ_VALUEvalue_name = StaleMidTimeoutFalse1
Fn
READ_VALUEvalue_name = SRPRunningObjectChecksFalse1
Fn
READ_VALUEvalue_name = SRPActivateAsActivatorChecksFalse1
Fn
READ_VALUEvalue_name = EnableSystemDynamicIPTrackingFalse1
Fn
READ_VALUEvalue_name = EnableEELoggingFalse1
Fn
READ_VALUEvalue_name = LogEEInfoAsNativeFalse1
Fn
READ_VALUEvalue_name = DCOM SecurityFalse1
Fn
READ_VALUEvalue_name = EnableDCOMTrue1
Fn
READ_VALUEvalue_name = OleModalLoopBehaviorFalse1
Fn
READ_VALUEvalue_name = DCOMSCMRemoteCallFlagsFalse1
Fn
READ_VALUEvalue_name = BreakOnUnexpectedActivationErrorsFalse1
Fn
READ_VALUEvalue_name = EnableDCOMHTTPFalse1
Fn
READ_VALUEvalue_name = IgnoreServerExceptionsFalse1
Fn
READ_VALUEvalue_name = BreakOnSilencedServerExceptionsFalse1
Fn
READ_VALUEvalue_name = LegacyAuthenticationServiceFalse1
Fn
READ_VALUEvalue_name = LegacyAuthenticationLevelFalse1
Fn
READ_VALUEvalue_name = LegacyImpersonationLevelTrue1
Fn
READ_VALUEvalue_name = LegacyMutualAuthenticationFalse1
Fn
READ_VALUEvalue_name = LegacySecureReferencesFalse1
Fn
READ_VALUEvalue_name = PingIntervalFalse1
Fn
READ_VALUEvalue_name = UserPingSetQuotaFalse1
Fn
READ_VALUEvalue_name = MaxActivationRetriesPerServerFalse1
Fn
READ_VALUEvalue_name = TypeTrue1
Fn
READ_VALUEvalue_name = Image PathTrue4
Fn
READ_VALUEvalue_name = MachineGuidTrue4
Fn
READ_VALUEvalue_name = DCOM ProtocolsTrue1
Fn
READ_VALUEvalue_name = WinSock_Registry_VersionTrue2
Fn
READ_VALUEvalue_name = NameSpace_CalloutTrue2
Fn
READ_VALUEvalue_name = Serial_Access_NumTrue4
Fn
READ_VALUEvalue_name = Next_Catalog_Entry_IDTrue1
Fn
READ_VALUEvalue_name = Num_Catalog_Entries64True2
Fn
READ_VALUEvalue_name = LibraryPathTrue2
Fn
READ_VALUEvalue_name = DisplayStringTrue4
Fn
READ_VALUEvalue_name = ProviderIdTrue1
Fn
READ_VALUEvalue_name = AddressFamilyFalse1
Fn
READ_VALUEvalue_name = SupportedNameSpaceTrue1
Fn
READ_VALUEvalue_name = EnabledTrue1
Fn
READ_VALUEvalue_name = VersionTrue1
Fn
READ_VALUEvalue_name = StoresServiceClassInfoTrue1
Fn
READ_VALUEvalue_name = ProviderInfoTrue2
Fn
READ_VALUEvalue_name = Ws2_32NumHandleBucketsFalse1
Fn
Driver (7)
+
OperationDriverAdditional InformationSuccessAmountLogfile
CONTROLTrue2
Fn
CONTROL\device\ndiscontrol_code = 0x170010True1
Fn
CONTROLcontrol_code = 0x390008True1
Fn
CONTROLcontrol_code = 0x110004True1
Fn
CONTROLcontrol_code = 0x110008False2
Fn
System (14)
+
OperationInformationSuccessAmountLogfile
GET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
GET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue7
Fn
GET_INFOTrue2
Fn
GET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue4
Fn
Process #14: winpeshl.exe
(Host: 641, Network: 0)
+
InformationValue
ID / OS PID#14 / 0x278
OS Parent PID0x194 (\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe
Command Linewinpeshl.exe
MonitorStart Time: 00:01:54, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:13
OS Thread IDs
#116
0x27C
#121
0x28C
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x000000a3b7c800000xa3b7c800000xa3b7c9ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000a3b7c800000xa3b7c800000xa3b7c8ffffPagefile Backed FileReadable, WritableTrue
private_0x000000a3b7c900000xa3b7c900000xa3b7c96fffPrivate MemoryReadable, WritableTrue
pagefile_0x000000a3b7ca00000xa3b7ca00000xa3b7caefffPagefile Backed FileReadableTrue
private_0x000000a3b7cb00000xa3b7cb00000xa3b7d2ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000a3b7d300000xa3b7d300000xa3b7d33fffPagefile Backed FileReadableTrue
private_0x000000a3b7d400000xa3b7d400000xa3b7d41fffPrivate MemoryReadable, WritableTrue
pagefile_0x000000a3b7d500000xa3b7d500000xa3b7d51fffPagefile Backed FileReadableTrue
private_0x000000a3b7d600000xa3b7d600000xa3b7e5ffffPrivate MemoryReadable, WritableTrue
locale.nls0xa3b7e600000xa3b7eddfffMemory Mapped FileReadableFalse
private_0x000000a3b7ee00000xa3b7ee00000xa3b7ee6fffPrivate MemoryReadable, WritableTrue
winpeshl.exe.mui0xa3b7ef00000xa3b7ef0fffMemory Mapped FileReadableFalse
private_0x000000a3b7f000000xa3b7f000000xa3b7f00fffPrivate MemoryReadable, WritableTrue
private_0x000000a3b7f100000xa3b7f100000xa3b7f10fffPrivate MemoryReadable, WritableTrue
SETUPAPI.dll.mui0xa3b7f200000xa3b7f2bfffMemory Mapped FileReadableFalse
newdev.dll.mui0xa3b7f300000xa3b7f36fffMemory Mapped FileReadableFalse
private_0x000000a3b7f900000xa3b7f900000xa3b7f9ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000a3b7fa00000xa3b7fa00000xa3b8127fffPagefile Backed FileReadableTrue
pagefile_0x000000a3b81300000xa3b81300000xa3b82b0fffPagefile Backed FileReadableTrue
pagefile_0x000000a3b82c00000xa3b82c00000xa3b96bffffPagefile Backed FileReadableTrue
private_0x000000a3b96c00000xa3b96c00000xa3b973ffffPrivate MemoryReadable, WritableTrue
private_0x000000a3b98700000xa3b98700000xa3b987ffffPrivate MemoryReadable, WritableTrue
sortdefault.nls0xa3b98800000xa3b9b54fffMemory Mapped FileReadableFalse
pagefile_0x00007ff74d7a00000x7ff74d7a00000x7ff74d89ffffPagefile Backed FileReadableTrue
pagefile_0x00007ff74d8a00000x7ff74d8a00000x7ff74d8c2fffPagefile Backed FileReadableTrue
private_0x00007ff74d8ca0000x7ff74d8ca0000x7ff74d8cafffPrivate MemoryReadable, WritableTrue
private_0x00007ff74d8cc0000x7ff74d8cc0000x7ff74d8cdfffPrivate MemoryReadable, WritableTrue
private_0x00007ff74d8ce0000x7ff74d8ce0000x7ff74d8cffffPrivate MemoryReadable, WritableTrue
winpeshl.exe0x7ff74e4100000x7ff74e498fffMemory Mapped FileReadable, Writable, ExecutableFalse
drvstore.dll0x7ffb6fe500000x7ffb6ff0afffMemory Mapped FileReadable, Writable, ExecutableFalse
SHCORE.DLL0x7ffb701b00000x7ffb70261fffMemory Mapped FileReadable, Writable, ExecutableFalse
MPR.dll0x7ffb702700000x7ffb7028dfffMemory Mapped FileReadable, Writable, ExecutableFalse
wkscli.dll0x7ffb702900000x7ffb702a6fffMemory Mapped FileReadable, Writable, ExecutableFalse
WpeUtil.dll0x7ffb702b00000x7ffb702cefffMemory Mapped FileReadable, Writable, ExecutableFalse
devrtl.DLL0x7ffb702d00000x7ffb702e5fffMemory Mapped FileReadable, Writable, ExecutableFalse
WINNSI.DLL0x7ffb702f00000x7ffb702f9fffMemory Mapped FileReadable, Writable, ExecutableFalse
FLTLIB.DLL0x7ffb703500000x7ffb70359fffMemory Mapped FileReadable, Writable, ExecutableFalse
UNATTEND.DLL0x7ffb703600000x7ffb7039ffffMemory Mapped FileReadable, Writable, ExecutableFalse
Input.dll0x7ffb703a00000x7ffb703e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
newdev.dll0x7ffb703f00000x7ffb70445fffMemory Mapped FileReadable, Writable, ExecutableFalse
IPHLPAPI.DLL0x7ffb704500000x7ffb70479fffMemory Mapped FileReadable, Writable, ExecutableFalse
UxTheme.dll0x7ffb704800000x7ffb705a8fffMemory Mapped FileReadable, Writable, ExecutableFalse
DEVOBJ.dll0x7ffb705b00000x7ffb705d7fffMemory Mapped FileReadable, Writable, ExecutableFalse
spinf.dll0x7ffb709a00000x7ffb709bdfffMemory Mapped FileReadable, Writable, ExecutableFalse
USERENV.dll0x7ffb70dd00000x7ffb70df0fffMemory Mapped FileReadable, Writable, ExecutableFalse
DNSAPI.dll0x7ffb70e400000x7ffb70ee3fffMemory Mapped FileReadable, Writable, ExecutableFalse
profapi.dll0x7ffb716b00000x7ffb716c4fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
CFGMGR32.dll0x7ffb718800000x7ffb718cefffMemory Mapped FileReadable, Writable, ExecutableTrue
Setupapi.dll0x7ffb718d00000x7ffb71aa9fffMemory Mapped FileReadable, Writable, ExecutableTrue
gdi32.dll0x7ffb71ad00000x7ffb71c20fffMemory Mapped FileReadable, Writable, ExecutableTrue
SHELL32.dll0x7ffb71c300000x7ffb73148fffMemory Mapped FileReadable, Writable, ExecutableTrue
SHLWAPI.dll0x7ffb733000000x7ffb73353fffMemory Mapped FileReadable, Writable, ExecutableTrue
WS2_32.dll0x7ffb733600000x7ffb733b9fffMemory Mapped FileReadable, Writable, ExecutableTrue
sechost.dll0x7ffb733c00000x7ffb73418fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
OLEAUT32.dll0x7ffb735c00000x7ffb73680fffMemory Mapped FileReadable, Writable, ExecutableTrue
advapi32.dll0x7ffb736900000x7ffb73739fffMemory Mapped FileReadable, Writable, ExecutableTrue
combase.dll0x7ffb737400000x7ffb73950fffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSCTF.dll0x7ffb73b800000x7ffb73cd2fffMemory Mapped FileReadable, Writable, ExecutableTrue
ole32.dll0x7ffb73ce00000x7ffb73e73fffMemory Mapped FileReadable, Writable, ExecutableTrue
NSI.dll0x7ffb73e800000x7ffb73e88fffMemory Mapped FileReadable, Writable, ExecutableTrue
user32.dll0x7ffb73e900000x7ffb74006fffMemory Mapped FileReadable, Writable, ExecutableTrue
IMM32.dll0x7ffb740100000x7ffb74045fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSVCRT.dll0x7ffb740500000x7ffb740f9fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Injection Information
+
Injection TypeSource ProcessSource Os Thread IDInjection InfoSuccessAmountLogfile
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8address = 0xd9cbf50000, size = 16384True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe0x198address = 0xa3b7d40000, size = 4704True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe0x198address = 0x7ff74d8ca2d8, size = 8True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8address = 0xd9cbf60000, size = 8192True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8No corresponding api call detected. Probably injected code via shellcode.True1
Host Behavior
File (66)
+
OperationFilenameAdditional InformationSuccessAmountLogfile
CREATE\device\deviceapi\cmapidesired_access = GENERIC_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATETrue3
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.logdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN_IF, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exedesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exedesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nlsdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\apps.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\defltbase.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\newdev.dlldesired_access = FILE_READ_DATA, FILE_READ_EA, FILE_READ_ATTRIBUTES, READ_CONTROL, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.inidesired_access = SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue3
Fn
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.inisize = 53True1
Fn
Data
WRITETrue25
Fn
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.logsize = 2True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.logsize = 50True6
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.logsize = 20True6
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.logsize = 72True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.logsize = 4True6
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.logsize = 246True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.logsize = 44True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.logsize = 110True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.logsize = 170True1
Fn
Data
WRITE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.logsize = 58True1
Fn
Data
Process (18)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
CREATETrue2
Fn
CREATEdesired_access = MAXIMUM_ALLOWED, creation_flags = CREATE_NEW_PROCESS_GROUPTrue2
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True3
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True2
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True2
Fn
GET_INFOTrue2
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True4
Fn
Memory (6)
+
OperationAddressAdditional InformationSuccessAmountLogfile
ALLOC0xa3b7d2f2e8process_name = , size = 703163724872, allocation_type = MEM_COMMIT, protection = PAGE_READWRITETrue1
Fn
ALLOC0xa3b7d2f2b8process_name = , size = 703163724824, allocation_type = MEM_COMMIT, protection = PAGE_READWRITETrue1
Fn
WRITE0x6356410000process_name = , size = 4704True1
Fn
Data
WRITE0x7ff618a9a2d8process_name = , size = 8True1
Fn
Data
WRITE0xe5e5420000process_name = , size = 4704True1
Fn
Data
WRITE0x7ff72999c2d8process_name = , size = 8True1
Fn
Data
Thread (3)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, proc_address = 0x7ff74e412780, desired_access = THREAD_ALL_ACCESSTrue1
Fn
RESUMETrue2
Fn
Module (44)
+
OperationModuleAdditional InformationSuccessAmountLogfile
LOADbase_address = 0x7ffb73e90000True1
Fn
LOADuser32.dllbase_address = 0x0True1
Fn
LOADbase_address = 0x7ffb74120000True1
Fn
LOADntdll.dllbase_address = 0x0True1
Fn
LOADkernel32.dllbase_address = 0x0True1
Fn
GET_HANDLEX:\windows\system32\IMM32.DLLTrue2
Fn
GET_HANDLErpcrt4.dllTrue1
Fn
GET_HANDLEX:\windows\system32\oleaut32.dllTrue1
Fn
GET_HANDLEext-ms-win-ole32-oleautomation-l1-1-0.dllTrue1
Fn
GET_HANDLE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exeTrue4
Fn
GET_HANDLEadvapi32.dllTrue1
Fn
GET_HANDLEntdll.dllTrue1
Fn
GET_HANDLEkernel32.dllTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingTrue2
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\apps.inf, maximum_size = 703191041456, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\defltbase.inf, maximum_size = 703191041456, protection = PAGE_READONLYTrue1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xa3b9740000False1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xa3b9880000True1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exeos_pid = 0x278, address = 0xa3b7f40000True2
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xa3b7f40000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xa3b7f40000True1
Fn
UNMAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, base_address = 0xa3b9740000True1
Fn
UNMAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exeos_pid = 0x278True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb741751c0True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb7413b300True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb7413c360True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb74175650True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb73483210True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb73e91700True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb73e91b00True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb74190030True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb741e0720True1
Fn
Registry (78)
+
OperationKeyAdditional InformationSuccessAmountLogfile
OPEN_KEY\Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySideTrue3
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\VersionsTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Error Message Instrument\False1
Fn
OPEN_KEY\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_InitializeTrue1
Fn
OPEN_KEYTrue8
Fn
OPEN_KEY\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocaleTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocaleTrue1
Fn
OPEN_KEY\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDllsFalse1
Fn
OPEN_KEY\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\OptionFalse1
Fn
OPEN_KEY\Registry\Machine\System\SetupTrue2
Fn
OPEN_KEY\REGISTRY\MACHINETrue6
Fn
OPEN_KEY\REGISTRY\MACHINE\System\SetupTrue1
Fn
OPEN_KEY\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Control\MiniNTTrue1
Fn
OPEN_KEY\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\SetupTrue2
Fn
OPEN_KEY\REGISTRY\MACHINE\Software\Microsoft\EmbeddedNT\SecurityFalse1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\IdsTrue1
Fn
OPEN_KEY\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\DeviceInstallFalse1
Fn
OPEN_KEYControl Panel\InternationalTrue1
Fn
READ_VALUE\Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySidevalue_name = PreferExternalManifestFalse3
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versionsvalue_name = 703163720896True1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initializevalue_name = DisableMetaFilesFalse1
Fn
READ_VALUEvalue_name = LoadAppInit_DLLsTrue1
Fn
READ_VALUEvalue_name = PageAllocatorUseSystemHeapFalse1
Fn
READ_VALUEvalue_name = PageAllocatorSystemHeapIsPrivateFalse1
Fn
READ_VALUEvalue_name = AggressiveMTATestingFalse1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRvalue_name = DisableTrue1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRvalue_name = SourcePathFalse1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRvalue_name = DevicePathTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocalevalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocalevalue_name = en-USFalse1
Fn
READ_VALUETrue6
Fn
READ_VALUEvalue_name = SystemSetupInProgressTrue1
Fn
READ_VALUEvalue_name = InstRootTrue2
Fn
READ_VALUEFalse2
Fn
READ_VALUEvalue_name = DisableExtraFontsFalse1
Fn
READ_VALUEvalue_name = CustomBackgroundTrue3
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = 140717948767312False1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = ShimEnableFalse1
Fn
READ_VALUEvalue_name = DisableRemovableStorageInitFalse1
Fn
READ_VALUE\REGISTRY\MACHINE\System\Setupvalue_name = SystemSetupInProgressTrue1
Fn
READ_VALUE\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Setupvalue_name = MinimizeFootprintTrue1
Fn
READ_VALUE\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Setupvalue_name = LogLevelTrue1
Fn
READ_VALUE\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Setupvalue_name = LogMaskFalse1
Fn
READ_VALUE\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Setupvalue_name = LogMaxFileSizeFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versionsvalue_name = 000602xxTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Idsvalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Idsvalue_name = enFalse1
Fn
READ_VALUEControl Panel\InternationalFalse1
Fn
READ_VALUEControl Panel\InternationalTrue1
Fn
READ_VALUEControl Panel\Internationalvalue_name = sCurrencyOverrideFalse1
Fn
Driver (309)
+
OperationDriverAdditional InformationSuccessAmountLogfile
CONTROL\device\deviceapi\cmapicontrol_code = 0x470803True1
Fn
CONTROL\device\deviceapi\cmapicontrol_code = 0x470843True42
Fn
CONTROL\device\deviceapi\cmapicontrol_code = 0x470813True45
Fn
CONTROL\device\deviceapi\cmapicontrol_code = 0x470827True15
Fn
CONTROLTrue103
Fn
CONTROLcontrol_code = 0x470813True101
Fn
CONTROLcontrol_code = 0x47086bTrue2
Fn
System (75)
+
OperationInformationSuccessAmountLogfile
SLEEPTrue23
Fn
SLEEPduration = 1 milliseconds (0.001 seconds)True43
Fn
GET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
GET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue6
Fn
GET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue2
Fn
Mutex (41)
+
OperationNameAdditional InformationSuccessAmountLogfile
CREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue11
Fn
CREATETrue8
Fn
RELEASETrue22
Fn
Ini (1)
+
OperationFilenameAdditional InformationSuccessAmountLogfile
READWin.iniTrue1
Fn
Process #15: winlogon.exe
+
InformationValue
ID / OS PID#15 / 0x26c
OS Parent PID0x194 (\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe
Command Linewinlogon.exe
MonitorStart Time: 00:01:54, Reason: Child Process
UnmonitorEnd Time: 00:01:54, Reason: Terminated
Monitor Duration00:00:00
OS Thread IDs
RemarksNo high level activity detected in monitored regions
Process #16: wallpaperhost.exe
(Host: 1938, Network: 0)
+
InformationValue
ID / OS PID#16 / 0x290
OS Parent PID0x278 (\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wallpaperhost.exe
Command LineX:\windows\system32\WallpaperHost.exe
MonitorStart Time: 00:01:55, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:12
OS Thread IDs
#122
0x294
#124
0x2A0
#125
0x2A4
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x00000063563400000x63563400000x635635ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000063563400000x63563400000x635634ffffPagefile Backed FileReadable, WritableTrue
private_0x00000063563500000x63563500000x6356356fffPrivate MemoryReadable, WritableTrue
pagefile_0x00000063563600000x63563600000x635636efffPagefile Backed FileReadableTrue
private_0x00000063563700000x63563700000x63563effffPrivate MemoryReadable, WritableTrue
pagefile_0x00000063563f00000x63563f00000x63563f3fffPagefile Backed FileReadableTrue
pagefile_0x00000063564000000x63564000000x6356402fffPagefile Backed FileReadableTrue
private_0x00000063564100000x63564100000x6356411fffPrivate MemoryReadable, WritableTrue
locale.nls0x63564200000x635649dfffMemory Mapped FileReadableFalse
private_0x00000063564a00000x63564a00000x63564affffPrivate MemoryReadable, WritableTrue
private_0x00000063564b00000x63564b00000x63564b6fffPrivate MemoryReadable, WritableTrue
private_0x00000063564c00000x63564c00000x63564c0fffPrivate MemoryReadable, WritableTrue
private_0x00000063564c00000x63564c00000x63564c0fffPrivate MemoryReadable, WritableTrue
private_0x00000063564d00000x63564d00000x63564d0fffPrivate MemoryReadable, WritableTrue
pagefile_0x00000063564e00000x63564e00000x63564e0fffPagefile Backed FileReadableTrue
pagefile_0x00000063564f00000x63564f00000x63564f0fffPagefile Backed FileReadable, WritableTrue
SETUPAPI.dll.mui0x63565000000x635650bfffMemory Mapped FileReadableFalse
pagefile_0x00000063565100000x63565100000x6356510fffPagefile Backed FileReadable, WritableTrue
private_0x00000063565200000x63565200000x6356520fffPrivate MemoryReadable, WritableTrue
private_0x00000063565200000x63565200000x6356520fffPrivate MemoryReadable, WritableTrue
pagefile_0x00000063565300000x63565300000x6356530fffPagefile Backed FileReadable, WritableTrue
pagefile_0x00000063565300000x63565300000x6356530fffPagefile Backed FileReadable, WritableTrue
private_0x00000063565600000x63565600000x635665ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000063566600000x63566600000x63567e7fffPagefile Backed FileReadableTrue
pagefile_0x00000063567f00000x63567f00000x6356970fffPagefile Backed FileReadableTrue
pagefile_0x00000063569800000x63569800000x6357d7ffffPagefile Backed FileReadableTrue
sortdefault.nls0x6357d800000x6358054fffMemory Mapped FileReadableFalse
private_0x00000063580600000x63580600000x63580dffffPrivate MemoryReadable, WritableTrue
private_0x00000063580e00000x63580e00000x635815ffffPrivate MemoryReadable, WritableTrue
private_0x00000063581600000x63581600000x635825ffffPrivate MemoryReadable, WritableTrue
private_0x00000063581600000x63581600000x635825ffffPrivate MemoryReadable, WritableTrue
private_0x00000063581600000x63581600000x635825ffffPrivate MemoryReadable, WritableTrue
private_0x00000063582600000x63582600000x635855ffffPrivate MemoryReadable, WritableTrue
shell32.dll.mui0x63585600000x63585c5fffMemory Mapped FileReadableFalse
pagefile_0x00007df5ff8e00000x7df5ff8e00000x7ff5ff8dffffPagefile Backed File-True
pagefile_0x00007ff6189700000x7ff6189700000x7ff618a6ffffPagefile Backed FileReadableTrue
pagefile_0x00007ff618a700000x7ff618a700000x7ff618a92fffPagefile Backed FileReadableTrue
private_0x00007ff618a980000x7ff618a980000x7ff618a99fffPrivate MemoryReadable, WritableTrue
private_0x00007ff618a9a0000x7ff618a9a0000x7ff618a9afffPrivate MemoryReadable, WritableTrue
private_0x00007ff618a9c0000x7ff618a9c0000x7ff618a9dfffPrivate MemoryReadable, WritableTrue
private_0x00007ff618a9e0000x7ff618a9e0000x7ff618a9ffffPrivate MemoryReadable, WritableTrue
WallpaperHost.exe0x7ff6198400000x7ff619846fffMemory Mapped FileReadable, Writable, ExecutableFalse
WindowsCodecs.dll0x7ffb6f9000000x7ffb6faadfffMemory Mapped FileReadable, Writable, ExecutableFalse
WindowsCodecs.dll0x7ffb6f9000000x7ffb6faadfffMemory Mapped FileReadable, Writable, ExecutableFalse
WINBRAND.dll0x7ffb6faa00000x7ffb6faadfffMemory Mapped FileReadable, Writable, ExecutableFalse
propsys.dll0x7ffb6fab00000x7ffb6fc2efffMemory Mapped FileReadable, Writable, ExecutableFalse
WLDP.DLL0x7ffb6fc300000x7ffb6fc3cfffMemory Mapped FileReadable, Writable, ExecutableFalse
kernel.appcore.dll0x7ffb6fe400000x7ffb6fe4afffMemory Mapped FileReadable, Writable, ExecutableFalse
SHCORE.DLL0x7ffb701b00000x7ffb70261fffMemory Mapped FileReadable, Writable, ExecutableFalse
winsta.dll0x7ffb709400000x7ffb70999fffMemory Mapped FileReadable, Writable, ExecutableFalse
bcryptPrimitives.dll0x7ffb715800000x7ffb715e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTBASE.dll0x7ffb715f00000x7ffb715fafffMemory Mapped FileReadable, Writable, ExecutableFalse
profapi.dll0x7ffb716b00000x7ffb716c4fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
CFGMGR32.dll0x7ffb718800000x7ffb718cefffMemory Mapped FileReadable, Writable, ExecutableTrue
Setupapi.dll0x7ffb718d00000x7ffb71aa9fffMemory Mapped FileReadable, Writable, ExecutableTrue
gdi32.dll0x7ffb71ad00000x7ffb71c20fffMemory Mapped FileReadable, Writable, ExecutableTrue
SHELL32.dll0x7ffb71c300000x7ffb73148fffMemory Mapped FileReadable, Writable, ExecutableTrue
SHLWAPI.dll0x7ffb733000000x7ffb73353fffMemory Mapped FileReadable, Writable, ExecutableTrue
sechost.dll0x7ffb733c00000x7ffb73418fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
OLEAUT32.dll0x7ffb735c00000x7ffb73680fffMemory Mapped FileReadable, Writable, ExecutableTrue
advapi32.dll0x7ffb736900000x7ffb73739fffMemory Mapped FileReadable, Writable, ExecutableTrue
combase.dll0x7ffb737400000x7ffb73950fffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSCTF.dll0x7ffb73b800000x7ffb73cd2fffMemory Mapped FileReadable, Writable, ExecutableTrue
ole32.dll0x7ffb73ce00000x7ffb73e73fffMemory Mapped FileReadable, Writable, ExecutableTrue
user32.dll0x7ffb73e900000x7ffb74006fffMemory Mapped FileReadable, Writable, ExecutableTrue
IMM32.dll0x7ffb740100000x7ffb74045fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSVCRT.dll0x7ffb740500000x7ffb740f9fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Injection Information
+
Injection TypeSource ProcessSource Os Thread IDInjection InfoSuccessAmountLogfile
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8address = 0xd9cbf60000, size = 12288True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe0x27caddress = 0x6356410000, size = 4704True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe0x27caddress = 0x7ff618a9a2d8, size = 8True1
Fn
Data
Host Behavior
File (864)
+
OperationFilenameAdditional InformationSuccessAmountLogfile
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nlsdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofiledesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False262
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roamingdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False261
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themesdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False261
Fn
CREATETrue4
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winre.jpgdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True4
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winre.jpgdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True3
Fn
CREATE\device\mountpointmanagerdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True9
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\desired_access = FILE_READ_DATA, FILE_READ_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windowsdesired_access = FILE_READ_DATA, FILE_READ_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32desired_access = FILE_READ_DATA, FILE_READ_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\deviceapi\cmapidesired_access = GENERIC_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\local\microsoft\windows\cachesdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windowsdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\configdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdatadesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\localdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\local\microsoftdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\local\microsoft\windowsdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\local\microsoft\windows\cachesdesired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
CREATEFalse3
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\local\microsoft\windows\caches\cversions.1.dbdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\desktop\desktop.inidesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\documents\desktop.inidesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\music\desktop.inidesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\pictures\desktop.inidesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\videos\desktop.inidesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False2
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\downloads\desktop.inidesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False2
Fn
CREATE_DIRFalse8
Fn
CREATE_DIRTrue3
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue2
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, open_options = FILE_SYNCHRONOUS_IO_ALERTTrue2
Fn
OPENc:desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
OPENc:desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, open_options = FILE_SYNCHRONOUS_IO_ALERTTrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\local\microsoft\windows\cachesdesired_access = READ_CONTROL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_OPEN_REPARSE_POINTTrue4
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\local\microsoft\windows\caches\{afbf9f1a-8ee8-4c77-af34-c647e37ca0d9}.1.ver0x0000000000000000.dbdesired_access = FILE_READ_ATTRIBUTES, DELETE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_NON_DIRECTORY_FILE, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINTFalse1
Fn
DELETEFalse1
Fn
READTrue2
Fn
READ\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winre.jpgsize = 4096True2
Fn
Data
Process (52)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
OPEN_TOKENTrue22
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True7
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True2
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True10
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True6
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True3
Fn
Thread (1)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
CREATE_WORKITEMTrue1
Fn
Module (89)
+
OperationModuleAdditional InformationSuccessAmountLogfile
LOADX:\windows\system32\IMM32.DLLbase_address = 0x0True1
Fn
LOADX:\windows\system32\shell32.dllbase_address = 0x0True1
Fn
LOADrpcrt4.dllbase_address = 0x0True1
Fn
LOADkernel32.dllbase_address = 0x0True1
Fn
LOADWLDP.DLLFalse1
Fn
LOADX:\windows\system32\propsys.dllFalse1
Fn
LOADbase_address = 0x7ffb6fab0000True1
Fn
LOADX:\windows\system32\ole32.dllbase_address = 0x0True1
Fn
LOADX:\windows\system32\windowscodecs.dllFalse2
Fn
LOADWLDP.DLLbase_address = 0x0True4
Fn
LOADbase_address = 0x0False4
Fn
GET_HANDLErpcrt4.dllTrue1
Fn
GET_HANDLEX:\windows\system32\IMM32.DLLFalse1
Fn
GET_HANDLEX:\windows\system32\IMM32.DLLTrue2
Fn
GET_HANDLEX:\windows\system32\oleaut32.dllFalse1
Fn
GET_HANDLE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wallpaperhost.exeTrue4
Fn
GET_HANDLEX:\windows\system32\rpcss.dllFalse1
Fn
GET_HANDLEcombase.dllTrue1
Fn
GET_HANDLEntdll.dllTrue27
Fn
GET_HANDLEext-ms-win-ole32-oleautomation-l1-1-0.dllTrue1
Fn
GET_HANDLEUSER32.dllTrue1
Fn
CREATE_MAPPINGNameless FileMappingTrue4
Fn
CREATE_MAPPINGwindows_shell_global_countersmodule_name = rpcrt4.dll, maximum_size = 426648726032, protection = PAGE_READWRITETrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winre.jpg, maximum_size = 426648714144, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winre.jpg, maximum_size = 0, protection = PAGE_READONLYTrue3
Fn
CREATE_MAPPINGGlobal\windows_shell_global_countersreg_name = \REGISTRY\MACHINE\Software\Classes\ActivatableClasses\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}, maximum_size = 426648702736, protection = PAGE_READWRITETrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winre.jpg, maximum_size = 426648713904, protection = PAGE_READONLYTrue1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, address = 0x63564e0000True1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wallpaperhost.exeos_pid = 0x290, address = 0x63564f0000True1
Fn
MAPwindows_shell_global_countersprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x63564f0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x6357d80000True1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wallpaperhost.exeos_pid = 0x290, address = 0x6356500000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x6356500000True2
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wallpaperhost.exeos_pid = 0x290, address = 0x6356510000True1
Fn
MAPGlobal\windows_shell_global_countersprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x6356510000True1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wallpaperhost.exeos_pid = 0x290, address = 0x6356520000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x6356520000True3
Fn
UNMAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wallpaperhost.exeos_pid = 0x290True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb7413b300True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb7413c360True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb74175650True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb741751c0True1
Fn
Com (24)
+
OperationClassInterfaceAdditional InformationSuccessAmountLogfile
CREATETrue1
Fn
CREATE{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}IClassFactoryTrue1
Fn
QUERY{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}IClassFactorynew_interface = {ECF31D61-E474-453C-BEE7-DE68E441C6D0}, True1
Fn
QUERY{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}{ECF31D61-E474-453C-BEE7-DE68E441C6D0}new_interface = {ECF31D61-E474-453C-BEE7-DE68E441C6D0}False1
Fn
METHODIUnknownmethod = AddRefFalse6
Fn
METHODIPersistmethod = GetClassIDTrue2
Fn
METHOD{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}IClassFactorymethod = CreateInstanceTrue1
Fn
METHOD{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}{ECF31D61-E474-453C-BEE7-DE68E441C6D0}method = AddRefFalse2
Fn
Registry (805)
+
OperationKeyAdditional InformationSuccessAmountLogfile
CREATE_KEYControl Panel\DesktopTrue4
Fn
CREATE_KEY\REGISTRY\MACHINE\SOFTWARE\CLASSESTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\VersionsTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Error Message Instrument\False1
Fn
OPEN_KEY\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_InitializeTrue1
Fn
OPEN_KEYHKEY_USERS\S-1-5-18_ClassesFalse3
Fn
OPEN_KEY\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\CLSIDTrue1
Fn
OPEN_KEY\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\CLSID\{75048700-EF1F-11D0-9888-006097DEACF9}False1
Fn
OPEN_KEY\REGISTRY\MACHINE\Software\Classes\ActivatableClasses\CLSIDTrue1
Fn
OPEN_KEY\REGISTRY\MACHINE\Software\Classes\ActivatableClasses\CLSID\{75048700-EF1F-11D0-9888-006097DEACF9}False1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocaleTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocaleTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocale\Control Panel\InternationalTrue1
Fn
OPEN_KEYTrue32
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
OPEN_KEY\Registry\Machine\System\SetupTrue2
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\IdsTrue1
Fn
OPEN_KEYFalse33
Fn
OPEN_KEY\Registry\Machine\Software\Microsoft\Windows\Tablet PC\True1
Fn
OPEN_KEY\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRTrue1
Fn
OPEN_KEY\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}False1
Fn
OPEN_KEY\REGISTRY\MACHINE\Software\Classes\ActivatableClasses\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}False1
Fn
OPEN_KEY\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\CLSID\{7E5FE3D9-985F-4908-91F9-EE19F9FD1514}False1
Fn
OPEN_KEY\REGISTRY\MACHINE\Software\Classes\ActivatableClasses\CLSID\{7E5FE3D9-985F-4908-91F9-EE19F9FD1514}False1
Fn
OPEN_KEY\REGISTRY\USER\S-1-5-18\Software\Classes\ActivatableClasses\CLSIDFalse1
Fn
OPEN_KEY\REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}False1
Fn
OPEN_KEY\REGISTRY\MACHINE\Software\Classes\ActivatableClasses\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}False1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\LocaleTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Locale\Alternate SortsTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Language GroupsTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versionsvalue_name = 426648723168True1
Fn
READ_VALUEvalue_name = PageAllocatorUseSystemHeapFalse1
Fn
READ_VALUEvalue_name = PageAllocatorSystemHeapIsPrivateFalse1
Fn
READ_VALUEvalue_name = AggressiveMTATestingFalse1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initializevalue_name = DisableMetaFilesFalse1
Fn
READ_VALUEvalue_name = LoadAppInit_DLLsTrue1
Fn
READ_VALUEvalue_name = Com+EnabledFalse1
Fn
READ_VALUEvalue_name = 426648726872True2
Fn
READ_VALUEvalue_name = InprocServer32False1
Fn
READ_VALUEvalue_name = 426648726760True2
Fn
READ_VALUEvalue_name = 426648726632True1
Fn
READ_VALUEvalue_name = ThreadingModelTrue1
Fn
READ_VALUEvalue_name = MaxSxSHashCountFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocalevalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocalevalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocale\Control Panel\InternationalFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocale\Control Panel\InternationalTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocale\Control Panel\Internationalvalue_name = sCurrencyOverrideFalse1
Fn
READ_VALUETrue30
Fn
READ_VALUEvalue_name = SystemSetupInProgressTrue1
Fn
READ_VALUEFalse31
Fn
READ_VALUEvalue_name = OOBEInProgressFalse1
Fn
READ_VALUEvalue_name = MaxRpcSizeFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNamevalue_name = ComputerNameTrue1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = OOBEInProgressFalse1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = SystemSetupInProgressTrue1
Fn
READ_VALUEvalue_name = IdleTimerWindowFalse1
Fn
READ_VALUEvalue_name = CategoryTrue7
Fn
READ_VALUEvalue_name = NameTrue7
Fn
READ_VALUEvalue_name = ParentFolderFalse6
Fn
READ_VALUEvalue_name = DescriptionFalse7
Fn
READ_VALUEvalue_name = RelativePathTrue7
Fn
READ_VALUEvalue_name = ParsingNameFalse7
Fn
READ_VALUEvalue_name = InfoTipFalse4
Fn
READ_VALUEvalue_name = LocalizedNameFalse2
Fn
READ_VALUEvalue_name = IconFalse2
Fn
READ_VALUEvalue_name = SecurityFalse7
Fn
READ_VALUEvalue_name = StreamResourceFalse7
Fn
READ_VALUEvalue_name = StreamResourceTypeFalse7
Fn
READ_VALUEvalue_name = LocalRedirectOnlyFalse7
Fn
READ_VALUEvalue_name = RoamableFalse2
Fn
READ_VALUEvalue_name = PreCreateFalse1
Fn
READ_VALUEvalue_name = StreamFalse7
Fn
READ_VALUEvalue_name = PublishExpandedPathFalse5
Fn
READ_VALUEvalue_name = DefinitionFlagsFalse7
Fn
READ_VALUEvalue_name = AttributesFalse3
Fn
READ_VALUEvalue_name = FolderTypeIDFalse7
Fn
READ_VALUEvalue_name = InitFolderHandlerFalse7
Fn
READ_VALUEvalue_name = AppDataTrue2
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versionsvalue_name = 000602xxTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Idsvalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Idsvalue_name = enFalse1
Fn
READ_VALUENameless FileMappingvalue_name = CategoryTrue2
Fn
READ_VALUENameless FileMappingvalue_name = NameTrue2
Fn
READ_VALUENameless FileMappingvalue_name = ParentFolderFalse2
Fn
READ_VALUENameless FileMappingvalue_name = DescriptionFalse2
Fn
READ_VALUENameless FileMappingvalue_name = RelativePathFalse1
Fn
READ_VALUENameless FileMappingvalue_name = ParsingNameFalse2
Fn
READ_VALUENameless FileMappingvalue_name = InfoTipFalse2
Fn
READ_VALUENameless FileMappingvalue_name = LocalizedNameFalse1
Fn
READ_VALUENameless FileMappingvalue_name = IconFalse1
Fn
READ_VALUENameless FileMappingvalue_name = SecurityFalse2
Fn
READ_VALUENameless FileMappingvalue_name = StreamResourceFalse2
Fn
READ_VALUENameless FileMappingvalue_name = StreamResourceTypeFalse2
Fn
READ_VALUENameless FileMappingvalue_name = LocalRedirectOnlyFalse2
Fn
READ_VALUENameless FileMappingvalue_name = RoamableFalse1
Fn
READ_VALUENameless FileMappingvalue_name = PreCreateFalse1
Fn
READ_VALUENameless FileMappingvalue_name = StreamFalse2
Fn
READ_VALUENameless FileMappingvalue_name = PublishExpandedPathFalse1
Fn
READ_VALUENameless FileMappingvalue_name = DefinitionFlagsFalse2
Fn
READ_VALUENameless FileMappingvalue_name = AttributesFalse1
Fn
READ_VALUENameless FileMappingvalue_name = FolderTypeIDFalse2
Fn
READ_VALUENameless FileMappingvalue_name = InitFolderHandlerFalse2
Fn
READ_VALUEvalue_name = ProfileImagePathTrue14
Fn
READ_VALUEvalue_name = LastUpdatedFalse1
Fn
READ_VALUEvalue_name = TranscodedImageCountFalse1
Fn
READ_VALUEvalue_name = TranscodedImageCache_000False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_001False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_002False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_003False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_004False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_005False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_006False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_007False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_008False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_009False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_010False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_011False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_012False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_013False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_014False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_015False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_016False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_017False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_018False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_019False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_020False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_021False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_022False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_023False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_024False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_025False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_026False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_027False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_028False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_029False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_030False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_031False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_032False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_033False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_034False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_035False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_036False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_037False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_038False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_039False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_040False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_041False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_042False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_043False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_044False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_045False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_046False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_047False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_048False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_049False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_050False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_051False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_052False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_053False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_054False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_055False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_056False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_057False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_058False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_059False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_060False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_061False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_062False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_063False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_064False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_065False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_066False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_067False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_068False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_069False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_070False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_071False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_072False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_073False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_074False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_075False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_076False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_077False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_078False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_079False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_080False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_081False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_082False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_083False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_084False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_085False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_086False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_087False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_088False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_089False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_090False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_091False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_092False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_093False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_094False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_095False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_096False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_097False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_098False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_099False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_100False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_101False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_102False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_103False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_104False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_105False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_106False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_107False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_108False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_109False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_110False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_111False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_112False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_113False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_114False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_115False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_116False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_117False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_118False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_119False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_120False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_121False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_122False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_123False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_124False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_125False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_126False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_127False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_128False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_129False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_130False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_131False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_132False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_133False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_134False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_135False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_136False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_137False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_138False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_139False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_140False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_141False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_142False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_143False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_144False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_145False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_146False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_147False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_148False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_149False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_150False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_151False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_152False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_153False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_154False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_155False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_156False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_157False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_158False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_159False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_160False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_161False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_162False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_163False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_164False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_165False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_166False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_167False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_168False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_169False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_170False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_171False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_172False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_173False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_174False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_175False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_176False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_177False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_178False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_179False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_180False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_181False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_182False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_183False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_184False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_185False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_186False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_187False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_188False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_189False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_190False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_191False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_192False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_193False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_194False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_195False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_196False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_197False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_198False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_199False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_200False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_201False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_202False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_203False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_204False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_205False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_206False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_207False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_208False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_209False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_210False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_211False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_212False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_213False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_214False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_215False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_216False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_217False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_218False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_219False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_220False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_221False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_222False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_223False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_224False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_225False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_226False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_227False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_228False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_229False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_230False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_231False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_232False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_233False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_234False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_235False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_236False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_237False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_238False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_239False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_240False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_241False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_242False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_243False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_244False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_245False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_246False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_247False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_248False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_249False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_250False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_251False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_252False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_253False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_254False1
Fn
READ_VALUEvalue_name = TranscodedImageCache_255False1
Fn
READ_VALUEvalue_name = PanoramaThresholdFalse1
Fn
READ_VALUEvalue_name = MaxVirtualDesktopDimensionFalse1
Fn
READ_VALUEControl Panel\Desktopvalue_name = MaxMonitorDimensionFalse1
Fn
READ_VALUENameless FileMappingvalue_name = AutoColorizationFalse2
Fn
READ_VALUEControl Panel\Desktopvalue_name = DisplayVersionFalse1
Fn
READ_VALUEControl Panel\Desktopvalue_name = PaintDesktopVersionTrue1
Fn
READ_VALUENameless FileMappingvalue_name = TileWallpaperTrue1
Fn
READ_VALUENameless FileMappingvalue_name = WallpaperStyleTrue1
Fn
READ_VALUEHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Systemvalue_name = WallpaperFalse1
Fn
READ_VALUEvalue_name = TileWallpaperTrue1
Fn
READ_VALUEvalue_name = WallpaperStyleTrue1
Fn
READ_VALUEHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorervalue_name = NoPropertiesMyComputerFalse1
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\value_name = NoPropertiesMyComputerFalse1
Fn
READ_VALUEHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorervalue_name = NoPropertiesMyComputerFalse1
Fn
READ_VALUEHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorervalue_name = NoPropertiesRecycleBinFalse1
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\value_name = NoPropertiesRecycleBinFalse1
Fn
READ_VALUEHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorervalue_name = NoPropertiesRecycleBinFalse1
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\value_name = NoControlPanelFalse1
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\value_name = NoSetFoldersFalse1
Fn
READ_VALUEHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorervalue_name = NoInternetIconFalse1
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\value_name = NoInternetIconFalse1
Fn
READ_VALUEHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorervalue_name = NoInternetIconFalse1
Fn
READ_VALUEHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorervalue_name = NoCommonGroupsFalse1
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\value_name = NoCommonGroupsFalse1
Fn
READ_VALUEHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorervalue_name = NoCommonGroupsFalse1
Fn
READ_VALUEvalue_name = AttributesFalse1
Fn
READ_VALUEvalue_name = CallForAttributesFalse1
Fn
READ_VALUEvalue_name = CallForAttributesFalse1
Fn
READ_VALUEvalue_name = RestrictedAttributesFalse1
Fn
READ_VALUEvalue_name = RestrictedAttributesFalse1
Fn
READ_VALUEvalue_name = FolderValueFlagsTrue1
Fn
READ_VALUEvalue_name = FolderValueFlagsTrue1
Fn
READ_VALUEvalue_name = {20D04FE0-3AEA-1069-A2D8-08002B30309D}False1
Fn
READ_VALUEHKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}value_name = DriveMaskTrue1
Fn
READ_VALUEvalue_name = DriveMaskTrue1
Fn
READ_VALUEHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorervalue_name = AllowFileCLSIDJunctionsFalse1
Fn
READ_VALUEvalue_name = AllowFileCLSIDJunctionsFalse1
Fn
READ_VALUEHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorervalue_name = AllowFileCLSIDJunctionsFalse1
Fn
READ_VALUEHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorervalue_name = DontShowSuperHiddenFalse1
Fn
READ_VALUEvalue_name = DontShowSuperHiddenFalse1
Fn
READ_VALUEHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorervalue_name = DontShowSuperHiddenFalse1
Fn
READ_VALUEvalue_name = ShellStateFalse2
Fn
READ_VALUEvalue_name = ShellStateFalse2
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Tablet PC\value_name = IsTabletPCTrue1
Fn
READ_VALUEHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorervalue_name = NoWebViewFalse1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Tablet PC\value_name = NoWebViewFalse1
Fn
READ_VALUEHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorervalue_name = NoWebViewFalse1
Fn
READ_VALUEHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorervalue_name = ClassicShellFalse1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Tablet PC\value_name = ClassicShellFalse1
Fn
READ_VALUEHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorervalue_name = ClassicShellFalse1
Fn
READ_VALUEHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorervalue_name = SeparateProcessFalse1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Tablet PC\value_name = SeparateProcessFalse1
Fn
READ_VALUEHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorervalue_name = SeparateProcessFalse1
Fn
READ_VALUEHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorervalue_name = NoNetCrawlingFalse1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Tablet PC\value_name = NoNetCrawlingFalse1
Fn
READ_VALUEHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorervalue_name = NoNetCrawlingFalse1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Tablet PC\value_name = DocObjectFalse1
Fn
READ_VALUEvalue_name = DocObjectFalse2
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Tablet PC\value_name = BrowseInPlaceFalse1
Fn
READ_VALUEvalue_name = BrowseInPlaceFalse2
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Tablet PC\value_name = IsShortcutFalse1
Fn
READ_VALUEvalue_name = IsShortcutFalse2
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Tablet PC\value_name = AlwaysShowExtTrue1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Tablet PC\value_name = NeverShowExtFalse1
Fn
READ_VALUEvalue_name = NeverShowExtFalse2
Fn
READ_VALUENameless FileMappingvalue_name = RelativePathTrue1
Fn
READ_VALUENameless FileMappingvalue_name = LocalizedNameTrue1
Fn
READ_VALUENameless FileMappingvalue_name = IconTrue1
Fn
READ_VALUENameless FileMappingvalue_name = RoamableTrue1
Fn
READ_VALUENameless FileMappingvalue_name = PreCreateTrue1
Fn
READ_VALUENameless FileMappingvalue_name = PublishExpandedPathTrue1
Fn
READ_VALUENameless FileMappingvalue_name = AttributesTrue1
Fn
READ_VALUEvalue_name = DesktopTrue1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRvalue_name = DisableTrue1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRvalue_name = SourcePathFalse1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRvalue_name = DevicePathTrue1
Fn
READ_VALUEvalue_name = 426648700712True2
Fn
READ_VALUENameless FileMappingvalue_name = InprocServer32False1
Fn
READ_VALUENameless FileMappingvalue_name = 426648700600True2
Fn
READ_VALUENameless FileMappingvalue_name = 426648700472True1
Fn
READ_VALUENameless FileMappingvalue_name = ThreadingModelTrue1
Fn
READ_VALUE\device\mountpointmanagervalue_name = Local AppDataTrue6
Fn
READ_VALUEvalue_name = Local AppDataTrue6
Fn
READ_VALUEvalue_name = ParentFolderTrue1
Fn
READ_VALUEvalue_name = PreCreateTrue6
Fn
READ_VALUEvalue_name = PublishExpandedPathTrue2
Fn
READ_VALUEvalue_name = {1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}False1
Fn
READ_VALUEvalue_name = ParsingNameTrue5
Fn
READ_VALUEvalue_name = LocalizedNameTrue5
Fn
READ_VALUEvalue_name = IconTrue5
Fn
READ_VALUEvalue_name = RoamableTrue5
Fn
READ_VALUEvalue_name = AttributesTrue5
Fn
READ_VALUEvalue_name = PersonalTrue1
Fn
READ_VALUEvalue_name = InfoTipTrue3
Fn
READ_VALUEvalue_name = My MusicTrue1
Fn
READ_VALUEvalue_name = My PicturesTrue1
Fn
READ_VALUEvalue_name = My VideoTrue1
Fn
READ_VALUEvalue_name = {374DE290-123F-4565-9164-39C4925E467B}True1
Fn
READ_VALUEvalue_name = EnableAnchorContextFalse1
Fn
READ_VALUEvalue_name = 426648723496False1
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winre.jpgvalue_name = InprocServer32False1
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winre.jpgvalue_name = 426648723384True2
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winre.jpgvalue_name = 426648723256True1
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winre.jpgvalue_name = ThreadingModelTrue1
Fn
READ_VALUEvalue_name = DisplayVersionFalse1
Fn
READ_VALUEvalue_name = PaintDesktopVersionTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Localevalue_name = 00000409True1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Language Groupsvalue_name = 1True1
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winre.jpgvalue_name = DisplayVersionFalse7
Fn
READ_VALUE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winre.jpgvalue_name = PaintDesktopVersionTrue1
Fn
WRITE_VALUEControl Panel\Desktopvalue_name = MaxVirtualDesktopDimension, data = 1024True1
Fn
WRITE_VALUEControl Panel\Desktopvalue_name = MaxMonitorDimension, data = 1024True1
Fn
WRITE_VALUEControl Panel\Desktopvalue_name = TranscodedImageCount, data = 1True1
Fn
WRITE_VALUEControl Panel\Desktopvalue_name = LastUpdated, data = 4294967295True1
Fn
DELETE_VALUEvalue_name = TranscodedImageCache_000False1
Fn
CHECK_KEY\Registry\Machine\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates\2BD63D28D7BCD0E251195AEB519243C13142EBC3False5
Fn
CHECK_KEY\Registry\Machine\SOFTWARE\Microsoft\SystemCertificates\Root\Certificates\2BD63D28D7BCD0E251195AEB519243C13142EBC3False5
Fn
CHECK_KEYHKEY_CURRENT_USER\\SOFTWARE\Microsoft\SystemCertificates\Root\Certificates\2BD63D28D7BCD0E251195AEB519243C13142EBC3False5
Fn
CHECK_KEY\Registry\Machine\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates\8A334AA8052DD244A647306A76B8178FA215F344False2
Fn
CHECK_KEY\Registry\Machine\SOFTWARE\Microsoft\SystemCertificates\Root\Certificates\8A334AA8052DD244A647306A76B8178FA215F344False2
Fn
CHECK_KEYHKEY_CURRENT_USER\\SOFTWARE\Microsoft\SystemCertificates\Root\Certificates\8A334AA8052DD244A647306A76B8178FA215F344False2
Fn
Driver (25)
+
OperationDriverAdditional InformationSuccessAmountLogfile
CONTROLTrue1
Fn
CONTROLcontrol_code = 0x390008True1
Fn
CONTROL\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}control_code = 0x4d0008True2
Fn
CONTROL\device\mountpointmanagercontrol_code = 0x6d0008False3
Fn
CONTROL\device\mountpointmanagercontrol_code = 0x6d0008True3
Fn
CONTROL\device\deviceapi\cmapicontrol_code = 0x470807True2
Fn
CONTROLc:control_code = 0x4d0008True1
Fn
CONTROL\device\mountpointmanagercontrol_code = 0x6d0034False6
Fn
CONTROL\device\mountpointmanagercontrol_code = 0x6d0034True6
Fn
System (47)
+
OperationInformationSuccessAmountLogfile
GET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
GET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue10
Fn
GET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue4
Fn
GET_INFOTrue17
Fn
GET_INFOFalse15
Fn
Mutex (31)
+
OperationNameAdditional InformationSuccessAmountLogfile
CREATETrue5
Fn
CREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue7
Fn
OPENLocal\MSCTF.Asm.MutexDefault1desired_access = SYNCHRONIZEFalse1
Fn
OPENCicLoadWinStaWinSta0desired_access = SYNCHRONIZEFalse1
Fn
RELEASETrue17
Fn
Process #17: recenv.exe
(Host: 1112, Network: 0)
+
InformationValue
ID / OS PID#17 / 0x298
OS Parent PID0x278 (\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe
Command LineX:\sources\recovery\recenv.exe
MonitorStart Time: 00:01:55, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:12
OS Thread IDs
#123
0x29C
#126
0x2A8
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x000000e5e53500000xe5e53500000xe5e536ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000e5e53500000xe5e53500000xe5e535ffffPagefile Backed FileReadable, WritableTrue
private_0x000000e5e53600000xe5e53600000xe5e5366fffPrivate MemoryReadable, WritableTrue
pagefile_0x000000e5e53700000xe5e53700000xe5e537efffPagefile Backed FileReadableTrue
private_0x000000e5e53800000xe5e53800000xe5e53fffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000e5e54000000xe5e54000000xe5e5403fffPagefile Backed FileReadableTrue
pagefile_0x000000e5e54100000xe5e54100000xe5e5411fffPagefile Backed FileReadableTrue
private_0x000000e5e54200000xe5e54200000xe5e5421fffPrivate MemoryReadable, WritableTrue
pagefile_0x000000e5e54300000xe5e54300000xe5e5431fffPagefile Backed FileReadableTrue
pagefile_0x000000e5e54400000xe5e54400000xe5e5441fffPagefile Backed FileReadableTrue
private_0x000000e5e54500000xe5e54500000xe5e5456fffPrivate MemoryReadable, WritableTrue
recenv.exe.mui0xe5e54600000xe5e5465fffMemory Mapped FileReadableTrue
private_0x000000e5e54700000xe5e54700000xe5e547ffffPrivate MemoryReadable, WritableTrue
private_0x000000e5e54800000xe5e54800000xe5e5480fffPrivate MemoryReadable, WritableTrue
private_0x000000e5e54900000xe5e54900000xe5e558ffffPrivate MemoryReadable, WritableTrue
locale.nls0xe5e55900000xe5e560dfffMemory Mapped FileReadableFalse
pagefile_0x000000e5e56100000xe5e56100000xe5e5797fffPagefile Backed FileReadableTrue
pagefile_0x000000e5e57a00000xe5e57a00000xe5e5920fffPagefile Backed FileReadableTrue
pagefile_0x000000e5e59300000xe5e59300000xe5e6d2ffffPagefile Backed FileReadableTrue
private_0x000000e5e6d300000xe5e6d300000xe5e6d30fffPrivate MemoryReadable, WritableTrue
SETUPAPI.dll.mui0xe5e6d400000xe5e6d4bfffMemory Mapped FileReadableFalse
pagefile_0x000000e5e6d500000xe5e6d500000xe5e6d52fffPagefile Backed FileReadableTrue
newdev.dll.mui0xe5e6d600000xe5e6d66fffMemory Mapped FileReadableFalse
private_0x000000e5e6d700000xe5e6d700000xe5e6deffffPrivate MemoryReadable, WritableTrue
private_0x000000e5e6e500000xe5e6e500000xe5e6e5ffffPrivate MemoryReadable, WritableTrue
sortdefault.nls0xe5e6e600000xe5e7134fffMemory Mapped FileReadableFalse
private_0x000000e5e71400000xe5e71400000xe5e723ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007ff7298700000x7ff7298700000x7ff72996ffffPagefile Backed FileReadableTrue
pagefile_0x00007ff7299700000x7ff7299700000x7ff729992fffPagefile Backed FileReadableTrue
private_0x00007ff72999a0000x7ff72999a0000x7ff72999bfffPrivate MemoryReadable, WritableTrue
private_0x00007ff72999c0000x7ff72999c0000x7ff72999cfffPrivate MemoryReadable, WritableTrue
private_0x00007ff72999e0000x7ff72999e0000x7ff72999ffffPrivate MemoryReadable, WritableTrue
recenv.exe0x7ff729ec00000x7ff729f63fffMemory Mapped FileReadable, Writable, ExecutableTrue
DismApi.DLL0x7ffb6fc400000x7ffb6fce2fffMemory Mapped FileReadable, Writable, ExecutableFalse
WDSCORE.dll0x7ffb6fcf00000x7ffb6fd37fffMemory Mapped FileReadable, Writable, ExecutableFalse
ReAgent.dll0x7ffb6fd400000x7ffb6fe2ffffMemory Mapped FileReadable, Writable, ExecutableFalse
VERSION.dll0x7ffb6fe300000x7ffb6fe39fffMemory Mapped FileReadable, Writable, ExecutableFalse
drvstore.dll0x7ffb6fe500000x7ffb6ff0afffMemory Mapped FileReadable, Writable, ExecutableFalse
COMCTL32.dll0x7ffb6ff100000x7ffb7018afffMemory Mapped FileReadable, Writable, ExecutableFalse
SHCORE.DLL0x7ffb701b00000x7ffb70261fffMemory Mapped FileReadable, Writable, ExecutableFalse
MPR.dll0x7ffb702700000x7ffb7028dfffMemory Mapped FileReadable, Writable, ExecutableFalse
wkscli.dll0x7ffb702900000x7ffb702a6fffMemory Mapped FileReadable, Writable, ExecutableFalse
WpeUtil.dll0x7ffb702b00000x7ffb702cefffMemory Mapped FileReadable, Writable, ExecutableFalse
devrtl.DLL0x7ffb702d00000x7ffb702e5fffMemory Mapped FileReadable, Writable, ExecutableFalse
WINNSI.DLL0x7ffb702f00000x7ffb702f9fffMemory Mapped FileReadable, Writable, ExecutableFalse
FLTLIB.DLL0x7ffb703500000x7ffb70359fffMemory Mapped FileReadable, Writable, ExecutableFalse
UNATTEND.DLL0x7ffb703600000x7ffb7039ffffMemory Mapped FileReadable, Writable, ExecutableFalse
Input.dll0x7ffb703a00000x7ffb703e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
newdev.dll0x7ffb703f00000x7ffb70445fffMemory Mapped FileReadable, Writable, ExecutableFalse
IPHLPAPI.DLL0x7ffb704500000x7ffb70479fffMemory Mapped FileReadable, Writable, ExecutableFalse
UxTheme.dll0x7ffb704800000x7ffb705a8fffMemory Mapped FileReadable, Writable, ExecutableFalse
DEVOBJ.dll0x7ffb705b00000x7ffb705d7fffMemory Mapped FileReadable, Writable, ExecutableFalse
spinf.dll0x7ffb709a00000x7ffb709bdfffMemory Mapped FileReadable, Writable, ExecutableFalse
USERENV.dll0x7ffb70dd00000x7ffb70df0fffMemory Mapped FileReadable, Writable, ExecutableFalse
DNSAPI.dll0x7ffb70e400000x7ffb70ee3fffMemory Mapped FileReadable, Writable, ExecutableFalse
powrprof.dll0x7ffb715300000x7ffb71575fffMemory Mapped FileReadable, Writable, ExecutableFalse
profapi.dll0x7ffb716b00000x7ffb716c4fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
CFGMGR32.dll0x7ffb718800000x7ffb718cefffMemory Mapped FileReadable, Writable, ExecutableTrue
Setupapi.dll0x7ffb718d00000x7ffb71aa9fffMemory Mapped FileReadable, Writable, ExecutableTrue
IMAGEHLP.dll0x7ffb71ab00000x7ffb71ac5fffMemory Mapped FileReadable, Writable, ExecutableTrue
gdi32.dll0x7ffb71ad00000x7ffb71c20fffMemory Mapped FileReadable, Writable, ExecutableTrue
SHELL32.dll0x7ffb71c300000x7ffb73148fffMemory Mapped FileReadable, Writable, ExecutableTrue
SHLWAPI.dll0x7ffb733000000x7ffb73353fffMemory Mapped FileReadable, Writable, ExecutableTrue
WS2_32.dll0x7ffb733600000x7ffb733b9fffMemory Mapped FileReadable, Writable, ExecutableTrue
sechost.dll0x7ffb733c00000x7ffb73418fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
OLEAUT32.dll0x7ffb735c00000x7ffb73680fffMemory Mapped FileReadable, Writable, ExecutableTrue
advapi32.dll0x7ffb736900000x7ffb73739fffMemory Mapped FileReadable, Writable, ExecutableTrue
combase.dll0x7ffb737400000x7ffb73950fffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSCTF.dll0x7ffb73b800000x7ffb73cd2fffMemory Mapped FileReadable, Writable, ExecutableTrue
ole32.dll0x7ffb73ce00000x7ffb73e73fffMemory Mapped FileReadable, Writable, ExecutableTrue
NSI.dll0x7ffb73e800000x7ffb73e88fffMemory Mapped FileReadable, Writable, ExecutableTrue
user32.dll0x7ffb73e900000x7ffb74006fffMemory Mapped FileReadable, Writable, ExecutableTrue
IMM32.dll0x7ffb740100000x7ffb74045fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSVCRT.dll0x7ffb740500000x7ffb740f9fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Injection Information
+
Injection TypeSource ProcessSource Os Thread IDInjection InfoSuccessAmountLogfile
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe0x27caddress = 0xe5e5420000, size = 4704True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe0x27caddress = 0x7ff72999c2d8, size = 8True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8address = 0xd9cbf90000, size = 12288True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8No corresponding api call detected. Probably injected code via shellcode.True1
Host Behavior
File (39)
+
OperationFilenameAdditional InformationSuccessAmountLogfile
CREATE\device\deviceapi\cmapidesired_access = GENERIC_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nlsdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
CREATETrue11
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\apps.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\defltbase.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\defltwk.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\dwup.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\errata.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\fontsetup.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netnb.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\puwk.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ramdisk.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sceregvl.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\secrecs.infdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\reagent.dlldesired_access = FILE_READ_DATA, FILE_READ_EA, FILE_READ_ATTRIBUTES, READ_CONTROL, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\newdev.dlldesired_access = FILE_READ_DATA, FILE_READ_EA, FILE_READ_ATTRIBUTES, READ_CONTROL, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\windowsshell.manifestdesired_access = FILE_READ_DATA, FILE_READ_EA, FILE_EXECUTE, FILE_READ_ATTRIBUTES, READ_CONTROL, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
OPEN\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue12
Fn
Process (31)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True3
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True2
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True22
Fn
Thread (1)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, proc_address = 0x7ff729ece3c4, desired_access = THREAD_ALL_ACCESSTrue1
Fn
Module (84)
+
OperationModuleAdditional InformationSuccessAmountLogfile
LOADrpcrt4.dllbase_address = 0x0True1
Fn
LOADntdll.dllbase_address = 0x0True1
Fn
LOADkernel32.dllbase_address = 0x0True1
Fn
GET_HANDLEX:\windows\system32\IMM32.DLLTrue2
Fn
GET_HANDLE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exeFalse1
Fn
GET_HANDLELPK.dllFalse1
Fn
GET_HANDLE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exeTrue3
Fn
GET_HANDLEGDI32.dllTrue1
Fn
GET_HANDLErpcrt4.dllTrue1
Fn
GET_HANDLEX:\windows\system32\oleaut32.dllTrue1
Fn
GET_HANDLEext-ms-win-ole32-oleautomation-l1-1-0.dllTrue1
Fn
GET_HANDLEadvapi32.dllTrue1
Fn
GET_HANDLEntdll.dllTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\windowsshell.manifest, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingTrue11
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\apps.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\defltbase.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\defltwk.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\dwup.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\errata.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\fontsetup.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netnb.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\puwk.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ramdisk.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sceregvl.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\secrecs.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6d40000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6e60000True1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exeos_pid = 0x298, address = 0xe5e6df0000True10
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6df0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6df0000True3
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6df0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6df0000True1
Fn
MAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exeos_pid = 0x298, address = 0xe5e7240000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e7240000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6df0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6df0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6df0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6df0000True1
Fn
UNMAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, base_address = 0xe5e6d40000True1
Fn
UNMAP\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exeos_pid = 0x298True11
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb71bf7350True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb741751c0True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb7413b300True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb7413c360True2
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb74175650True1
Fn
Service (3)
+
OperationServiceAdditional InformationSuccessAmountLogfile
OPEN_MGRSERVICES_ACTIVE_DATABASEhost = LocalhostTrue1
Fn
OPENTrue1
Fn
SET_CONFIGTrue1
Fn
Registry (229)
+
OperationKeyAdditional InformationSuccessAmountLogfile
CREATE_KEYTrue1
Fn
CREATE_KEYSystem\CurrentControlSet\Services\Tcpip\ParametersTrue1
Fn
OPEN_KEY\Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySideTrue3
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\VersionsTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Error Message Instrument\False1
Fn
OPEN_KEY\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_InitializeTrue1
Fn
OPEN_KEYTrue6
Fn
OPEN_KEY\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocaleTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocaleTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
OPEN_KEY\Registry\Machine\System\SetupTrue2
Fn
OPEN_KEYFalse2
Fn
OPEN_KEY\REGISTRY\MACHINETrue6
Fn
OPEN_KEY\REGISTRY\MACHINE\System\SetupTrue1
Fn
OPEN_KEY\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Control\MiniNTTrue1
Fn
OPEN_KEY\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\SetupTrue2
Fn
OPEN_KEY\REGISTRY\MACHINE\Software\Microsoft\EmbeddedNT\SecurityFalse1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\IdsTrue1
Fn
OPEN_KEY\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\DeviceInstallFalse1
Fn
OPEN_KEYControl Panel\InternationalTrue1
Fn
READ_VALUE\Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySidevalue_name = PreferExternalManifestFalse3
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versionsvalue_name = 987393678784True1
Fn
READ_VALUESTD_OUTPUT_HANDLEvalue_name = DisableMetaFilesFalse1
Fn
READ_VALUEvalue_name = LoadAppInit_DLLsTrue1
Fn
READ_VALUENameless FileMappingvalue_name = PageAllocatorUseSystemHeapFalse1
Fn
READ_VALUENameless FileMappingvalue_name = PageAllocatorSystemHeapIsPrivateFalse1
Fn
READ_VALUENameless FileMappingvalue_name = AggressiveMTATestingFalse1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRvalue_name = DisableTrue1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRvalue_name = SourcePathFalse1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRvalue_name = DevicePathTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocalevalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocalevalue_name = en-USFalse1
Fn
READ_VALUETrue2
Fn
READ_VALUEvalue_name = SystemSetupInProgressTrue2
Fn
READ_VALUEvalue_name = MaxRpcSizeFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNamevalue_name = ComputerNameTrue1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = OOBEInProgressFalse1
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = SystemSetupInProgressTrue1
Fn
READ_VALUEvalue_name = IdleTimerWindowFalse1
Fn
READ_VALUEFalse79
Fn
READ_VALUEvalue_name = SetComputerNameFalse1
Fn
READ_VALUEvalue_name = QueryAdapterNameFalse1
Fn
READ_VALUESystem\CurrentControlSet\Services\Tcpip\Parametersvalue_name = DisableAdapterDomainNameFalse1
Fn
READ_VALUEvalue_name = UseDomainNameDevolutionFalse1
Fn
READ_VALUESystem\CurrentControlSet\Services\Tcpip\Parametersvalue_name = UseDomainNameDevolutionFalse1
Fn
READ_VALUEvalue_name = DomainNameDevolutionLevelFalse1
Fn
READ_VALUEvalue_name = PrioritizeRecordDataFalse1
Fn
READ_VALUESystem\CurrentControlSet\Services\Tcpip\Parametersvalue_name = PrioritizeRecordDataFalse1
Fn
READ_VALUEvalue_name = AllowUnqualifiedQueryFalse1
Fn
READ_VALUESystem\CurrentControlSet\Services\Tcpip\Parametersvalue_name = AllowUnqualifiedQueryFalse1
Fn
READ_VALUEvalue_name = AppendToMultiLabelNameFalse1
Fn
READ_VALUEvalue_name = ScreenBadTldsFalse1
Fn
READ_VALUEvalue_name = ScreenUnreachableServersFalse1
Fn
READ_VALUEvalue_name = ScreenDefaultServersFalse1
Fn
READ_VALUEvalue_name = DynamicServerQueryOrderFalse1
Fn
READ_VALUEvalue_name = FilterClusterIpFalse1
Fn
READ_VALUEvalue_name = WaitForNameErrorOnAllFalse1
Fn
READ_VALUEvalue_name = UseEdnsFalse1
Fn
READ_VALUEvalue_name = DnsSecureNameQueryFallbackFalse1
Fn
READ_VALUEvalue_name = EnableDAForAllNetworksFalse1
Fn
READ_VALUEvalue_name = DirectAccessQueryOrderFalse1
Fn
READ_VALUEvalue_name = QueryIpMatchingFalse1
Fn
READ_VALUEvalue_name = UseHostsFileFalse1
Fn
READ_VALUEvalue_name = AddrConfigControlFalse1
Fn
READ_VALUEvalue_name = DisableSmartNameResolutionFalse1
Fn
READ_VALUEvalue_name = PreferLocalOverLowerBindingDNSFalse1
Fn
READ_VALUEvalue_name = QueryNetBTFQDNFalse1
Fn
READ_VALUEvalue_name = DisableSmartProtocolReorderingFalse1
Fn
READ_VALUEvalue_name = UdpRecvBufferSizeFalse1
Fn
READ_VALUEvalue_name = DisableParallelAandAAAAFalse1
Fn
READ_VALUEvalue_name = DisableCoalescingFalse1
Fn
READ_VALUEvalue_name = FilterVPNTriggerFalse1
Fn
READ_VALUEvalue_name = RegistrationEnabledFalse1
Fn
READ_VALUESystem\CurrentControlSet\Services\Tcpip\Parametersvalue_name = DisableDynamicUpdateFalse1
Fn
READ_VALUEvalue_name = RegisterPrimaryNameFalse1
Fn
READ_VALUEvalue_name = RegisterAdapterNameFalse1
Fn
READ_VALUESystem\CurrentControlSet\Services\Tcpip\Parametersvalue_name = EnableAdapterDomainNameRegistrationFalse1
Fn
READ_VALUEvalue_name = RegisterReverseLookupFalse1
Fn
READ_VALUESystem\CurrentControlSet\Services\Tcpip\Parametersvalue_name = DisableReverseAddressRegistrationsFalse1
Fn
READ_VALUEvalue_name = RegisterWanAdaptersFalse1
Fn
READ_VALUESystem\CurrentControlSet\Services\Tcpip\Parametersvalue_name = DisableWanDynamicUpdateFalse1
Fn
READ_VALUEvalue_name = RegistrationTtlFalse1
Fn
READ_VALUESystem\CurrentControlSet\Services\Tcpip\Parametersvalue_name = DefaultRegistrationTTLFalse1
Fn
READ_VALUEvalue_name = RegistrationRefreshIntervalFalse1
Fn
READ_VALUESystem\CurrentControlSet\Services\Tcpip\Parametersvalue_name = DefaultRegistrationRefreshIntervalFalse1
Fn
READ_VALUEvalue_name = RegistrationMaxAddressCountFalse1
Fn
READ_VALUESystem\CurrentControlSet\Services\Tcpip\Parametersvalue_name = MaxNumberOfAddressesToRegisterFalse1
Fn
READ_VALUEvalue_name = UpdateSecurityLevelFalse1
Fn
READ_VALUESystem\CurrentControlSet\Services\Tcpip\Parametersvalue_name = UpdateSecurityLevelFalse1
Fn
READ_VALUEvalue_name = UpdateTopLevelDomainZonesFalse1
Fn
READ_VALUEvalue_name = DowncaseSpnCauseApiOwnerIsTooLazyFalse1
Fn
READ_VALUEvalue_name = RegistrationOverwriteFalse1
Fn
READ_VALUEvalue_name = MaxCacheSizeFalse1
Fn
READ_VALUEvalue_name = MaxCacheTtlFalse1
Fn
READ_VALUEvalue_name = MaxNegativeCacheTtlFalse1
Fn
READ_VALUEvalue_name = AdapterTimeoutLimitFalse1
Fn
READ_VALUEvalue_name = ServerPriorityTimeLimitFalse1
Fn
READ_VALUEvalue_name = MaxCachedSocketsFalse1
Fn
READ_VALUEvalue_name = DisableServerUnreachabilityFalse1
Fn
READ_VALUEvalue_name = EnableMulticastFalse1
Fn
READ_VALUEvalue_name = MulticastResponderFlagsFalse1
Fn
READ_VALUEvalue_name = MulticastSenderFlagsFalse1
Fn
READ_VALUEvalue_name = MulticastSenderMaxTimeoutFalse1
Fn
READ_VALUEvalue_name = DnsTestFalse1
Fn
READ_VALUEvalue_name = UseCompartmentsFalse1
Fn
READ_VALUEvalue_name = CacheAllCompartmentsFalse1
Fn
READ_VALUEvalue_name = UseNewRegistrationFalse1
Fn
READ_VALUEvalue_name = ResolverRegistrationFalse1
Fn
READ_VALUEvalue_name = ResolverRegistrationOnlyFalse1
Fn
READ_VALUEvalue_name = NewDhcpSrvRegistrationFalse1
Fn
READ_VALUEvalue_name = DirectAccessPreferLocalFalse1
Fn
READ_VALUEvalue_name = DisableIdnEncodingFalse1
Fn
READ_VALUEvalue_name = EnableIdnMappingFalse1
Fn
READ_VALUEvalue_name = TestMode_AdaptiveTimeoutHistoryLengthFalse1
Fn
READ_VALUEvalue_name = TestMode_AdaptiveTimeoutRecalculationIntervalFalse1
Fn
READ_VALUEvalue_name = DnsQueryTimeoutsFalse1
Fn
READ_VALUESystem\CurrentControlSet\Services\Tcpip\Parametersvalue_name = DnsQueryTimeoutsFalse1
Fn
READ_VALUEvalue_name = DnsQuickQueryTimeoutsFalse1
Fn
READ_VALUESystem\CurrentControlSet\Services\Tcpip\Parametersvalue_name = DnsQuickQueryTimeoutsFalse1
Fn
READ_VALUE\REGISTRY\MACHINE\System\Setupvalue_name = SystemSetupInProgressTrue1
Fn
READ_VALUE\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Setupvalue_name = MinimizeFootprintTrue1
Fn
READ_VALUEvalue_name = SQMServiceListTrue1
Fn
READ_VALUE\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Setupvalue_name = LogLevelTrue1
Fn
READ_VALUE\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Setupvalue_name = LogMaskFalse1
Fn
READ_VALUE\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Setupvalue_name = LogMaxFileSizeFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versionsvalue_name = 000602xxTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Idsvalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Idsvalue_name = enFalse1
Fn
READ_VALUEControl Panel\InternationalFalse1
Fn
READ_VALUEControl Panel\InternationalTrue1
Fn
READ_VALUEControl Panel\Internationalvalue_name = sCurrencyOverrideFalse1
Fn
Driver (565)
+
OperationDriverAdditional InformationSuccessAmountLogfile
CONTROL\device\deviceapi\cmapicontrol_code = 0x470803True1
Fn
CONTROL\device\deviceapi\cmapicontrol_code = 0x470843True42
Fn
CONTROL\device\deviceapi\cmapicontrol_code = 0x470813True45
Fn
CONTROL\device\deviceapi\cmapicontrol_code = 0x470827True15
Fn
CONTROLTrue231
Fn
CONTROLcontrol_code = 0x470813True220
Fn
CONTROLcontrol_code = 0x47086bTrue11
Fn
User (1)
+
OperationUser/Group/ServerAdditional InformationSuccessAmountLogfile
SET_PRIVILEGELocalhostprivilege = SeRestorePrivilege, enable_privilege = 1True1
Fn
System (99)
+
OperationInformationSuccessAmountLogfile
SLEEPTrue34
Fn
SLEEPduration = 1 milliseconds (0.001 seconds)True54
Fn
GET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
GET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue7
Fn
GET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue2
Fn
GET_INFOTrue1
Fn
Mutex (60)
+
OperationNameAdditional InformationSuccessAmountLogfile
CREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue19
Fn
CREATETrue18
Fn
CREATEWinPEProfilingMutexinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
RELEASETrue22
Fn
Process #18: svchost.exe
(Host: 231, Network: 0)
+
InformationValue
ID / OS PID#18 / 0x2b0
OS Parent PID0x1ac (c:\windows\system32\csrss.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exe
Command LineX:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
MonitorStart Time: 00:02:04, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:03
OS Thread IDs
#127
0x2B4
#130
0x2C4
#131
0x2C8
#132
0x2CC
#133
0x2D0
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x00000020608b00000x20608b00000x20608cffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000020608b00000x20608b00000x20608bffffPagefile Backed FileReadable, WritableTrue
private_0x00000020608c00000x20608c00000x20608c6fffPrivate MemoryReadable, WritableTrue
pagefile_0x00000020608d00000x20608d00000x20608defffPagefile Backed FileReadableTrue
private_0x00000020608e00000x20608e00000x206095ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000020609600000x20609600000x2060963fffPagefile Backed FileReadableTrue
pagefile_0x00000020609700000x20609700000x2060970fffPagefile Backed FileReadableTrue
private_0x00000020609800000x20609800000x2060981fffPrivate MemoryReadable, WritableTrue
locale.nls0x20609900000x2060a0dfffMemory Mapped FileReadableFalse
private_0x0000002060a100000x2060a100000x2060a16fffPrivate MemoryReadable, WritableTrue
pagefile_0x0000002060a200000x2060a200000x2060adffffPagefile Backed FileReadableTrue
svchost.exe.mui0x2060ae00000x2060ae0fffMemory Mapped FileReadableFalse
private_0x0000002060af00000x2060af00000x2060af0fffPrivate MemoryReadable, WritableTrue
private_0x0000002060b000000x2060b000000x2060b00fffPrivate MemoryReadable, WritableTrue
private_0x0000002060b100000x2060b100000x2060b16fffPrivate MemoryReadable, WritableTrue
private_0x0000002060b200000x2060b200000x2060c1ffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000002060c200000x2060c200000x2060da7fffPagefile Backed FileReadableTrue
private_0x0000002060e000000x2060e000000x2060e0ffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000002060e100000x2060e100000x2060f90fffPagefile Backed FileReadableTrue
private_0x0000002060fa00000x2060fa00000x206101ffffPrivate MemoryReadable, WritableTrue
private_0x00000020610200000x20610200000x206109ffffPrivate MemoryReadable, WritableTrue
sortdefault.nls0x20610a00000x2061374fffMemory Mapped FileReadableFalse
private_0x00000020613800000x20613800000x206147ffffPrivate MemoryReadable, WritableTrue
private_0x00000020614800000x20614800000x2061487fffPrivate MemoryReadable, WritableTrue
private_0x00000020614900000x20614900000x206150ffffPrivate MemoryReadable, WritableTrue
wevtapi.dll0x20615100000x2061579fffMemory Mapped FileReadableFalse
private_0x00000020615800000x20615800000x20615fffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007df5ff1d00000x7df5ff1d00000x7ff5ff1cffffPagefile Backed File-True
pagefile_0x00007ff7c98c00000x7ff7c98c00000x7ff7c99bffffPagefile Backed FileReadableTrue
pagefile_0x00007ff7c99c00000x7ff7c99c00000x7ff7c99e2fffPagefile Backed FileReadableTrue
private_0x00007ff7c99e50000x7ff7c99e50000x7ff7c99e6fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c99e70000x7ff7c99e70000x7ff7c99e8fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c99e90000x7ff7c99e90000x7ff7c99e9fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c99ea0000x7ff7c99ea0000x7ff7c99ebfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c99ec0000x7ff7c99ec0000x7ff7c99edfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c99ee0000x7ff7c99ee0000x7ff7c99effffPrivate MemoryReadable, WritableTrue
svchost.exe0x7ff7ca8100000x7ff7ca81cfffMemory Mapped FileReadable, Writable, ExecutableFalse
wevtsvc.dll0x7ffb6f8f00000x7ffb6fa91fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernel.appcore.dll0x7ffb6fe400000x7ffb6fe4afffMemory Mapped FileReadable, Writable, ExecutableFalse
SspiCli.dll0x7ffb715000000x7ffb7152dfffMemory Mapped FileReadable, Writable, ExecutableFalse
powrprof.dll0x7ffb715300000x7ffb71575fffMemory Mapped FileReadable, Writable, ExecutableFalse
bcryptPrimitives.dll0x7ffb715800000x7ffb715e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTBASE.dll0x7ffb715f00000x7ffb715fafffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
gdi32.dll0x7ffb71ad00000x7ffb71c20fffMemory Mapped FileReadable, Writable, ExecutableTrue
sechost.dll0x7ffb733c00000x7ffb73418fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
combase.dll0x7ffb737400000x7ffb73950fffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
user32.dll0x7ffb73e900000x7ffb74006fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSVCRT.dll0x7ffb740500000x7ffb740f9fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Injection Information
+
Injection TypeSource ProcessSource Os Thread IDInjection InfoSuccessAmountLogfile
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe0x1b0address = 0x2060980000, size = 4704True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe0x1b0address = 0x7ff7c99e92d8, size = 8True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1d0No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1d0No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1d0No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1d0No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1d0No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1d0No corresponding api call detected. Probably injected code via shellcode.True1
Host Behavior
File (2)
+
OperationFilenameAdditional InformationSuccessAmountLogfile
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nlsdesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wevtapi.dlldesired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
Process (10)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
OPEN_TOKENTrue1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True1
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True4
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True2
Fn
GET_INFO\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134True2
Fn
Thread (2)
+
OperationProcess NameAdditional InformationSuccessAmountLogfile
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, proc_address = 0x7ffb733c7ef0, desired_access = THREAD_ALL_ACCESSTrue1
Fn
CREATE\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exeos_pid = 0x134, proc_address = 0x7ffb6f922a20, desired_access = THREAD_ALL_ACCESSTrue1
Fn
Module (19)
+
OperationModuleAdditional InformationSuccessAmountLogfile
LOADrpcrt4.dllbase_address = 0x0True1
Fn
LOADkernel32.dllbase_address = 0x0True1
Fn
LOADbase_address = 0x7ffb6f8f0000True1
Fn
LOADx:\windows\system32\wevtsvc.dllbase_address = 0x0True1
Fn
LOADbase_address = 0x2061510002True1
Fn
LOADbase_address = 0x7ffb73480000True1
Fn
LOADsspicli.dllbase_address = 0x0True2
Fn
LOADbase_address = 0x7ffb71500000True1
Fn
GET_HANDLErpcrt4.dllTrue1
Fn
GET_HANDLEX:\windows\system32\rpcss.dllFalse1
Fn
GET_HANDLEntdll.dllTrue1
Fn
GET_HANDLEcombase.dllTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
CREATE_MAPPINGNameless FileMappingfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wevtapi.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x20610a0000True1
Fn
MAPNameless FileMappingprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x2061510000False1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb6f947ee0True1
Fn
GET_PROC_ADDRESSaddress_out = 0x7ffb6f94efc0True1
Fn
Service (1)
+
OperationServiceAdditional InformationSuccessAmountLogfile
REGISTER_HANDLERTrue1
Fn
Com (1)
+
OperationClassInterfaceAdditional InformationSuccessAmountLogfile
CREATETrue1
Fn
Registry (172)
+
OperationKeyAdditional InformationSuccessAmountLogfile
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\VersionsTrue1
Fn
OPEN_KEYTrue17
Fn
OPEN_KEYFalse4
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Error Message Instrument\False1
Fn
OPEN_KEY\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_InitializeTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue5
Fn
OPEN_KEY\Registry\Machine\System\SetupTrue4
Fn
OPEN_KEYHKEY_USERS\S-1-5-19_ClassesFalse1
Fn
OPEN_KEY\REGISTRY\MACHINE\Software\Microsoft\Rpc\ExtensionsTrue1
Fn
OPEN_KEYControl Panel\InternationalTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocaleTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocaleTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\IdsTrue1
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Services\Tcpip\ParametersTrue4
Fn
OPEN_KEY\Registry\Machine\System\CurrentControlSet\Control\ComputerNameTrue3
Fn
OPEN_KEY\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\OptionFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versionsvalue_name = 139059393024True1
Fn
READ_VALUETrue26
Fn
READ_VALUEvalue_name = LocalServiceNetworkRestrictedTrue2
Fn
READ_VALUEvalue_name = CoInitializeSecurityParamTrue1
Fn
READ_VALUEFalse21
Fn
READ_VALUEvalue_name = CoInitializeSecurityAllowLowBoxFalse1
Fn
READ_VALUEvalue_name = AuthenticationLevelFalse1
Fn
READ_VALUEvalue_name = ImpersonationLevelFalse1
Fn
READ_VALUEvalue_name = AuthenticationCapabilitiesFalse1
Fn
READ_VALUEvalue_name = CoInitializeSecurityAppIDFalse1
Fn
READ_VALUEvalue_name = DefaultRpcStackSizeTrue1
Fn
READ_VALUEvalue_name = RpcExceptionFilterModeFalse1
Fn
READ_VALUEvalue_name = SystemCriticalFalse1
Fn
READ_VALUEvalue_name = NoGuiAccessFalse1
Fn
READ_VALUEvalue_name = PageAllocatorUseSystemHeapFalse1
Fn
READ_VALUEvalue_name = PageAllocatorSystemHeapIsPrivateFalse1
Fn
READ_VALUEvalue_name = AggressiveMTATestingFalse1
Fn
READ_VALUE\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initializevalue_name = DisableMetaFilesFalse1
Fn
READ_VALUEvalue_name = LoadAppInit_DLLsTrue1
Fn
READ_VALUEvalue_name = MaxRpcSizeFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNamevalue_name = ComputerNameTrue5
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = OOBEInProgressFalse2
Fn
READ_VALUE\Registry\Machine\System\Setupvalue_name = SystemSetupInProgressTrue2
Fn
READ_VALUEvalue_name = IdleTimerWindowFalse1
Fn
READ_VALUE\REGISTRY\MACHINE\Software\Microsoft\Rpc\Extensionsvalue_name = NdrOleExtDLLTrue1
Fn
READ_VALUEControl Panel\InternationalFalse1
Fn
READ_VALUEControl Panel\InternationalTrue1
Fn
READ_VALUEControl Panel\Internationalvalue_name = sCurrencyOverrideFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocalevalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocalevalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versionsvalue_name = 000602xxTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Idsvalue_name = en-USFalse1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Idsvalue_name = enFalse1
Fn
READ_VALUENameless FileMappingvalue_name = ServiceDllTrue1
Fn
READ_VALUENameless FileMappingvalue_name = ServiceManifestFalse1
Fn
READ_VALUENameless FileMappingvalue_name = ServiceMainTrue2
Fn
READ_VALUEvalue_name = CompatFlagsFalse1
Fn
READ_VALUEvalue_name = MaxSizeTrue3
Fn
READ_VALUEvalue_name = RetentionTrue3
Fn
READ_VALUEvalue_name = AutoBackupLogFilesFalse4
Fn
READ_VALUEvalue_name = CustomSDFalse3
Fn
READ_VALUEvalue_name = MaxSizeFalse1
Fn
READ_VALUEvalue_name = RetentionFalse1
Fn
READ_VALUEvalue_name = CustomSDTrue2
Fn
READ_VALUEvalue_name = WarningLevelFalse1
Fn
READ_VALUEvalue_name = SystemSetupInProgressTrue3
Fn
READ_VALUEvalue_name = ProductNameTrue1
Fn
READ_VALUEvalue_name = CurrentTypeTrue3
Fn
READ_VALUEvalue_name = InstallDateTrue1
Fn
READ_VALUEvalue_name = BuildLabTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parametersvalue_name = HostnameFalse4
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNamevalue_name = SystemSetupInProgressTrue1
Fn
READ_VALUE\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNamevalue_name = 9True1
Fn
READ_VALUEvalue_name = SecurityProvidersFalse1
Fn
READ_VALUEvalue_name = crashonauditfailTrue1
Fn
Driver (3)
+
OperationDriverAdditional InformationSuccessAmountLogfile
CONTROLTrue1
Fn
CONTROLcontrol_code = 0x390008True1
Fn
CONTROLcontrol_code = 0x110008False1
Fn
System (21)
+
OperationInformationSuccessAmountLogfile
SLEEPTrue2
Fn
SLEEPduration = 1 milliseconds (0.001 seconds)True2
Fn
SLEEPFalse1
Fn
SLEEPduration = 1 milliseconds (0.001 seconds)False1
Fn
GET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
GET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue8
Fn
GET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue3
Fn
GET_INFOTrue2
Fn
GET_INFOFalse1
Fn
Process #19: wallpaperhost.exe
+
InformationValue
ID / OS PID#19 / 0x2ac
OS Parent PID0x290 (\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wallpaperhost.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wallpaperhost.exe
Command LineX:\windows\system32\WallpaperHost.exe
MonitorStart Time: 00:02:04, Reason: Child Process
UnmonitorEnd Time: 00:02:04, Reason: Terminated
Monitor Duration00:00:00
OS Thread IDs
RemarksNo high level activity detected in monitored regions
Process #20: wallpaperhost.exe
+
InformationValue
ID / OS PID#20 / 0x2b8
OS Parent PID0x290 (\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wallpaperhost.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wallpaperhost.exe
Command LineX:\windows\system32\WallpaperHost.exe
MonitorStart Time: 00:02:04, Reason: Child Process
UnmonitorEnd Time: 00:02:04, Reason: Terminated
Monitor Duration00:00:00
OS Thread IDs
RemarksNo high level activity detected in monitored regions
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefox with deactivated setting "security.fileuri.strict_origin_policy".


Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image