VMRay Analyzer Report
Monitored Processes
Process Graph
Behavior Information - Sequential View
Process #1: cb91b8695d3990b5b5eae8a714bd357e.exe
(Host: 408, Network: 0)
+
InformationValue
ID / OS PID#1 / 0x7a8
OS Parent PID0x358 (c:\windows\explorer.exe)
Initial Working DirectoryC:\Users\uWZPA0LPqa\Desktop
File Namec:\users\uwzpa0lpqa\desktop\cb91b8695d3990b5b5eae8a714bd357e.exe
Command Line"C:\Users\uWZPA0LPqa\Desktop\cb91b8695d3990b5b5eae8a714bd357e.exe"
MonitorStart Time: 00:00:38, Reason: Analysis Target
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:01:29
OS Thread IDs
#1
0xA98
#2
0x5FC
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x00000000000100000x000100000x0002ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000000000100000x000100000x0001ffffPagefile Backed FileReadable, WritableTrue
private_0x00000000000200000x000200000x00023fffPrivate MemoryReadable, WritableTrue
private_0x00000000000300000x000300000x00030fffPrivate MemoryReadable, WritableTrue
private_0x00000000000300000x000300000x00030fffPrivate MemoryReadable, WritableTrue
pagefile_0x00000000000400000x000400000x0004efffPagefile Backed FileReadableTrue
private_0x00000000000500000x000500000x0008ffffPrivate MemoryReadable, WritableTrue
private_0x00000000000900000x000900000x0018ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000000001900000x001900000x00193fffPagefile Backed FileReadableTrue
private_0x00000000001a00000x001a00000x001a1fffPrivate MemoryReadable, WritableTrue
private_0x00000000001b00000x001b00000x001b0fffPrivate MemoryReadable, WritableTrue
private_0x00000000001d00000x001d00000x001dffffPrivate MemoryReadable, WritableTrue
private_0x00000000001e00000x001e00000x001effffPrivate MemoryReadable, WritableTrue
locale.nls0x001f00000x0026dfffMemory Mapped FileReadableFalse
private_0x00000000002700000x002700000x002d3fffPrivate MemoryReadableTrue
private_0x00000000002e00000x002e00000x003dffffPrivate MemoryReadable, WritableTrue
cb91b8695d3990b5b5eae8a714bd357e.exe0x004000000x00463fffMemory Mapped FileReadable, Writable, ExecutableTrue
private_0x00000000004700000x004700000x00495fffPrivate MemoryReadable, WritableTrue
private_0x00000000005200000x005200000x0052ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000000005300000x005300000x006b7fffPagefile Backed FileReadableTrue
pagefile_0x00000000006c00000x006c00000x00840fffPagefile Backed FileReadableTrue
pagefile_0x00000000008500000x008500000x01c4ffffPagefile Backed FileReadableTrue
SortDefault.nls0x01c500000x01f24fffMemory Mapped FileReadableFalse
winspool.drv0x74ab00000x74b14fffMemory Mapped FileReadable, Writable, ExecutableFalse
profapi.dll0x74b200000x74b2efffMemory Mapped FileReadable, Writable, ExecutableFalse
userenv.dll0x74b300000x74b4afffMemory Mapped FileReadable, Writable, ExecutableFalse
iertutil.dll0x74b500000x74d81fffMemory Mapped FileReadable, Writable, ExecutableFalse
wininet.dll0x74d900000x74f65fffMemory Mapped FileReadable, Writable, ExecutableFalse
comctl32.dll0x74f700000x74ff8fffMemory Mapped FileReadable, Writable, ExecutableFalse
apphelp.dll0x750000000x7509ffffMemory Mapped FileReadable, Writable, ExecutableFalse
bcryptprimitives.dll0x750a00000x750f3fffMemory Mapped FileReadable, Writable, ExecutableFalse
cryptbase.dll0x751000000x75109fffMemory Mapped FileReadable, Writable, ExecutableFalse
sspicli.dll0x751100000x7512dfffMemory Mapped FileReadable, Writable, ExecutableFalse
KernelBase.dll0x751900000x75266fffMemory Mapped FileReadable, Writable, ExecutableFalse
imagehlp.dll0x752700000x75283fffMemory Mapped FileReadable, Writable, ExecutableFalse
gdi32.dll0x753200000x7542dfffMemory Mapped FileReadable, Writable, ExecutableFalse
advapi32.dll0x754300000x754abfffMemory Mapped FileReadable, Writable, ExecutableFalse
shlwapi.dll0x755000000x75544fffMemory Mapped FileReadable, Writable, ExecutableFalse
psapi.dll0x755500000x75555fffMemory Mapped FileReadable, Writable, ExecutableFalse
rpcrt4.dll0x756200000x756d9fffMemory Mapped FileReadable, Writable, ExecutableFalse
sechost.dll0x757900000x757d0fffMemory Mapped FileReadable, Writable, ExecutableFalse
combase.dll0x757e00000x7595cfffMemory Mapped FileReadable, Writable, ExecutableFalse
kernel32.dll0x759600000x75a9ffffMemory Mapped FileReadable, Writable, ExecutableFalse
ole32.dll0x75aa00000x75bc7fffMemory Mapped FileReadable, Writable, ExecutableFalse
shell32.dll0x75c600000x76f0cfffMemory Mapped FileReadable, Writable, ExecutableFalse
msvcrt.dll0x772400000x77302fffMemory Mapped FileReadable, Writable, ExecutableFalse
msctf.dll0x773500000x77462fffMemory Mapped FileReadable, Writable, ExecutableFalse
user32.dll0x776a00000x777f2fffMemory Mapped FileReadable, Writable, ExecutableFalse
imm32.dll0x778000000x77826fffMemory Mapped FileReadable, Writable, ExecutableFalse
wow64.dll0x778400000x7788afffMemory Mapped FileReadable, Writable, ExecutableFalse
wow64win.dll0x778900000x778f7fffMemory Mapped FileReadable, Writable, ExecutableFalse
wow64cpu.dll0x779000000x77908fffMemory Mapped FileReadable, Writable, ExecutableFalse
ntdll.dll0x779100000x77a7dfffMemory Mapped FileReadable, Writable, ExecutableFalse
pagefile_0x000000007feb00000x7feb00000x7ffaffffPagefile Backed FileReadableTrue
pagefile_0x000000007ffb00000x7ffb00000x7ffd2fffPagefile Backed FileReadableTrue
private_0x000000007ffdb0000x7ffdb0000x7ffddfffPrivate MemoryReadable, WritableTrue
private_0x000000007ffde0000x7ffde0000x7ffdefffPrivate MemoryReadable, WritableTrue
private_0x000000007ffdf0000x7ffdf0000x7ffdffffPrivate MemoryReadable, WritableTrue
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x000000007fff00000x7fff00000x7ff80c08ffffPrivate MemoryReadableTrue
ntdll.dll0x7ff80c0900000x7ff80c23bfffMemory Mapped FileReadable, Writable, ExecutableFalse
private_0x00007ff80c23c0000x7ff80c23c0000x7ffffffeffffPrivate MemoryReadableTrue
Created or Modified Files
+
FilenameFile SizeHash Values
c:\users\uwzpa0~1\appdata\local\temp\3e0d.tmp 225.50 KB (230912 bytes)MD5: cb91b8695d3990b5b5eae8a714bd357e
SHA1: 3cd6ef10dd6cbe6f158a360cf5b112cef2e18304
SHA256: eec6bfe112155ab94029f0f8f27a484edf35b5d743503e0199637084d9520ebc
Threads
Thread 0xa98
(Host: 408, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
MODGET_PROC_ADDRESSfunction = StrCmpNIA, address_out = 0x7551b430True1
Fn
MODGET_HANDLEmodule_name = KERNEL32.dllTrue1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = GetTempPathA, address_out = 0x75985890True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = GetProcAddress, address_out = 0x75977b50True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = GetModuleHandleA, address_out = 0x75978f60True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = CopyFileA, address_out = 0x7597fe50True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = LoadLibraryExA, address_out = 0x7597a970True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = FreeLibrary, address_out = 0x7597a790True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = DeleteFileA, address_out = 0x75988950True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = GetPrivateProfileIntA, address_out = 0x7597ca90True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = GetPrivateProfileStringA, address_out = 0x7597cb60True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = WritePrivateProfileStringA, address_out = 0x7597c590True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = CreateFileA, address_out = 0x75988920True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = WriteFile, address_out = 0x75988cf0True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = CloseHandle, address_out = 0x759886f0True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = GetTempFileNameA, address_out = 0x759a3bf0True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = GetSystemTime, address_out = 0x75979200True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = GetFileAttributesA, address_out = 0x75988aa0True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = DeviceIoControl, address_out = 0x75978a50True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = SystemTimeToFileTime, address_out = 0x7597a950True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = GetCurrentProcessId, address_out = 0x759722d0True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = FreeLibraryAndExitThread, address_out = 0x75985c10True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = GetCurrentProcess, address_out = 0x759728e0True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = CreateFileW, address_out = 0x75988930True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = GetFileSize, address_out = 0x75988af0True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = ReadFile, address_out = 0x75988c00True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = SetFilePointer, address_out = 0x75988c90True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = SetEndOfFile, address_out = 0x75988c50True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = GetModuleHandleW, address_out = 0x7597a0c0True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = CopyFileW, address_out = 0x75986770True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = CreateFileMappingA, address_out = 0x759770f0True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = MapViewOfFile, address_out = 0x75978b50True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = UnmapViewOfFile, address_out = 0x7597a100True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = Sleep, address_out = 0x759782d0True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = DeleteFileW, address_out = 0x75988960True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = ExitProcess, address_out = 0x75989850True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = GetCommandLineA, address_out = 0x7597b5a0True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = CreateThread, address_out = 0x7597a740True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = GetSystemTimeAsFileTime, address_out = 0x759770c0True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = VirtualProtect, address_out = 0x75978ab0True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = VirtualFree, address_out = 0x75978f20True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = GetLastError, address_out = 0x759726e0True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = GetVersionExA, address_out = 0x75978b10True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = MoveFileExW, address_out = 0x7597b950True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = GetTempFileNameW, address_out = 0x75988b80True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = GetTempPathW, address_out = 0x75988b90True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = GetModuleFileNameW, address_out = 0x7597a0e0True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = GetWindowsDirectoryW, address_out = 0x7597b6c0True1
Fn
MODGET_PROC_ADDRESSmodule_name = KERNEL32.dll, function = VirtualAlloc, address_out = 0x75978b90True1
Fn
MODGET_HANDLEmodule_name = ADVAPI32.dllTrue1
Fn
MODGET_PROC_ADDRESSmodule_name = ADVAPI32.dll, function = QueryServiceStatusEx, address_out = 0x7545ce30True1
Fn
MODGET_PROC_ADDRESSmodule_name = ADVAPI32.dll, function = StartServiceA, address_out = 0x754746d0True1
Fn
MODGET_PROC_ADDRESSmodule_name = ADVAPI32.dll, function = OpenSCManagerA, address_out = 0x75439510True1
Fn
MODGET_PROC_ADDRESSmodule_name = ADVAPI32.dll, function = OpenServiceA, address_out = 0x75474320True1
Fn
MODGET_PROC_ADDRESSmodule_name = ADVAPI32.dll, function = GetUserNameW, address_out = 0x75447190True1
Fn
MODGET_PROC_ADDRESSmodule_name = ADVAPI32.dll, function = OpenProcessToken, address_out = 0x75439290True1
Fn
MODGET_PROC_ADDRESSmodule_name = ADVAPI32.dll, function = RegCloseKey, address_out = 0x75439330True1
Fn
MODGET_PROC_ADDRESSmodule_name = ADVAPI32.dll, function = RegSetValueExA, address_out = 0x75446fb0True1
Fn
MODGET_PROC_ADDRESSmodule_name = ADVAPI32.dll, function = RegCreateKeyA, address_out = 0x7545c620True1
Fn
MODGET_PROC_ADDRESSmodule_name = ADVAPI32.dll, function = CloseServiceHandle, address_out = 0x754394f0True1
Fn
MODGET_HANDLEmodule_name = ntdll.dllTrue1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = RtlComputeCrc32, address_out = 0x779e7db0True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = LdrAddRefDll, address_out = 0x77973f70True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = ZwImpersonateThread, address_out = 0x7794d7e0True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = ZwOpenThread, address_out = 0x7794da70True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = RtlEqualUnicodeString, address_out = 0x7795a050True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = ZwQueryInformationToken, address_out = 0x7794cb40True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = wcsncpy, address_out = 0x779ad5b0True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = ZwOpenFile, address_out = 0x7794cc60True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = ZwClose, address_out = 0x7794ca20True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = ZwLoadDriver, address_out = 0x7794d850True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = strncat, address_out = 0x77938c30True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = ZwCreateEvent, address_out = 0x7794cdb0True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = RtlInitUnicodeString, address_out = 0x77937520True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = _snwprintf, address_out = 0x779ac100True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = atoi, address_out = 0x779abbf0True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = ZwTestAlert, address_out = 0x7794e2f0True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = RtlRandom, address_out = 0x779f2780True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = ZwRaiseHardError, address_out = 0x7794ddb0True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = RtlAdjustPrivilege, address_out = 0x779ab650True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = ZwQuerySystemInformation, address_out = 0x7794cc90True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = sscanf, address_out = 0x779acff0True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = strncpy, address_out = 0x77938d70True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = _chkstk, address_out = 0x77951140True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = memcpy, address_out = 0x779382c0True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = _snprintf, address_out = 0x779ac050True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = RtlImageNtHeader, address_out = 0x77964af0True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = ZwDeviceIoControlFile, address_out = 0x7794c9a0True1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = memset, address_out = 0x77938940True1
Fn
MODGET_HANDLEmodule_name = SHLWAPI.dllTrue1
Fn
MODGET_PROC_ADDRESSmodule_name = SHLWAPI.dll, function = StrStrIW, address_out = 0x75508bc0True1
Fn
MODGET_PROC_ADDRESSmodule_name = SHLWAPI.dll, function = SHDeleteKeyA, address_out = 0x7551ba40True1
Fn
MODGET_PROC_ADDRESSmodule_name = SHLWAPI.dll, function = PathFileExistsW, address_out = 0x75508fc0True1
Fn
MODGET_PROC_ADDRESSmodule_name = SHLWAPI.dll, function = StrStrIA, address_out = 0x7550f9c0True1
Fn
MODGET_PROC_ADDRESSmodule_name = SHLWAPI.dll, function = PathFileExistsA, address_out = 0x7551ab40True1
Fn
MODGET_PROC_ADDRESSmodule_name = SHLWAPI.dll, function = PathAppendA, address_out = 0x7551aa60True1
Fn
MODGET_PROC_ADDRESSmodule_name = SHLWAPI.dll, function = PathFindFileNameW, address_out = 0x75508ba0True1
Fn
MODGET_PROC_ADDRESSmodule_name = SHLWAPI.dll, function = SHGetValueA, address_out = 0x7550f890True1
Fn
MODGET_PROC_ADDRESSmodule_name = SHLWAPI.dll, function = PathRemoveFileSpecA, address_out = 0x7551aee0True1
Fn
MODGET_HANDLEmodule_name = imagehlp.dllFalse1
Fn
MODLOADmodule_name = imagehlp.dll, base_address = 0x75270000True1
Fn
MODGET_PROC_ADDRESSmodule_name = imagehlp.dll, function = CheckSumMappedFile, address_out = 0x75277d30True1
Fn
MODGET_HANDLEmodule_name = PSAPI.DLLFalse1
Fn
MODLOADmodule_name = PSAPI.DLL, base_address = 0x75550000True1
Fn
MODGET_PROC_ADDRESSmodule_name = PSAPI.DLL, function = GetMappedFileNameW, address_out = 0x75551720True1
Fn
MODGET_HANDLEmodule_name = RPCRT4.dllTrue1
Fn
MODGET_PROC_ADDRESSmodule_name = RPCRT4.dll, function = UuidCreateSequential, address_out = 0x7564bb50True1
Fn
MODGET_HANDLEmodule_name = WININET.dllFalse1
Fn
MODLOADmodule_name = WININET.dll, base_address = 0x74d90000True1
Fn
MODGET_PROC_ADDRESSmodule_name = WININET.dll, function = InternetCrackUrlA, address_out = 0x74e0fd30True1
Fn
MODGET_PROC_ADDRESSmodule_name = WININET.dll, function = InternetConnectA, address_out = 0x74e3a3c0True1
Fn
MODGET_PROC_ADDRESSmodule_name = WININET.dll, function = HttpOpenRequestA, address_out = 0x74e3a450True1
Fn
MODGET_PROC_ADDRESSmodule_name = WININET.dll, function = HttpSendRequestA, address_out = 0x74e370c0True1
Fn
MODGET_PROC_ADDRESSmodule_name = WININET.dll, function = InternetQueryOptionA, address_out = 0x74da1e40True1
Fn
MODGET_PROC_ADDRESSmodule_name = WININET.dll, function = InternetSetOptionA, address_out = 0x74da4230True1
Fn
MODGET_PROC_ADDRESSmodule_name = WININET.dll, function = InternetCloseHandle, address_out = 0x74db43c0True1
Fn
MODGET_PROC_ADDRESSmodule_name = WININET.dll, function = InternetOpenA, address_out = 0x74dd34f0True1
Fn
MODGET_HANDLEmodule_name = SHELL32.dllFalse1
Fn
MODLOADmodule_name = SHELL32.dll, base_address = 0x75c60000True1
Fn
MODGET_PROC_ADDRESSmodule_name = SHELL32.dll, function = ShellExecuteW, address_out = 0x75d408f0True1
Fn
MODGET_HANDLEmodule_name = ole32.dllFalse1
Fn
MODLOADmodule_name = ole32.dll, base_address = 0x75aa0000True1
Fn
MODGET_PROC_ADDRESSmodule_name = ole32.dll, function = CoCreateInstance, address_out = 0x75800590True1
Fn
MODGET_PROC_ADDRESSmodule_name = ole32.dll, function = CoInitialize, address_out = 0x75aa9ec0True1
Fn
MODGET_PROC_ADDRESSmodule_name = ole32.dll, function = CoUninitialize, address_out = 0x757eb890True1
Fn
MODGET_HANDLEmodule_name = WINSPOOL.DRVFalse1
Fn
MODLOADmodule_name = WINSPOOL.DRV, base_address = 0x74ab0000True1
Fn
MODGET_PROC_ADDRESSmodule_name = WINSPOOL.DRV, function = DeletePrintProvidorW, address_out = 0x74ad6410True1
Fn
MODGET_PROC_ADDRESSmodule_name = WINSPOOL.DRV, function = AddPrintProvidorW, address_out = 0x74ad4aa0True1
Fn
MODGET_HANDLEmodule_name = c:\users\uwzpa0lpqa\desktop\cb91b8695d3990b5b5eae8a714bd357e.exeTrue1
Fn
MODGET_HANDLEmodule_name = kernel32.dllTrue1
Fn
MODGET_PROC_ADDRESSmodule_name = kernel32.dll, function = IsWow64Process, address_out = 0x75978f40True1
Fn
FILECREATE_TMPFILEfile_name = c:\users\uwzpa0~1\appdata\local\temp\ff1e.tmp, path = C:\Users\UWZPA0~1\AppData\Local\Temp\True1
Fn
MODGET_HANDLEmodule_name = ntdll.dllTrue1
Fn
MODGET_PROC_ADDRESSmodule_name = ntdll.dll, function = _snwprintf, address_out = 0x779ac100True1
Fn
FILEOPENfile_name = c:, desired_access = SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERTTrue1
Fn
DRVCONTROLfile_name = c:, control_code = 0x560000True1
Fn
FILEOPENfile_name = \device\harddisk0\dr0, desired_access = SYNCHRONIZE, GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERTTrue1
Fn
DRVCONTROLfile_name = \device\harddisk0\dr0, control_code = 0x4d014True266
Fn
FILECREATE_TMPFILEfile_name = c:\users\uwzpa0~1\appdata\local\temp\3e0d.tmp, path = C:\Users\UWZPA0~1\AppData\Local\Temp\True1
Fn
FILEMOVEfile_name = c:\users\uwzpa0~1\appdata\local\temp\3e0d.tmp, file_name = c:\users\uwzpa0lpqa\desktop\cb91b8695d3990b5b5eae8a714bd357e.exeTrue1
Fn
FILEMOVEfile_name = c:\users\uwzpa0~1\appdata\local\temp\3e0d.tmpTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, privilege = SeShutdownPrivilege, enable_privilege = 1True1
Fn
Process #2: System
+
InformationValue
ID / OS PID#2 / 0x4
OS Parent PID0xffffffffffffffff (Unknown)
Initial Working Directory
File NameSystem
Command Line
MonitorStart Time: 00:01:20, Reason: Kernel Analysis
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:47
OS Thread IDs
#3
0x8
#4
0x18
#5
0x14
#6
0x28
#7
0x38
#8
0x70
#9
0x74
#10
0x90
#11
0x94
#12
0x5C
#13
0x30
#14
0x9C
#15
0xAC
#16
0xB0
#17
0x88
#18
0x84
#19
0x80
#20
0x8C
#21
0xC8
#22
0x78
#23
0x7C
#24
0xE0
#26
0x4C
#28
0xFC
#29
0x100
#30
0x104
#31
0x108
#32
0x110
#33
0xF4
#34
0x10C
#35
0x58
#36
0x11C
#37
0x10
#38
0x34
#39
0x124
#42
0x13C
#43
0x144
#44
0x148
#57
0x20
#60
0x190
#61
0x140
#70
0xE8
#86
0x128
#89
0x1F0
#96
0x3C
#118
0x48
RemarksNo high level activity detected in monitored regions
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
pagefile_0x000000d9847a00000xd9847a00000xd9847c2fffPagefile Backed FileReadable, WritableTrue
Process #3: smss.exe
+
InformationValue
ID / OS PID#3 / 0xec
OS Parent PID0x4 (System)
Initial Working DirectoryX:\windows
File Namec:\windows\system32\smss.exe
Command Line\SystemRoot\System32\smss.exe
MonitorStart Time: 00:01:27, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:40
OS Thread IDs
#25
0xF0
#27
0xF8
#66
0x1A8
RemarksNo high level activity detected in monitored regions
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x00000075205b00000x75205b00000x75205cffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000075205d00000x75205d00000x75205defffPagefile Backed FileReadableTrue
private_0x00000075205e00000x75205e00000x752065ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007ff6fef700000x7ff6fef700000x7ff6fef92fffPagefile Backed FileReadableTrue
private_0x00007ff6fef9c0000x7ff6fef9c0000x7ff6fef9cfffPrivate MemoryReadable, WritableTrue
private_0x00007ff6fef9e0000x7ff6fef9e0000x7ff6fef9ffffPrivate MemoryReadable, WritableTrue
smss.exe0x7ff6ff8f00000x7ff6ff914fffMemory Mapped FileReadable, Writable, ExecutableFalse
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Process #4: smss.exe
+
InformationValue
ID / OS PID#4 / 0x12c
OS Parent PID0xec (c:\windows\system32\smss.exe)
Initial Working DirectoryX:\windows
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\smss.exe
Command Line\SystemRoot\System32\smss.exe 00000000 00000050
MonitorStart Time: 00:01:32, Reason: Child Process
UnmonitorEnd Time: 00:01:33, Reason: Terminated
Monitor Duration00:00:01
OS Thread IDs
#40
0x130
RemarksNo high level activity detected in monitored regions
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x000000af73b500000xaf73b500000xaf73b6ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000af73b700000xaf73b700000xaf73b7efffPagefile Backed FileReadableTrue
private_0x000000af73b800000xaf73b800000xaf73bfffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007ff6fef000000x7ff6fef000000x7ff6fef22fffPagefile Backed FileReadableTrue
private_0x00007ff6fef2c0000x7ff6fef2c0000x7ff6fef2dfffPrivate MemoryReadable, WritableTrue
private_0x00007ff6fef2e0000x7ff6fef2e0000x7ff6fef2efffPrivate MemoryReadable, WritableTrue
smss.exe0x7ff6ff8f00000x7ff6ff914fffMemory Mapped FileReadable, Writable, ExecutableFalse
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Process #5: csrss.exe
(Host: 258, Network: 0)
+
InformationValue
ID / OS PID#5 / 0x134
OS Parent PID0x12c (\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\smss.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe
Command Line%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
MonitorStart Time: 00:01:32, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:35
OS Thread IDs
#41
0x138
#45
0x14C
#46
0x150
#47
0x154
#48
0x158
#58
0x188
#63
0x1A0
#64
0x1A4
#87
0x200
#128
0x2BC
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x00000045829600000x45829600000x458297ffffPrivate MemoryReadable, WritableTrue
private_0x00000045829600000x45829600000x4582966fffPrivate MemoryReadable, WritableTrue
csrss.exe.mui0x45829700000x4582970fffMemory Mapped FileReadableFalse
pagefile_0x00000045829800000x45829800000x458298efffPagefile Backed FileReadableTrue
private_0x00000045829900000x45829900000x45829cffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000045829900000x45829900000x458299ffffPagefile Backed FileReadable, WritableTrue
MARLETT.TTF0x45829a00000x45829a6fffMemory Mapped FileReadableFalse
pagefile_0x00000045829b00000x45829b00000x45829c7fffPagefile Backed FileReadableTrue
locale.nls0x45829d00000x4582a4dfffMemory Mapped FileReadableFalse
winsrv.DLL.mui0x4582a500000x4582a51fffMemory Mapped FileReadableFalse
private_0x0000004582a600000x4582a600000x4582a60fffPrivate MemoryReadable, WritableTrue
VGASYS.FON0x4582a700000x4582a71fffMemory Mapped FileReadableFalse
private_0x0000004582a800000x4582a800000x4582abffffPrivate MemoryReadable, WritableTrue
private_0x0000004582ac00000x4582ac00000x4582ac0fffPrivate MemoryReadable, WritableTrue
private_0x0000004582ad00000x4582ad00000x4582ad0fffPrivate MemoryReadable, WritableTrue
private_0x0000004582ae00000x4582ae00000x4582ae0fffPrivate MemoryReadable, WritableTrue
private_0x0000004582af00000x4582af00000x4582beffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000004582bf00000x4582bf00000x4582d70fffPagefile Backed FileReadableTrue
private_0x0000004582d800000x4582d800000x4582dbffffPrivate MemoryReadable, WritableTrue
private_0x0000004582dc00000x4582dc00000x4582dfffffPrivate MemoryReadable, WritableTrue
private_0x0000004582e000000x4582e000000x4582e3ffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000004582e400000x4582e400000x4582fc7fffPagefile Backed FileReadableTrue
private_0x0000004582fd00000x4582fd00000x458300ffffPrivate MemoryReadable, WritableTrue
private_0x00000045830100000x45830100000x458304ffffPrivate MemoryReadable, WritableTrue
private_0x00000045830500000x45830500000x458308ffffPrivate MemoryReadable, WritableTrue
TAHOMABD.TTF0x45830900000x4583139fffMemory Mapped FileReadableFalse
TAHOMA.TTF0x45831400000x45831f6fffMemory Mapped FileReadableFalse
pagefile_0x00000045832000000x45832000000x458322ffffPagefile Backed FileReadableTrue
pagefile_0x00000045832300000x45832300000x458462ffffPagefile Backed FileReadableTrue
pagefile_0x00000045846300000x45846300000x458463ffffPagefile Backed FileReadable, WritableTrue
pagefile_0x00000045846400000x45846400000x458464ffffPagefile Backed FileReadable, WritableTrue
private_0x00000045846500000x45846500000x458468ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000045846900000x45846900000x458469ffffPagefile Backed FileReadable, WritableTrue
pagefile_0x00000045846a00000x45846a00000x45846affffPagefile Backed FileReadable, WritableTrue
private_0x00007ff61939c0000x7ff61939c0000x7ff61939dfffPrivate MemoryReadable, WritableTrue
private_0x00007ff61939e0000x7ff61939e0000x7ff61939ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007ff6193a00000x7ff6193a00000x7ff61949ffffPagefile Backed FileReadable, WritableTrue
pagefile_0x00007ff6194a00000x7ff6194a00000x7ff6194c2fffPagefile Backed FileReadableTrue
private_0x00007ff6194c30000x7ff6194c30000x7ff6194c4fffPrivate MemoryReadable, WritableTrue
private_0x00007ff6194c50000x7ff6194c50000x7ff6194c6fffPrivate MemoryReadable, WritableTrue
private_0x00007ff6194c70000x7ff6194c70000x7ff6194c8fffPrivate MemoryReadable, WritableTrue
private_0x00007ff6194c90000x7ff6194c90000x7ff6194cafffPrivate MemoryReadable, WritableTrue
private_0x00007ff6194cb0000x7ff6194cb0000x7ff6194ccfffPrivate MemoryReadable, WritableTrue
private_0x00007ff6194cd0000x7ff6194cd0000x7ff6194cefffPrivate MemoryReadable, WritableTrue
private_0x00007ff6194cd0000x7ff6194cd0000x7ff6194cefffPrivate MemoryReadable, WritableTrue
private_0x00007ff6194cf0000x7ff6194cf0000x7ff6194cffffPrivate MemoryReadable, WritableTrue
csrss.exe0x7ff61a1000000x7ff61a106fffMemory Mapped FileReadable, Writable, ExecutableFalse
bcryptPrimitives.dll0x7ffb715800000x7ffb715e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTBASE.dll0x7ffb715f00000x7ffb715fafffMemory Mapped FileReadable, Writable, ExecutableFalse
sxs.dll0x7ffb716000000x7ffb71698fffMemory Mapped FileReadable, Writable, ExecutableFalse
sxssrv.DLL0x7ffb716d00000x7ffb716dcfffMemory Mapped FileReadable, Writable, ExecutableFalse
winsrv.DLL0x7ffb716e00000x7ffb71713fffMemory Mapped FileReadable, Writable, ExecutableFalse
basesrv.DLL0x7ffb717200000x7ffb71732fffMemory Mapped FileReadable, Writable, ExecutableFalse
CSRSRV.dll0x7ffb717400000x7ffb71755fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
gdi32.dll0x7ffb71ad00000x7ffb71c20fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
user32.dll0x7ffb73e900000x7ffb74006fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Threads
Thread 0x138
(Host: 17, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
SYSGET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue2
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Terminal ServerTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Terminal Server, value_name = TSAppCompatFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Terminal Server, value_name = TSUserEnabledFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
MODGET_HANDLEmodule_name = csrsrv.dllTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_InitializeTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize, value_name = DisableMetaFilesFalse1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True7
Fn
Thread 0x154
(Host: 24, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, maximum_size = 298548457472, protection = PAGE_READWRITETrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x4584630000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x4584630000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, maximum_size = 298548457472, protection = PAGE_READWRITETrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x4584690000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x4584690000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, maximum_size = 298548458592, protection = PAGE_READWRITETrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x45846b0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x45846b0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
Thread 0x188
(Host: 217, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 298550616872True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.systemcompatible_6595b64144ccf1df_6.0.9600.16384_none_69e3a25fa94e130a.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.systemcompatible_6595b64144ccf1df_6.0.9600.16384_none_69e3a25fa94e130a.manifest, size = 4095True1
Fn
Data
FILEREADTrue2
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.systemcompatible_6595b64144ccf1df_6.0.9600.16384_none_69e3a25fa94e130a.manifest, size = 8180False1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 298550613992True1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 298550613992True1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 298550613992True1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.isolationautomation_6595b64144ccf1df_1.0.0.0_none_ee2620cf57bc84de.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.isolationautomation_6595b64144ccf1df_1.0.0.0_none_ee2620cf57bc84de.manifest, size = 2True1
Fn
Data
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.isolationautomation_6595b64144ccf1df_1.0.0.0_none_ee2620cf57bc84de.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.isolationautomation_6595b64144ccf1df_1.0.0.0_none_ee2620cf57bc84de.manifest, size = 4095True1
Fn
Data
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x390008True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.isolationautomation_6595b64144ccf1df_1.0.0.0_none_ee2620cf57bc84de.manifest, size = 8180False1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 298550613992True1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.17415_none_932b3b5547500489.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.17415_none_932b3b5547500489.manifest, size = 2True1
Fn
Data
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.17415_none_932b3b5547500489.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.17415_none_932b3b5547500489.manifest, size = 4095True1
Fn
Data
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.17415_none_932b3b5547500489.manifest, size = 8180False1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52.manifest, size = 2True1
Fn
Data
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52.manifest, size = 4095True1
Fn
Data
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52.manifest, size = 8180False1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 298550613992True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_1.0.9600.17415_none_bd4349237a1100f7.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_1.0.9600.17415_none_bd4349237a1100f7.manifest, size = 2True1
Fn
Data
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_1.0.9600.17415_none_bd4349237a1100f7.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_1.0.9600.17415_none_bd4349237a1100f7.manifest, size = 4095True1
Fn
Data
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_1.0.9600.17415_none_bd4349237a1100f7.manifest, size = 8180False1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.9600.16384_en-us_4ab3da74c23648d7.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.9600.16384_en-us_4ab3da74c23648d7.manifest, size = 2True1
Fn
Data
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.9600.16384_en-us_4ab3da74c23648d7.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.9600.16384_en-us_4ab3da74c23648d7.manifest, size = 4095True1
Fn
Data
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.9600.16384_en-us_4ab3da74c23648d7.manifest, size = 8180False1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, maximum_size = 298550618448, protection = PAGE_READWRITETrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x4584630000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x4584630000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, maximum_size = 298550618992, protection = PAGE_READWRITETrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x4584630000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x4584630000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
Process #6: smss.exe
+
InformationValue
ID / OS PID#6 / 0x15c
OS Parent PID0xec (c:\windows\system32\smss.exe)
Initial Working DirectoryX:\windows
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\smss.exe
Command Line\SystemRoot\System32\smss.exe 00000001 00000050
MonitorStart Time: 00:01:33, Reason: Child Process
UnmonitorEnd Time: 00:01:34, Reason: Terminated
Monitor Duration00:00:01
OS Thread IDs
#49
0x160
RemarksNo high level activity detected in monitored regions
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x000000ae85eb00000xae85eb00000xae85ecffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000ae85ed00000xae85ed00000xae85edefffPagefile Backed FileReadableTrue
private_0x000000ae85ee00000xae85ee00000xae85f5ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007ff6ff7900000x7ff6ff7900000x7ff6ff7b2fffPagefile Backed FileReadableTrue
private_0x00007ff6ff7bd0000x7ff6ff7bd0000x7ff6ff7bdfffPrivate MemoryReadable, WritableTrue
private_0x00007ff6ff7be0000x7ff6ff7be0000x7ff6ff7bffffPrivate MemoryReadable, WritableTrue
smss.exe0x7ff6ff8f00000x7ff6ff914fffMemory Mapped FileReadable, Writable, ExecutableFalse
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Process #7: wininit.exe
(Host: 447, Network: 0)
+
InformationValue
ID / OS PID#7 / 0x164
OS Parent PID0x12c (\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\smss.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wininit.exe
Command Linewininit.exe
MonitorStart Time: 00:01:33, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:34
OS Thread IDs
#50
0x168
#59
0x18C
#62
0x19C
#65
0x1BC
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x0000005ebd1400000x5ebd1400000x5ebd15ffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000005ebd1400000x5ebd1400000x5ebd14ffffPagefile Backed FileReadable, WritableTrue
private_0x0000005ebd1500000x5ebd1500000x5ebd156fffPrivate MemoryReadable, WritableTrue
pagefile_0x0000005ebd1600000x5ebd1600000x5ebd16efffPagefile Backed FileReadableTrue
private_0x0000005ebd1700000x5ebd1700000x5ebd1effffPrivate MemoryReadable, WritableTrue
private_0x0000005ebd1f00000x5ebd1f00000x5ebd1f6fffPrivate MemoryReadable, WritableTrue
wininit.exe.mui0x5ebd2000000x5ebd201fffMemory Mapped FileReadableFalse
USER32.dll.mui0x5ebd2000000x5ebd204fffMemory Mapped FileReadableFalse
private_0x0000005ebd2100000x5ebd2100000x5ebd210fffPrivate MemoryReadable, WritableTrue
private_0x0000005ebd2200000x5ebd2200000x5ebd220fffPrivate MemoryReadable, WritableTrue
USER32.dll.mui0x5ebd2400000x5ebd244fffMemory Mapped FileReadableFalse
private_0x0000005ebd2600000x5ebd2600000x5ebd35ffffPrivate MemoryReadable, WritableTrue
locale.nls0x5ebd3600000x5ebd3ddfffMemory Mapped FileReadableFalse
private_0x0000005ebd3e00000x5ebd3e00000x5ebd45ffffPrivate MemoryReadable, WritableTrue
private_0x0000005ebd4600000x5ebd4600000x5ebd4dffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000005ebd4e00000x5ebd4e00000x5ebd50ffffPagefile Backed FileReadableTrue
private_0x0000005ebd5100000x5ebd5100000x5ebd51ffffPrivate MemoryReadable, WritableTrue
private_0x0000005ebd5600000x5ebd5600000x5ebd56ffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000005ebd5700000x5ebd5700000x5ebd6f7fffPagefile Backed FileReadableTrue
pagefile_0x0000005ebd7000000x5ebd7000000x5ebd880fffPagefile Backed FileReadableTrue
sortdefault.nls0x5ebd8900000x5ebdb64fffMemory Mapped FileReadableFalse
private_0x0000005ebdb700000x5ebdb700000x5ebdbeffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007df5ffd900000x7df5ffd900000x7ff5ffd8ffffPagefile Backed File-True
pagefile_0x00007df5ffd900000x7df5ffd900000x7ff5ffd8ffffPagefile Backed File-True
pagefile_0x00007ff73ef700000x7ff73ef700000x7ff73f06ffffPagefile Backed FileReadableTrue
pagefile_0x00007ff73f0700000x7ff73f0700000x7ff73f092fffPagefile Backed FileReadableTrue
private_0x00007ff73f0960000x7ff73f0960000x7ff73f097fffPrivate MemoryReadable, WritableTrue
private_0x00007ff73f0980000x7ff73f0980000x7ff73f099fffPrivate MemoryReadable, WritableTrue
private_0x00007ff73f09a0000x7ff73f09a0000x7ff73f09bfffPrivate MemoryReadable, WritableTrue
private_0x00007ff73f09c0000x7ff73f09c0000x7ff73f09dfffPrivate MemoryReadable, WritableTrue
private_0x00007ff73f09e0000x7ff73f09e0000x7ff73f09efffPrivate MemoryReadable, WritableTrue
wininit.exe0x7ff73f3b00000x7ff73f3d7fffMemory Mapped FileReadable, Writable, ExecutableFalse
KBDUS.DLL0x7ffb716900000x7ffb71693fffMemory Mapped FileReadable, Writable, ExecutableFalse
KBDUS.DLL0x7ffb716900000x7ffb71693fffMemory Mapped FileReadable, Writable, ExecutableFalse
wininitext.dll0x7ffb716a00000x7ffb716aafffMemory Mapped FileReadable, Writable, ExecutableFalse
profapi.dll0x7ffb716b00000x7ffb716c4fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
gdi32.dll0x7ffb71ad00000x7ffb71c20fffMemory Mapped FileReadable, Writable, ExecutableTrue
WS2_32.dll0x7ffb733600000x7ffb733b9fffMemory Mapped FileReadable, Writable, ExecutableTrue
sechost.dll0x7ffb733c00000x7ffb73418fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
advapi32.dll0x7ffb736900000x7ffb73739fffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
NSI.dll0x7ffb73e800000x7ffb73e88fffMemory Mapped FileReadable, Writable, ExecutableTrue
user32.dll0x7ffb73e900000x7ffb74006fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSVCRT.dll0x7ffb740500000x7ffb740f9fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Threads
Thread 0x168
(Host: 387, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
SYSGET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue2
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\VersionsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versions, value_name = 406899844400True1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wininit.exeTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = OOBEInProgressFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = SystemSetupInProgressTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = NV HostnameFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = NV DomainFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = RespecializeTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = SetupTypeTrue1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = DisableLockWorkstationFalse1
Fn
PROCOPEN_TOKENTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = ProfileImagePathTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = ProfileImagePathTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = PublicTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = PublicTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = ProgramDataTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = ProgramDataTrue1
Fn
FILECREATE_DIRFalse1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\temp, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
MODLOADmodule_name = rpcrt4.dll, base_address = 0x0True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = MaxRpcSizeFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = ComputerNameTrue1
Fn
SYSGET_INFOTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEvalue_name = IdleTimerWindowFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Error Message Instrument\False1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_InitializeTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize, value_name = DisableMetaFilesFalse1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEvalue_name = LoadAppInit_DLLsTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = RespecializeTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SetupTypeTrue1
Fn
REGOPEN_KEYreg_name = Keyboard Layout\PreloadTrue1
Fn
REGREAD_VALUEreg_name = Keyboard Layout\Preload, value_name = 1True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Keyboard Layouts\00000409True1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Keyboard Layouts\00000409, value_name = Layout FileTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Keyboard Layouts\00000409, value_name = AttributesFalse1
Fn
MODLOADmodule_name = KBDUS.DLL, base_address = 0x0True1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\kbdus.dll, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True6
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\segoeuib.ttf, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, open_options = FILE_SYNCHRONOUS_IO_NONALERTTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\segoeuib.ttf, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x5ebd890000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, base_address = 0x5ebd890000True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True3
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\segoeui.ttf, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, open_options = FILE_SYNCHRONOUS_IO_NONALERTTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\segoeui.ttf, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x5ebd890000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, base_address = 0x5ebd890000True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True5
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\tahoma.ttf, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, open_options = FILE_SYNCHRONOUS_IO_NONALERTTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\tahoma.ttf, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x5ebd890000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, base_address = 0x5ebd890000True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True10
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\micross.ttf, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, open_options = FILE_SYNCHRONOUS_IO_NONALERTTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\micross.ttf, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x5ebd890000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, base_address = 0x5ebd890000True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True61
Fn
REGOPEN_KEYreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR, value_name = DisableTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR\Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR\Control Panel\InternationalFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR\Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR\Control Panel\International, value_name = sCurrencyOverrideFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocaleTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocale, value_name = en-USFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocaleTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocale, value_name = en-USFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\LocaleTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Locale\Alternate SortsTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Language GroupsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Locale, value_name = 00000409True1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Language Groups, value_name = 1True1
Fn
SYSCREATE_DESKTOPTrue2
Fn
SYSSWITCH_DESKTOPTrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot KeysTrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000010True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000010, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000010, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000010, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000011True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000011, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000011, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000011, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000012True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000012, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000012, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000012, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000070True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000070, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000070, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000070, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000071True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000071, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000071, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000071, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000072True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000072, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000072, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000072, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000104True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000104, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000104, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000104, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000200True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000200, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000200, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000200, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000201True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000201, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000201, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000201, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000202True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000202, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000202, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000202, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000203True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000203, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000203, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000203, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\USER\S-1-5-18True1
Fn
REGOPEN_KEYreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\PreloadTrue1
Fn
REGREAD_VALUEreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\Preload, value_name = 1False1
Fn
REGREAD_VALUEreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\Preload, value_name = 1True1
Fn
REGOPEN_KEYreg_name = \REGISTRY\USER\S-1-5-18True1
Fn
REGOPEN_KEYreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\PreloadTrue1
Fn
REGREAD_VALUEreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\Preload, value_name = 2False1
Fn
REGOPEN_KEYreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\Preload\Keyboard Layout\PreloadTrue1
Fn
REGREAD_VALUEreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\Preload\Keyboard Layout\Preload, value_name = 1True1
Fn
REGOPEN_KEYreg_name = \REGISTRY\USER\S-1-5-18True1
Fn
REGOPEN_KEYreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\SubstitutesTrue1
Fn
REGREAD_VALUEreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\Substitutes, value_name = 00000409False1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Keyboard Layouts\00000409True1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Keyboard Layouts\00000409, value_name = Layout FileTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Keyboard Layouts\00000409, value_name = AttributesFalse1
Fn
MODLOADmodule_name = KBDUS.DLL, base_address = 0x0True1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\kbdus.dll, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot KeysTrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000010True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000010, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000010, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000010, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000011True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000011, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000011, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000011, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000012True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000012, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000012, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000012, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000070True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000070, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000070, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000070, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000071True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000071, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000071, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000071, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000072True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000072, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000072, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000072, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000104True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000104, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000104, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000104, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000200True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000200, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000200, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000200, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000201True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000201, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000201, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000201, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000202True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000202, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000202, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000202, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000203True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000203, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000203, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000203, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\USER\S-1-5-18True1
Fn
REGOPEN_KEYreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\PreloadTrue1
Fn
REGREAD_VALUEreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\Preload, value_name = 2False1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SecureBootFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\Preload, value_name = DisableShutdownNamedPipeFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versions, value_name = 000602xxTrue1
Fn
MODLOADmodule_name = kernel32.dll, base_address = 0x0True1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x5ebd890000True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\IdsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Ids, value_name = en-USFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Ids, value_name = enFalse1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True4
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = ProgramFilesDirTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = CommonFilesDirTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = ProgramFilesDir (x86)True1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = CommonFilesDir (x86)True1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = ProgramW6432DirTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = CommonW6432DirTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = DontWatchSysProcsFalse1
Fn
PROCCREATEprocess_name = True1
Fn
PROCCREATEprocess_name = , desired_access = MAXIMUM_ALLOWED, creation_flags = CREATE_IDLE_PRIORITY_CLASS, CREATE_NEW_PROCESS_GROUPTrue1
Fn
REGOPEN_KEYreg_name = \Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDllsFalse1
Fn
PROCGET_INFOprocess_name = True1
Fn
REGOPEN_KEYreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySideTrue1
Fn
REGREAD_VALUEreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide, value_name = PreferExternalManifestFalse1
Fn
THREADRESUMETrue1
Fn
REGOPEN_KEYFalse2
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ShutdownEventPendingFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ShutdownStateSnapshotFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RunasPPLFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RunasPPLTestFalse1
Fn
PROCCREATEprocess_name = True1
Fn
PROCCREATEprocess_name = , desired_access = MAXIMUM_ALLOWED, creation_flags = CREATE_NEW_PROCESS_GROUPTrue1
Fn
REGOPEN_KEYreg_name = \Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\OptionFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = 140717948767312False1
Fn
PROCGET_INFOprocess_name = True1
Fn
REGOPEN_KEYreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySideTrue1
Fn
REGREAD_VALUEreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide, value_name = PreferExternalManifestFalse1
Fn
MEMALLOCaddress = 0x5ebd1eeb78, process_name = , size = 406899846360, allocation_type = MEM_COMMIT, protection = PAGE_READWRITETrue1
Fn
MEMWRITEaddress = 0x6b29b00000, process_name = , size = 4704True1
Fn
Data
MEMWRITEaddress = 0x7ff676b272d8, process_name = , size = 8True1
Fn
Data
THREADRESUMETrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGOPEN_KEYFalse1
Fn
THREADCREATE_WORKITEMTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableRemoteShutdownRPCInterfaceFalse1
Fn
THREADCREATE_WORKITEMTrue1
Fn
Thread 0x18c
(Host: 8, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
DRVCONTROLreg_name = Control Panel\Input Method\Hot Keys, control_code = 0x110008False1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
SVCOPEN_MGRdatabase_name = SERVICES_ACTIVE_DATABASE, host = LocalhostTrue1
Fn
SVCOPENTrue1
Fn
SVCGET_INFOtype = StatusTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 406902403200 milliseconds (406902403.200 seconds)False1
Fn
Thread 0x19c
(Host: 49, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
SVCOPEN_MGRdatabase_name = SERVICES_ACTIVE_DATABASE, host = LocalhostTrue1
Fn
SVCOPENTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide, value_name = SQMServiceListTrue1
Fn
SVCGET_INFOtype = StatusTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 406902929056 milliseconds (406902929.056 seconds)False1
Fn
REGREAD_VALUEreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide, value_name = WinSock_Registry_VersionTrue2
Fn
REGREAD_VALUEvalue_name = AppFullPathTrue2
Fn
REGREAD_VALUEvalue_name = PermittedLspCategoriesTrue1
Fn
REGREAD_VALUEreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide, value_name = NameSpace_CalloutTrue2
Fn
REGREAD_VALUEvalue_name = Serial_Access_NumTrue2
Fn
REGREAD_VALUEvalue_name = Next_Catalog_Entry_IDTrue1
Fn
REGREAD_VALUEvalue_name = Num_Catalog_Entries64True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEvalue_name = Serial_Access_NumTrue2
Fn
REGREAD_VALUEvalue_name = Num_Catalog_Entries64True1
Fn
REGREAD_VALUEvalue_name = LibraryPathTrue2
Fn
REGREAD_VALUEvalue_name = DisplayStringTrue4
Fn
REGREAD_VALUEvalue_name = ProviderIdTrue1
Fn
REGREAD_VALUEvalue_name = AddressFamilyFalse1
Fn
REGREAD_VALUEvalue_name = SupportedNameSpaceTrue1
Fn
REGREAD_VALUEvalue_name = EnabledTrue1
Fn
REGREAD_VALUEvalue_name = VersionTrue1
Fn
REGREAD_VALUEvalue_name = StoresServiceClassInfoTrue1
Fn
REGREAD_VALUEvalue_name = ProviderInfoTrue2
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide, value_name = Ws2_32NumHandleBucketsFalse1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 406902929136 milliseconds (406902929.136 seconds)True1
Fn
SVCOPEN_MGRdatabase_name = SERVICES_ACTIVE_DATABASE, host = LocalhostTrue1
Fn
SVCOPENTrue1
Fn
SVCGET_INFOtype = StatusTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 406902929168 milliseconds (406902929.168 seconds)False1
Fn
Thread 0x1bc
(Host: 3, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = LoadAppInit_DLLsTrue1
Fn
Process #8: csrss.exe
(Host: 590, Network: 0)
+
InformationValue
ID / OS PID#8 / 0x16c
OS Parent PID0x15c (c:\windows\winstore\wshost.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe
Command Line%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
MonitorStart Time: 00:01:33, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:34
OS Thread IDs
#51
0x170
#52
0x174
#53
0x178
#54
0x17C
#55
0x180
#56
0x184
#81
0x1E8
#84
0x1F8
#85
0x1FC
#88
0x204
#113
0x268
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x000000d9c9ed00000xd9c9ed00000xd9c9eeffffPrivate MemoryReadable, WritableTrue
private_0x000000d9c9ed00000xd9c9ed00000xd9c9ed6fffPrivate MemoryReadable, WritableTrue
csrss.exe.mui0xd9c9ee00000xd9c9ee0fffMemory Mapped FileReadableFalse
pagefile_0x000000d9c9ef00000xd9c9ef00000xd9c9efefffPagefile Backed FileReadableTrue
private_0x000000d9c9f000000xd9c9f000000xd9c9f3ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000d9c9f000000xd9c9f000000xd9c9f0ffffPagefile Backed FileReadable, WritableTrue
MARLETT.TTF0xd9c9f100000xd9c9f16fffMemory Mapped FileReadableFalse
pagefile_0x000000d9c9f200000xd9c9f200000xd9c9f37fffPagefile Backed FileReadableTrue
locale.nls0xd9c9f400000xd9c9fbdfffMemory Mapped FileReadableFalse
winsrv.DLL.mui0xd9c9fc00000xd9c9fc1fffMemory Mapped FileReadableFalse
private_0x000000d9c9fd00000xd9c9fd00000xd9c9fd0fffPrivate MemoryReadable, WritableTrue
private_0x000000d9c9fe00000xd9c9fe00000xd9c9fe0fffPrivate MemoryReadable, WritableTrue
private_0x000000d9c9ff00000xd9c9ff00000xd9c9ff0fffPrivate MemoryReadable, WritableTrue
private_0x000000d9ca0000000xd9ca0000000xd9ca000fffPrivate MemoryReadable, WritableTrue
VGASYS.FON0xd9ca0100000xd9ca011fffMemory Mapped FileReadableFalse
private_0x000000d9ca0200000xd9ca0200000xd9ca05ffffPrivate MemoryReadable, WritableTrue
private_0x000000d9ca0600000xd9ca0600000xd9ca060fffPrivate MemoryReadable, WritableTrue
private_0x000000d9ca0700000xd9ca0700000xd9ca070fffPrivate MemoryReadable, WritableTrue
private_0x000000d9ca0800000xd9ca0800000xd9ca080fffPrivate MemoryReadable, WritableTrue
private_0x000000d9ca0900000xd9ca0900000xd9ca18ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000d9ca1900000xd9ca1900000xd9ca310fffPagefile Backed FileReadableTrue
pagefile_0x000000d9ca3200000xd9ca3200000xd9ca61ffffPagefile Backed FileReadable, WritableTrue
private_0x000000d9ca6200000xd9ca6200000xd9ca65ffffPrivate MemoryReadable, WritableTrue
private_0x000000d9ca6600000xd9ca6600000xd9ca69ffffPrivate MemoryReadable, WritableTrue
private_0x000000d9ca6a00000xd9ca6a00000xd9ca6dffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000d9ca6e00000xd9ca6e00000xd9ca867fffPagefile Backed FileReadableTrue
private_0x000000d9ca8700000xd9ca8700000xd9ca8affffPrivate MemoryReadable, WritableTrue
private_0x000000d9ca8b00000xd9ca8b00000xd9ca8effffPrivate MemoryReadable, WritableTrue
private_0x000000d9ca8f00000xd9ca8f00000xd9ca92ffffPrivate MemoryReadable, WritableTrue
TAHOMABD.TTF0xd9ca9300000xd9ca9d9fffMemory Mapped FileReadableFalse
TAHOMA.TTF0xd9ca9e00000xd9caa96fffMemory Mapped FileReadableFalse
pagefile_0x000000d9caaa00000xd9caaa00000xd9caacffffPagefile Backed FileReadableTrue
pagefile_0x000000d9caad00000xd9caad00000xd9cbecffffPagefile Backed FileReadableTrue
private_0x000000d9cbed00000xd9cbed00000xd9cbf0ffffPrivate MemoryReadable, WritableTrue
private_0x000000d9cbf100000xd9cbf100000xd9cbf4ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000d9cbf500000xd9cbf500000xd9cbf5ffffPagefile Backed FileReadable, WritableTrue
private_0x00007ff6196e80000x7ff6196e80000x7ff6196e9fffPrivate MemoryReadable, WritableTrue
private_0x00007ff6196ea0000x7ff6196ea0000x7ff6196ebfffPrivate MemoryReadable, WritableTrue
private_0x00007ff6196ec0000x7ff6196ec0000x7ff6196edfffPrivate MemoryReadable, WritableTrue
private_0x00007ff6196ee0000x7ff6196ee0000x7ff6196effffPrivate MemoryReadable, WritableTrue
pagefile_0x00007ff6196f00000x7ff6196f00000x7ff6197effffPagefile Backed FileReadable, WritableTrue
pagefile_0x00007ff6197f00000x7ff6197f00000x7ff619812fffPagefile Backed FileReadableTrue
private_0x00007ff6198140000x7ff6198140000x7ff619815fffPrivate MemoryReadable, WritableTrue
private_0x00007ff6198160000x7ff6198160000x7ff619817fffPrivate MemoryReadable, WritableTrue
private_0x00007ff6198180000x7ff6198180000x7ff619819fffPrivate MemoryReadable, WritableTrue
private_0x00007ff61981a0000x7ff61981a0000x7ff61981afffPrivate MemoryReadable, WritableTrue
private_0x00007ff61981c0000x7ff61981c0000x7ff61981dfffPrivate MemoryReadable, WritableTrue
private_0x00007ff61981e0000x7ff61981e0000x7ff61981ffffPrivate MemoryReadable, WritableTrue
private_0x00007ff61981e0000x7ff61981e0000x7ff61981ffffPrivate MemoryReadable, WritableTrue
csrss.exe0x7ff61a1000000x7ff61a106fffMemory Mapped FileReadable, Writable, ExecutableFalse
bcryptPrimitives.dll0x7ffb715800000x7ffb715e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTBASE.dll0x7ffb715f00000x7ffb715fafffMemory Mapped FileReadable, Writable, ExecutableFalse
sxs.dll0x7ffb716000000x7ffb71698fffMemory Mapped FileReadable, Writable, ExecutableFalse
sxssrv.DLL0x7ffb716d00000x7ffb716dcfffMemory Mapped FileReadable, Writable, ExecutableFalse
winsrv.DLL0x7ffb716e00000x7ffb71713fffMemory Mapped FileReadable, Writable, ExecutableFalse
basesrv.DLL0x7ffb717200000x7ffb71732fffMemory Mapped FileReadable, Writable, ExecutableFalse
CSRSRV.dll0x7ffb717400000x7ffb71755fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
gdi32.dll0x7ffb71ad00000x7ffb71c20fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
user32.dll0x7ffb73e900000x7ffb74006fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Threads
Thread 0x170
(Host: 17, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
SYSGET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue2
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Terminal ServerTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Terminal Server, value_name = TSAppCompatFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Terminal Server, value_name = TSUserEnabledFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
MODGET_HANDLEmodule_name = csrsrv.dllTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_InitializeTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize, value_name = DisableMetaFilesFalse1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True7
Fn
Thread 0x180
(Host: 136, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 935403837784True1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, size = 2True1
Fn
Data
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, size = 4095True1
Fn
Data
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, size = 8180False1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 935403837784True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, size = 2True1
Fn
Data
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, size = 4095True1
Fn
Data
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, size = 8180False1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, maximum_size = 935403842240, protection = PAGE_READWRITETrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x16c, address = 0xd9cbf60000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xd9cbf60000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x16cTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 935403838904True1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, size = 2True1
Fn
Data
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, size = 4095True1
Fn
Data
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, size = 8180False1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 935403838904True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, size = 2True1
Fn
Data
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, size = 4095True1
Fn
Data
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, size = 8180False1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, maximum_size = 935403843360, protection = PAGE_READWRITETrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x16c, address = 0xd9cbf80000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xd9cbf80000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x16cTrue1
Fn
Thread 0x1e8
(Host: 437, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 935406002472True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.systemcompatible_6595b64144ccf1df_6.0.9600.16384_none_69e3a25fa94e130a.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.systemcompatible_6595b64144ccf1df_6.0.9600.16384_none_69e3a25fa94e130a.manifest, size = 4095True1
Fn
Data
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.systemcompatible_6595b64144ccf1df_6.0.9600.16384_none_69e3a25fa94e130a.manifest, size = 8180False1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 935405999592True1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 935405999592True1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 935405999592True1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.isolationautomation_6595b64144ccf1df_1.0.0.0_none_ee2620cf57bc84de.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.isolationautomation_6595b64144ccf1df_1.0.0.0_none_ee2620cf57bc84de.manifest, size = 2True1
Fn
Data
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.isolationautomation_6595b64144ccf1df_1.0.0.0_none_ee2620cf57bc84de.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.isolationautomation_6595b64144ccf1df_1.0.0.0_none_ee2620cf57bc84de.manifest, size = 4095True1
Fn
Data
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x390008True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.isolationautomation_6595b64144ccf1df_1.0.0.0_none_ee2620cf57bc84de.manifest, size = 8180False1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 935405999592True1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.17415_none_932b3b5547500489.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.17415_none_932b3b5547500489.manifest, size = 2True1
Fn
Data
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.17415_none_932b3b5547500489.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.17415_none_932b3b5547500489.manifest, size = 4095True1
Fn
Data
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.17415_none_932b3b5547500489.manifest, size = 8180False1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52.manifest, size = 2True1
Fn
Data
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52.manifest, size = 4095True1
Fn
Data
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17415_none_34aa3313958e7a52.manifest, size = 8180False1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 935405999592True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_1.0.9600.17415_none_bd4349237a1100f7.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_1.0.9600.17415_none_bd4349237a1100f7.manifest, size = 2True1
Fn
Data
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_1.0.9600.17415_none_bd4349237a1100f7.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_1.0.9600.17415_none_bd4349237a1100f7.manifest, size = 4095True1
Fn
Data
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_1.0.9600.17415_none_bd4349237a1100f7.manifest, size = 8180False1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.9600.16384_en-us_4ab3da74c23648d7.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.9600.16384_en-us_4ab3da74c23648d7.manifest, size = 2True1
Fn
Data
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.9600.16384_en-us_4ab3da74c23648d7.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.9600.16384_en-us_4ab3da74c23648d7.manifest, size = 4095True1
Fn
Data
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.9600.16384_en-us_4ab3da74c23648d7.manifest, size = 8180False1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, maximum_size = 935406004048, protection = PAGE_READWRITETrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x16c, address = 0xd9cbf50000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xd9cbf50000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x16cTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 935406001256True1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, size = 2True1
Fn
Data
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, size = 4095True1
Fn
Data
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, size = 8180False1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 935406001256True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, size = 2True1
Fn
Data
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, size = 4095True1
Fn
Data
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, size = 8180False1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, maximum_size = 935406005712, protection = PAGE_READWRITETrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x16c, address = 0xd9cbf60000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xd9cbf60000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x16cTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = targetNamespaceTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = targetNamespaceTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = dpiAwareTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = dpiAwareTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 935406000136True1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, size = 2True1
Fn
Data
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, size = 4095True1
Fn
Data
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, size = 8180False1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 935406000136True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, size = 2True1
Fn
Data
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, size = 4095True1
Fn
Data
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, size = 8180False1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, maximum_size = 935406004592, protection = PAGE_READWRITETrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x16c, address = 0xd9cbf60000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xd9cbf60000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x16cTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = targetNamespaceTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = targetNamespaceTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = dpiAwareTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = dpiAwareTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 935406001256True1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, size = 2True1
Fn
Data
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, size = 4095True1
Fn
Data
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17415_none_6240486fecbd8abb.manifest, size = 8180False1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = 935406001256True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue2
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, size = 2True1
Fn
Data
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, size = 4095True1
Fn
Data
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\winsxs\manifests\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.9600.16384_en-us_7852a861195d56f0.manifest, size = 8180False1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, maximum_size = 935406005712, protection = PAGE_READWRITETrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x16c, address = 0xd9cbf90000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xd9cbf90000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x16cTrue1
Fn
Process #9: winlogon.exe
(Host: 604, Network: 0)
+
InformationValue
ID / OS PID#9 / 0x194
OS Parent PID0x15c (c:\windows\winstore\wshost.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe
Command Linewinlogon.exe
MonitorStart Time: 00:01:34, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:33
OS Thread IDs
#67
0x198
#82
0x1EC
#83
0x1F4
#114
0x270
#115
0x274
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x0000009f3e8a00000x9f3e8a00000x9f3e8bffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000009f3e8a00000x9f3e8a00000x9f3e8affffPagefile Backed FileReadable, WritableTrue
private_0x0000009f3e8b00000x9f3e8b00000x9f3e8b6fffPrivate MemoryReadable, WritableTrue
pagefile_0x0000009f3e8c00000x9f3e8c00000x9f3e8cefffPagefile Backed FileReadableTrue
private_0x0000009f3e8d00000x9f3e8d00000x9f3e94ffffPrivate MemoryReadable, WritableTrue
locale.nls0x9f3e9500000x9f3e9cdfffMemory Mapped FileReadableFalse
private_0x0000009f3e9d00000x9f3e9d00000x9f3e9d6fffPrivate MemoryReadable, WritableTrue
winlogon.exe.mui0x9f3e9e00000x9f3e9e5fffMemory Mapped FileReadableFalse
USER32.dll.mui0x9f3e9e00000x9f3e9e4fffMemory Mapped FileReadableFalse
private_0x0000009f3e9f00000x9f3e9f00000x9f3e9f0fffPrivate MemoryReadable, WritableTrue
private_0x0000009f3ea000000x9f3ea000000x9f3ea00fffPrivate MemoryReadable, WritableTrue
private_0x0000009f3ea100000x9f3ea100000x9f3ea16fffPrivate MemoryReadable, WritableTrue
USER32.dll.mui0x9f3ea200000x9f3ea24fffMemory Mapped FileReadableFalse
Aero.msstyles.mui0x9f3ea200000x9f3ea20fffMemory Mapped FileReadableFalse
private_0x0000009f3ea300000x9f3ea300000x9f3ea30fffPrivate MemoryReadable, WritableTrue
pagefile_0x0000009f3ea400000x9f3ea400000x9f3ea40fffPagefile Backed FileReadable, WritableTrue
private_0x0000009f3ea500000x9f3ea500000x9f3eb4ffffPrivate MemoryReadable, WritableTrue
private_0x0000009f3eb500000x9f3eb500000x9f3ebcffffPrivate MemoryReadable, WritableTrue
private_0x0000009f3ebd00000x9f3ebd00000x9f3ec4ffffPrivate MemoryReadable, WritableTrue
private_0x0000009f3ebd00000x9f3ebd00000x9f3ec4ffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000009f3ec500000x9f3ec500000x9f3ec7ffffPagefile Backed FileReadableTrue
private_0x0000009f3ec800000x9f3ec800000x9f3ec8ffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000009f3ec900000x9f3ec900000x9f3ee17fffPagefile Backed FileReadableTrue
pagefile_0x0000009f3ee200000x9f3ee200000x9f3efa0fffPagefile Backed FileReadableTrue
sortdefault.nls0x9f3efb00000x9f3f284fffMemory Mapped FileReadableFalse
private_0x0000009f3f3000000x9f3f3000000x9f3f30ffffPrivate MemoryReadable, WritableTrue
Aero.msstyles0x9f3f3100000x9f3f418fffMemory Mapped FileReadableFalse
private_0x0000009f3f3900000x9f3f3900000x9f3f40ffffPrivate MemoryReadable, WritableTrue
private_0x0000009f3f4200000x9f3f4200000x9f3fe1ffffPrivate MemoryReadable, WritableTrue
private_0x0000009f3fe200000x9f3fe200000x9f3ff1ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007df5ff3e00000x7df5ff3e00000x7ff5ff3dffffPagefile Backed File-True
pagefile_0x00007df5ff3e00000x7df5ff3e00000x7ff5ff3dffffPagefile Backed File-True
pagefile_0x00007ff7f65200000x7ff7f65200000x7ff7f661ffffPagefile Backed FileReadableTrue
pagefile_0x00007ff7f66200000x7ff7f66200000x7ff7f6642fffPagefile Backed FileReadableTrue
private_0x00007ff7f66440000x7ff7f66440000x7ff7f6645fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7f66480000x7ff7f66480000x7ff7f6649fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7f664a0000x7ff7f664a0000x7ff7f664bfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7f664c0000x7ff7f664c0000x7ff7f664cfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7f664c0000x7ff7f664c0000x7ff7f664cfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7f664e0000x7ff7f664e0000x7ff7f664ffffPrivate MemoryReadable, WritableTrue
winlogon.exe0x7ff7f6bc00000x7ff7f6c52fffMemory Mapped FileReadable, Writable, ExecutableFalse
WindowsCodecs.dll0x7ffb702d00000x7ffb7047dfffMemory Mapped FileReadable, Writable, ExecutableFalse
UxTheme.dll0x7ffb704800000x7ffb705a8fffMemory Mapped FileReadable, Writable, ExecutableFalse
uxinit.dll0x7ffb705e00000x7ffb705f6fffMemory Mapped FileReadable, Writable, ExecutableFalse
winsta.dll0x7ffb709400000x7ffb70999fffMemory Mapped FileReadable, Writable, ExecutableFalse
KBDUS.DLL0x7ffb709900000x7ffb70993fffMemory Mapped FileReadable, Writable, ExecutableFalse
KBDUS.DLL0x7ffb70a200000x7ffb70a23fffMemory Mapped FileReadable, Writable, ExecutableFalse
winlogonext.dll0x7ffb70a300000x7ffb70a48fffMemory Mapped FileReadable, Writable, ExecutableFalse
rsaenh.dll0x7ffb70b000000x7ffb70b35fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTSP.dll0x7ffb710400000x7ffb7105ffffMemory Mapped FileReadable, Writable, ExecutableFalse
bcrypt.dll0x7ffb712600000x7ffb71285fffMemory Mapped FileReadable, Writable, ExecutableFalse
powrprof.dll0x7ffb715300000x7ffb71575fffMemory Mapped FileReadable, Writable, ExecutableFalse
bcryptPrimitives.dll0x7ffb715800000x7ffb715e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTBASE.dll0x7ffb715f00000x7ffb715fafffMemory Mapped FileReadable, Writable, ExecutableFalse
profapi.dll0x7ffb716b00000x7ffb716c4fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
gdi32.dll0x7ffb71ad00000x7ffb71c20fffMemory Mapped FileReadable, Writable, ExecutableTrue
sechost.dll0x7ffb733c00000x7ffb73418fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
advapi32.dll0x7ffb736900000x7ffb73739fffMemory Mapped FileReadable, Writable, ExecutableTrue
combase.dll0x7ffb737400000x7ffb73950fffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSCTF.dll0x7ffb73b800000x7ffb73cd2fffMemory Mapped FileReadable, Writable, ExecutableTrue
user32.dll0x7ffb73e900000x7ffb74006fffMemory Mapped FileReadable, Writable, ExecutableTrue
IMM32.dll0x7ffb740100000x7ffb74045fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSVCRT.dll0x7ffb740500000x7ffb740f9fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Threads
Thread 0x198
(Host: 604, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
SYSGET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue2
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\VersionsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versions, value_name = 683949743520True1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exeTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
MODGET_HANDLEmodule_name = X:\windows\system32\IMM32.DLLFalse1
Fn
MODLOADmodule_name = X:\windows\system32\IMM32.DLL, base_address = 0x0True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
MODGET_HANDLEmodule_name = X:\windows\system32\IMM32.DLLTrue2
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Error Message Instrument\False1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_InitializeTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize, value_name = DisableMetaFilesFalse1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEvalue_name = LoadAppInit_DLLsTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = TracingControlLevelFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGCREATE_KEYreg_name = \REGISTRY\MACHINE\SOFTWARE\CLASSESTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SimulateDebugSessionFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = RespecializeTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SetupTypeTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = NoDebugThreadFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerNameTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = ComputerNameTrue1
Fn
REGCREATE_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
REGWRITE_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName, value_name = ComputerName, data = MINWINPCTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = OOBEInProgressFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = SystemSetupInProgressTrue1
Fn
PROCOPEN_TOKENTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = ProfileImagePathTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = ProfileImagePathTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = PublicTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = PublicTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = ProgramDataTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = ProgramDataTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = ProgramFilesDirTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = CommonFilesDirTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = ProgramFilesDir (x86)True1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = CommonFilesDir (x86)True1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = ProgramW6432DirTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = CommonW6432DirTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = AllowBlockingAppsAtShutdownFalse1
Fn
MODLOADmodule_name = rpcrt4.dll, base_address = 0x0True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = MaxRpcSizeFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = OOBEInProgressFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = SystemSetupInProgressTrue1
Fn
SYSGET_INFOTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEvalue_name = IdleTimerWindowFalse1
Fn
REGOPEN_KEYreg_name = Keyboard Layout\PreloadTrue1
Fn
REGREAD_VALUEreg_name = Keyboard Layout\Preload, value_name = 1True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Keyboard Layouts\00000409True1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Keyboard Layouts\00000409, value_name = Layout FileTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Keyboard Layouts\00000409, value_name = AttributesFalse1
Fn
MODLOADmodule_name = KBDUS.DLL, base_address = 0x0True1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\kbdus.dll, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True6
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\segoeuib.ttf, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, open_options = FILE_SYNCHRONOUS_IO_NONALERTTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\segoeuib.ttf, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x9f3efb0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, base_address = 0x9f3efb0000True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True3
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\segoeui.ttf, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, open_options = FILE_SYNCHRONOUS_IO_NONALERTTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\segoeui.ttf, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x9f3efb0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, base_address = 0x9f3efb0000True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True5
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\tahoma.ttf, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, open_options = FILE_SYNCHRONOUS_IO_NONALERTTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\tahoma.ttf, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x9f3efb0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, base_address = 0x9f3efb0000True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True10
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\micross.ttf, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, open_options = FILE_SYNCHRONOUS_IO_NONALERTTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\fonts\micross.ttf, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x9f3efb0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, base_address = 0x9f3efb0000True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True61
Fn
REGOPEN_KEYreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR, value_name = DisableTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR\Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR\Control Panel\InternationalFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR\Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR\Control Panel\International, value_name = sCurrencyOverrideFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocaleTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocale, value_name = en-USFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocaleTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocale, value_name = en-USFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\LocaleTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Locale\Alternate SortsTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Language GroupsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Locale, value_name = 00000409True1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Language Groups, value_name = 1True1
Fn
SYSCREATE_DESKTOPTrue2
Fn
SYSSWITCH_DESKTOPTrue1
Fn
MODGET_HANDLEmodule_name = IMM32.DLLTrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot KeysTrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000010True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000010, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000010, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000010, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000011True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000011, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000011, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000011, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000012True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000012, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000012, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000012, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000070True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000070, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000070, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000070, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000071True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000071, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000071, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000071, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000072True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000072, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000072, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000072, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000104True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000104, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000104, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000104, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000200True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000200, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000200, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000200, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000201True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000201, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000201, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000201, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000202True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000202, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000202, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000202, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000203True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000203, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000203, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000203, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\USER\S-1-5-18True1
Fn
REGOPEN_KEYreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\PreloadTrue1
Fn
REGREAD_VALUEreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\Preload, value_name = 1False1
Fn
REGREAD_VALUEreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\Preload, value_name = 1True1
Fn
REGOPEN_KEYreg_name = \REGISTRY\USER\S-1-5-18True1
Fn
REGOPEN_KEYreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\PreloadTrue1
Fn
REGREAD_VALUEreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\Preload, value_name = 2False1
Fn
REGOPEN_KEYreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\Preload\Keyboard Layout\PreloadTrue1
Fn
REGREAD_VALUEreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\Preload\Keyboard Layout\Preload, value_name = 1True1
Fn
REGOPEN_KEYreg_name = \REGISTRY\USER\S-1-5-18True1
Fn
REGOPEN_KEYreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\SubstitutesTrue1
Fn
REGREAD_VALUEreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\Substitutes, value_name = 00000409False1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Keyboard Layouts\00000409True1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Keyboard Layouts\00000409, value_name = Layout FileTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Keyboard Layouts\00000409, value_name = AttributesFalse1
Fn
MODLOADmodule_name = KBDUS.DLL, base_address = 0x0True1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\kbdus.dll, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot KeysTrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000010True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000010, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000010, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000010, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000011True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000011, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000011, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000011, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000012True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000012, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000012, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000012, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000070True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000070, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000070, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000070, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000071True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000071, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000071, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000071, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000072True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000072, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000072, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000072, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000104True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000104, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000104, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000104, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000200True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000200, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000200, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000200, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000201True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000201, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000201, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000201, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000202True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000202, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000202, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000202, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\Input Method\Hot Keys\00000203True1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000203, value_name = Virtual KeyTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000203, value_name = Key ModifiersTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys\00000203, value_name = Target IMETrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\USER\S-1-5-18True1
Fn
REGOPEN_KEYreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\PreloadTrue1
Fn
REGREAD_VALUEreg_name = \REGISTRY\USER\S-1-5-18\Keyboard Layout\Preload, value_name = 2False1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Control Panel\Input Method\Hot Keys, value_name = SecureBootTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe, os_pid = 0x194, address = 0x9f3ea10000True1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x9f3ea10000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe, os_pid = 0x194True1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USERFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManagerTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = LMVersionTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = LMVersionFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGDELETE_VALUEFalse1
Fn
REGDELETE_VALUEvalue_name = InstallThemeFalse1
Fn
REGDELETE_VALUEFalse1
Fn
REGDELETE_VALUEvalue_name = SetVisualStyleFalse1
Fn
REGDELETE_VALUEFalse1
Fn
REGDELETE_VALUEvalue_name = InstallVisualStyleFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = LMVersion, data = 105True1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = LMOverRideTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versions, value_name = 000602xxTrue1
Fn
MODLOADmodule_name = kernel32.dll, base_address = 0x0True1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x9f3efb0000True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\IdsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Ids, value_name = en-USFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Ids, value_name = enFalse1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = DllName, data = %SystemRoot%\resources\themes\Aero\Aero.msstylesTrue1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = LMVersion, data = 105True1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = ThemeActive, data = 1True1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = LoadedBefore, data = 0True1
Fn
REGDELETE_VALUEFalse1
Fn
REGDELETE_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = ColorNameFalse1
Fn
REGDELETE_VALUEFalse1
Fn
REGDELETE_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = SizeNameFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = LoadedBeforeTrue1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = LoadedBefore, data = 0True1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEvalue_name = LoadedBefore, data = 1True1
Fn
SVCOPEN_MGRdatabase_name = SERVICES_ACTIVE_DATABASE, host = LocalhostTrue1
Fn
SVCOPENFalse1
Fn
SVCOPEN_MGRdatabase_name = SERVICES_ACTIVE_DATABASE, host = LocalhostTrue1
Fn
SVCOPENFalse1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USERFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManagerTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = LMVersionTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = LMVersionTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = LoadedBeforeTrue1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USERFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = DllNameTrue1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USERFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = ColorNameFalse1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USERFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = SizeNameFalse1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USERFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = LoadedBeforeTrue1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USERFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = LastUserLangIDFalse1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USERFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = LastLoadedDPIFalse1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USERFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = LastLoadedPPIFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = LMVersionTrue1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USERFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = LMVersionTrue1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exeTrue1
Fn
MODGET_HANDLEmodule_name = user32.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb73e94c30True1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe, os_pid = 0x194, address = 0x9f3ea10000True1
Fn
MODMAPreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x9f3ea10000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe, os_pid = 0x194True1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = PageAllocatorUseSystemHeapFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = PageAllocatorSystemHeapIsPrivateFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\ThemeManager, value_name = AggressiveMTATestingFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODGET_HANDLEmodule_name = rpcrt4.dllTrue1
Fn
FILECREATEFalse1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\vscache\aero.msstyles_1033_96.mss, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\aero.msstyles, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODLOADbase_address = 0x9f3f310001True1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\aero.msstyles, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\aero.msstyles, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x9f3f310000True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\aero.msstyles, value_name = NameTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\aero.msstyles, value_name = NameTrue2
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\aero.msstyles, value_name = TypeTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\aero.msstyles, value_name = Image PathTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\aero.msstyles, value_name = Image PathTrue2
Fn
MODLOADbase_address = 0x7ffb70b00000True1
Fn
MODLOADmodule_name = X:\windows\system32\rsaenh.dll, base_address = 0x0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b01570True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b01080True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b06090True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b1e1d0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b02ce0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b0af70True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b03880True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b03a30True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b03260True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b06be0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b04ea0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b027d0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b02b00True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b1d8d0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b024f0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b06830True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b03c50True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b01030True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b05bb0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b0f290True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b0f750True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b03f50True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b02630True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b0d330True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b1d6e0True1
Fn
REGOPEN_KEYFalse1
Fn
PROCOPEN_TOKENTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MachineGuidTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MachineGuidTrue2
Fn
REGOPEN_KEYFalse1
Fn
PROCOPEN_TOKENTrue1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x390008True1
Fn
MODLOADbase_address = 0x7ffb71580000True1
Fn
MODLOADmodule_name = X:\windows\system32\bcryptprimitives.dll, base_address = 0x0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb715848b0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb7159b3d0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\aero.msstyles, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe, os_pid = 0x194, address = 0x9f3f420000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x9f3f420000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe, os_pid = 0x194True1
Fn
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\aero.msstyles, size = 16True1
Fn
Data
FILEREADTrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\aero.msstyles, size = 128True1
Fn
Data
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\resources\themes\aero\aero.msstyles, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, base_address = 0x9f3f310000True1
Fn
THREADCREATEprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, proc_address = 0x7ff7f6bcf270, desired_access = THREAD_ALL_ACCESSTrue1
Fn
MODLOADbase_address = 0x0False1
Fn
MODLOADmodule_name = oobe\WinLGDep.dll, base_address = 0xc0000135False1
Fn
SYSSWITCH_DESKTOPTrue1
Fn
REGOPEN_KEYTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True4
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ProgramFilesDirTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = CommonFilesDirTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ProgramFilesDir (x86)True1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = CommonFilesDir (x86)True1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ProgramW6432DirTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = CommonW6432DirTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = UserinitTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = userinitTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = UserinitTrue1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEvalue_name = Userinit, data = True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = UserinitTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = UserinitTrue1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEvalue_name = Userinit, data = X:\windows\system32\userinit.exe,True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SystemFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = CmdlineTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEvalue_name = SetupType, data = 0True1
Fn
REGOPEN_KEYTrue1
Fn
REGDELETE_VALUEFalse1
Fn
REGDELETE_VALUEvalue_name = AutoAdminLogonFalse1
Fn
KEYBOARDREADresult_out = 0True2
Fn
PROCOPEN_TOKENTrue1
Fn
PROCCREATEprocess_name = True1
Fn
PROCCREATEprocess_name = , desired_access = MAXIMUM_ALLOWED, creation_flags = CREATE_NEW_PROCESS_GROUPTrue1
Fn
REGOPEN_KEYreg_name = \Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDllsFalse1
Fn
REGOPEN_KEYreg_name = \Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\OptionFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = 140717948767312False1
Fn
PROCGET_INFOprocess_name = True1
Fn
REGOPEN_KEYreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySideTrue1
Fn
REGREAD_VALUEreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide, value_name = PreferExternalManifestFalse1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x9f3f410000False1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, base_address = 0x9f3f410000True1
Fn
MEMALLOCaddress = 0x9f3e94dc78, process_name = , size = 683949743576, allocation_type = MEM_COMMIT, protection = PAGE_READWRITETrue1
Fn
MEMWRITEaddress = 0xa3b7d40000, process_name = , size = 4704True1
Fn
Data
MEMWRITEaddress = 0x7ff74d8ca2d8, process_name = , size = 8True1
Fn
Data
THREADRESUMETrue1
Fn
Process #10: services.exe
(Host: 10677, Network: 0)
+
InformationValue
ID / OS PID#10 / 0x1ac
OS Parent PID0x164 (c:\windows\system32\csrss.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe
Command LineX:\windows\system32\services.exe -setup
MonitorStart Time: 00:01:35, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:32
OS Thread IDs
#68
0x1B0
#90
0x208
#91
0x20C
#97
0x224
#111
0x260
#134
0x2D4
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x00000094cfe900000x94cfe900000x94cfeaffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000094cfe900000x94cfe900000x94cfe9ffffPagefile Backed FileReadable, WritableTrue
private_0x00000094cfea00000x94cfea00000x94cfea6fffPrivate MemoryReadable, WritableTrue
pagefile_0x00000094cfeb00000x94cfeb00000x94cfebefffPagefile Backed FileReadableTrue
private_0x00000094cfec00000x94cfec00000x94cff3ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000094cff400000x94cff400000x94cff43fffPagefile Backed FileReadableTrue
pagefile_0x00000094cff500000x94cff500000x94cff50fffPagefile Backed FileReadableTrue
locale.nls0x94cff600000x94cffddfffMemory Mapped FileReadableFalse
private_0x00000094cffe00000x94cffe00000x94cffe6fffPrivate MemoryReadable, WritableTrue
pagefile_0x00000094cfff00000x94cfff00000x94cfff2fffPagefile Backed FileReadable, WritableTrue
services.exe.mui0x94d00000000x94d0004fffMemory Mapped FileReadableFalse
private_0x00000094d00400000x94d00400000x94d004ffffPrivate MemoryReadable, WritableTrue
private_0x00000094d00c00000x94d00c00000x94d01bffffPrivate MemoryReadable, WritableTrue
sortdefault.nls0x94d01c00000x94d0494fffMemory Mapped FileReadableFalse
private_0x00000094d04a00000x94d04a00000x94d059ffffPrivate MemoryReadable, WritableTrue
private_0x00000094d05a00000x94d05a00000x94d079ffffPrivate MemoryReadable, WritableTrue
private_0x00000094d07a00000x94d07a00000x94d081ffffPrivate MemoryReadable, WritableTrue
private_0x00000094d08200000x94d08200000x94d089ffffPrivate MemoryReadable, WritableTrue
private_0x00000094d08a00000x94d08a00000x94d091ffffPrivate MemoryReadable, WritableTrue
private_0x00000094d09200000x94d09200000x94d099ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007df5fff400000x7df5fff400000x7ff5fff3ffffPagefile Backed File-True
pagefile_0x00007df5fff400000x7df5fff400000x7ff5fff3ffffPagefile Backed File-True
pagefile_0x00007df5fff400000x7df5fff400000x7ff5fff3ffffPagefile Backed File-True
pagefile_0x00007ff6727700000x7ff6727700000x7ff67286ffffPagefile Backed FileReadableTrue
pagefile_0x00007ff6728700000x7ff6728700000x7ff672892fffPagefile Backed FileReadableTrue
private_0x00007ff6728930000x7ff6728930000x7ff672893fffPrivate MemoryReadable, WritableTrue
private_0x00007ff6728960000x7ff6728960000x7ff672897fffPrivate MemoryReadable, WritableTrue
private_0x00007ff6728980000x7ff6728980000x7ff672899fffPrivate MemoryReadable, WritableTrue
private_0x00007ff67289a0000x7ff67289a0000x7ff67289bfffPrivate MemoryReadable, WritableTrue
private_0x00007ff67289c0000x7ff67289c0000x7ff67289dfffPrivate MemoryReadable, WritableTrue
private_0x00007ff67289e0000x7ff67289e0000x7ff67289ffffPrivate MemoryReadable, WritableTrue
services.exe0x7ff6730600000x7ff6730c5fffMemory Mapped FileReadable, Writable, ExecutableFalse
AUTHZ.dll0x7ffb708600000x7ffb708a7fffMemory Mapped FileReadable, Writable, ExecutableFalse
scesrv.dll0x7ffb708b00000x7ffb70939fffMemory Mapped FileReadable, Writable, ExecutableFalse
spinf.dll0x7ffb709a00000x7ffb709bdfffMemory Mapped FileReadable, Writable, ExecutableFalse
srvcli.dll0x7ffb709c00000x7ffb709e5fffMemory Mapped FileReadable, Writable, ExecutableFalse
EventAggregation.dll0x7ffb709f00000x7ffb709fafffMemory Mapped FileReadable, Writable, ExecutableFalse
DABAPI.dll0x7ffb70a000000x7ffb70a07fffMemory Mapped FileReadable, Writable, ExecutableFalse
scext.dll0x7ffb70a100000x7ffb70a20fffMemory Mapped FileReadable, Writable, ExecutableFalse
SspiCli.dll0x7ffb715000000x7ffb7152dfffMemory Mapped FileReadable, Writable, ExecutableFalse
bcryptPrimitives.dll0x7ffb715800000x7ffb715e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTBASE.dll0x7ffb715f00000x7ffb715fafffMemory Mapped FileReadable, Writable, ExecutableFalse
profapi.dll0x7ffb716b00000x7ffb716c4fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
sechost.dll0x7ffb733c00000x7ffb73418fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSVCRT.dll0x7ffb740500000x7ffb740f9fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Injection Information
+
Injection TypeSource ProcessSource Os Thread IDInjection InfoSuccessAmountLogfile
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188address = 0x4584630000, size = 16384True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188address = 0x4584630000, size = 4096True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188No corresponding api call detected. Probably injected code via shellcode.True1
Created or Modified Files
+
FilenameFile SizeHash Values
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbxhci.pnf 11.26 KB (11528 bytes)MD5: 72a7d52c829219fe574e86638fb6a23b
SHA1: e59da7ae2aab26f70663f39adf91efcb191aad2c
SHA256: ffff12546c87da3388192d28602e3fdaa9a1aaf30d43335b17e5af27867b97ce
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hdaudbus.pnf 9.04 KB (9256 bytes)MD5: cae8133113b0fa8eb45181f9c5d6dbdb
SHA1: ec18aa17bdc203b0d550c8fd8c6300b3df857b6f
SHA256: 76ab1f207f5c4c1bbac23e93fac1526804230fb8b3b2bb5c2d67396d8088111d
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat 256.00 KB (262144 bytes)MD5: 2aa9bd6793f83cef98d5d7fd60ab405b
SHA1: 21c2f6d19d1b0bacbc3f77e3d65e268de288a4e4
SHA256: 5c082b5c231e8b2543ae6add7a80da48de09b3a17f67e79bdd465be59b3a3d84
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat 256.00 KB (262144 bytes)MD5: 2aa9bd6793f83cef98d5d7fd60ab405b
SHA1: 21c2f6d19d1b0bacbc3f77e3d65e268de288a4e4
SHA256: 5c082b5c231e8b2543ae6add7a80da48de09b3a17f67e79bdd465be59b3a3d84
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msmouse.pnf 90.35 KB (92520 bytes)MD5: 348c682409045af377e6a1dca770dc90
SHA1: 2bae29b156217f52678974af1c94aca774a28736
SHA256: 7f4f7089b57310b37eab34376b7dfc2950630a7f1b4aeec32fe397b543142d2c
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\errdev.pnf 8.43 KB (8628 bytes)MD5: 913f6bc3d9c97be46972c278ba84e164
SHA1: 7a40bf25292697394f6a5e3fe0e27e1b31da778c
SHA256: 3bcfc47aa85bda59cebebb0f950d97a3f3c6fd5fb144c4a90e4514416d69a9cb
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cdrom.pnf 13.08 KB (13396 bytes)MD5: ea8c9d9fd77d6fa9d3fe8cadf4b15d99
SHA1: a3318b388daf7c943d3d3f0dab70187fa450568e
SHA256: 060a3c11e01858498e7867135d78acb5126cad3167590a5dbe8d08e063e47bf0
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000001.regtrans-ms 512.00 KB (524288 bytes)MD5: 61bb82ecefdac3b60b11441cc6c780b0
SHA1: da763f11762558805d9b32096c8e47bd03132b5e
SHA256: ca0e01a9ed63401c0d0458a315adbc586e19d7638272aafb5ecadd4817efc5c7
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000001.regtrans-ms 512.00 KB (524288 bytes)MD5: 61bb82ecefdac3b60b11441cc6c780b0
SHA1: da763f11762558805d9b32096c8e47bd03132b5e
SHA256: ca0e01a9ed63401c0d0458a315adbc586e19d7638272aafb5ecadd4817efc5c7
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\qlfcoei.pnf 10.95 KB (11216 bytes)MD5: 62816a91b4b87f7dc7f57f2503502325
SHA1: bd3fdee1b75f0674723f66cee4f0b2ea0bd33ce4
SHA256: cc07c110eaf6a978c3a67642c58f5230d1188cab4766578e68e604dc1ea9f275
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cht4vx64.pnf 25.11 KB (25708 bytes)MD5: 60222a0f4c6c8de63f3d768f74aa73e4
SHA1: 2061d813df910a2fbd525928eaf0eead093ee607
SHA256: 1e04432c12cfcf7ac033fb0ebf1267e23a48686942b8b10ea29fc3391c8b3fac
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxois.pnf 17.07 KB (17480 bytes)MD5: b8cf94487fa53de1e07885eb5a03b13c
SHA1: a29d0433472bea0bd0245674bfad3d0d6d5a42e0
SHA256: cec39cf75e876d284ce5eb58df6e5eb9844c7b841b550606fe9e7959ffcf7662
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\agp.pnf 15.05 KB (15408 bytes)MD5: b91108bbe0218f1c933f540dcfcd4559
SHA1: bfa39b3a402fd707f07ecb2ce223fc35ed86bc97
SHA256: dad053eab78fd20eb15e06525b54349c9bdf0a0988d023132faaf3cdfa64a16f
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usb.pnf 71.04 KB (72748 bytes)MD5: 0ea6f3c600dd9b540faf720d418be41d
SHA1: d639d62e21e966c50d4fb5b434d68c0fcd950e90
SHA256: 31ac1218f82d67a4ff37423ed037776fd9fef2d5ff5b12040696fc2d812f61a8
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programs\system tools\command prompt.lnk 1.12 KB (1142 bytes)MD5: 9c82e435db86860edb5ced5f369bdfb3
SHA1: a63c6007e8679aac89632ff7ac88b29df4a11b9e
SHA256: 23db6dd5bb4644850d5afe83f1126d582238162ab480479fb12a6b9998a82511
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programs\system tools\command prompt.lnk 1.12 KB (1142 bytes)MD5: 9c82e435db86860edb5ced5f369bdfb3
SHA1: a63c6007e8679aac89632ff7ac88b29df4a11b9e
SHA256: 23db6dd5bb4644850d5afe83f1126d582238162ab480479fb12a6b9998a82511
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mssmbios.pnf 7.59 KB (7768 bytes)MD5: 47bc949bb6ff56c1cd36c2c0350bc4c6
SHA1: 4610333269123f7eeb62a9995ea8511c2cd3bfa6
SHA256: 4156895c97ab1ebd9f9ca34944eace2f79909ba88929c42e29ee61ca4aa358e9
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tm.blf 64.00 KB (65536 bytes)MD5: f05bb5e3d62100de94995032e40318cd
SHA1: 316e1aa45ca7d1026ce8243c34ee9adb32939923
SHA256: 29ca52555753d55ac9d1940ad746ad540d6beaac8209fddadfb7d74f37ec3e90
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tm.blf 64.00 KB (65536 bytes)MD5: f05bb5e3d62100de94995032e40318cd
SHA1: 316e1aa45ca7d1026ce8243c34ee9adb32939923
SHA256: 29ca52555753d55ac9d1940ad746ad540d6beaac8209fddadfb7d74f37ec3e90
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tm.blf 64.00 KB (65536 bytes)MD5: 287d4d682e1c88640cbeebe11fac2f85
SHA1: d5a3b04c46d5ff20170d8c63ca6996b575100475
SHA256: 22db3ce0e70a6b5975906794e5c2c3459d7f7353890638e4c25598d02fe5b824
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tm.blf 64.00 KB (65536 bytes)MD5: 287d4d682e1c88640cbeebe11fac2f85
SHA1: d5a3b04c46d5ff20170d8c63ca6996b575100475
SHA256: 22db3ce0e70a6b5975906794e5c2c3459d7f7353890638e4c25598d02fe5b824
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf 59.45 KB (60880 bytes)MD5: a2a4e415e53c25caa790c4178227df85
SHA1: d7a41ad4470f3f6794428ed87e2361f013c479e9
SHA256: a87689bf630dfe0a52fdbedc428242cf97c8c0c620a7cd8361670dc8417def9b
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorav.pnf 11.79 KB (12068 bytes)MD5: 105c62370e5c9f9126893cb464701bb9
SHA1: 53126901723d0bd87095a00c3b8212ef3908d1d9
SHA256: 4d20985fc88f173cdba2e141a2041ca535cd19469200ffa52cceaa03fe5678aa
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf 6.66 KB (6820 bytes)MD5: 4a6bf9c2a829cf4d1b96a66e42e88632
SHA1: cb1fe3699f00a3b27280432283006797177ed9be
SHA256: 369d0b0a8076207617c5fb414e434f98281b41a597d8bda7ae1781b2c7e7ebe8
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iscsi.pnf 10.80 KB (11056 bytes)MD5: aff57dbe66f472508a675099d19ea93f
SHA1: b941f03eeb507efee9bd9d076a5ad7b1995cd203
SHA256: 09a00b446c358f759e70ed188f0cc0755405cf2449cb09f7d2983e58c63bb155
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\stornvme.pnf 10.67 KB (10928 bytes)MD5: 9f32d460d749e4622855bb0a37d4383a
SHA1: c9289529f91964d50b01d1d8cd55eebbbd0d6bb3
SHA256: e419cb3d2e6cdf80af892e376cb7621f59fcfe556b8b083b2d7d78984f265b27
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mlx4_bus.pnf 42.48 KB (43500 bytes)MD5: 944671ca7c6b2f500b8d22be8bb3d3b4
SHA1: c4682261d5ccee536d15761b9e1a9e0d73af2d7c
SHA256: 6c77e42da8c288ffe671b5bbd89e86ab559d48e3d6d9d0e3696cc7c7e77d6484
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf 6.85 KB (7012 bytes)MD5: 395fac9d715c0fcdb4bd67f5f35b8139
SHA1: ea1935ec1ef0cc542b431b224d588f57af303c3f
SHA256: 088f67825e30087fb14c060945c700cd444c6c2d03c35e7da253a48f0c9dd99c
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hiddigi.pnf 8.23 KB (8424 bytes)MD5: d13ec5c97793dd65f4f736c218c96978
SHA1: 14089394e9628bb62e5561f343a5fae7f8d76711
SHA256: dbe5d2cadb841aee93e69ef91674e64445e72ededdc5e8026ce03a6814a7b625
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\wmiacpi.pnf 8.42 KB (8620 bytes)MD5: 77604f04a353eb260633e7bbe855f674
SHA1: 540d62060faade559c4a4d52880855e5ce7f1992
SHA256: e70208995a288adda18e57b38c17c77d707e7486b172056cc53f75d27ab9ff8d
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf 7.26 KB (7436 bytes)MD5: a5b48c42f2e98e2607edf30231cb6023
SHA1: 3fba6e9464fdc544351d9ffb694767d945be7a60
SHA256: eb2ad0f6616dd07e96f7665cf2b86c88063f749efc81ae182bdf86e5c224c43c
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat.log1 40.00 KB (40960 bytes)MD5: 639b969e8dd1c282e9825028177b18ff
SHA1: b550008e1b974ee1d7a7d2ba7b1ed5554a2b7275
SHA256: 032103171a4ce9388e2791d63055101b2034c7440be8a5e1849049ba906dbaf5
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat.log1 40.00 KB (40960 bytes)MD5: 639b969e8dd1c282e9825028177b18ff
SHA1: b550008e1b974ee1d7a7d2ba7b1ed5554a2b7275
SHA256: 032103171a4ce9388e2791d63055101b2034c7440be8a5e1849049ba906dbaf5
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uaspstor.pnf 8.01 KB (8204 bytes)MD5: 8cb26037632d2b7ff36c9ac526ebff16
SHA1: c1f3b2c9d7ecf4f6fef1481f85fb29d50a67341a
SHA256: 056e165a7a876d15a6a5bc5538e6f418185ca1a7e017414f8ebef90ae7c31cb3
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_i2c.pnf 8.52 KB (8720 bytes)MD5: 8ba2ca105e90b447660af73f12d6fda5
SHA1: 56e7d2985a9c71e3c9bbeb3b46583fb3a870a1ec
SHA256: 30373ae81ecc7e3425036718fbb9aaa5b5184fcdf8e10f9e0c98a21057384bc4
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\keyboard.pnf 119.92 KB (122800 bytes)MD5: 6c6312b24a1d82a99745754ad75a7407
SHA1: a264405060499c7a6093e02371aef6cf5809811c
SHA256: 32afc799fbc8f4351cedc36783bd1c107e084037de1babec75928d541be3376b
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sbp2.pnf 7.39 KB (7572 bytes)MD5: e8fb4e90af26ce8b6f6ab0feadeb89eb
SHA1: 1d012a60cd34f2519d9c1b59d04d90be527c7d62
SHA256: 3f0c39717c726f19a063b131ca629d35d7aa7a97f0b17e3fc91e4242ef75b031
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000002.regtrans-ms 512.00 KB (524288 bytes)MD5: 59071590099d21dd439896592338bf95
SHA1: 6a521e1d2a632c26e53b83d2cc4b0edecfc1e68c
SHA256: 07854d2fef297a06ba81685e660c332de36d5d18d546927d30daad6d7fda1541
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000002.regtrans-ms 512.00 KB (524288 bytes)MD5: 59071590099d21dd439896592338bf95
SHA1: 6a521e1d2a632c26e53b83d2cc4b0edecfc1e68c
SHA256: 07854d2fef297a06ba81685e660c332de36d5d18d546927d30daad6d7fda1541
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{2df2d1e8-0b32-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000002.regtrans-ms 512.00 KB (524288 bytes)MD5: 59071590099d21dd439896592338bf95
SHA1: 6a521e1d2a632c26e53b83d2cc4b0edecfc1e68c
SHA256: 07854d2fef297a06ba81685e660c332de36d5d18d546927d30daad6d7fda1541
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000002.regtrans-ms 512.00 KB (524288 bytes)MD5: 59071590099d21dd439896592338bf95
SHA1: 6a521e1d2a632c26e53b83d2cc4b0edecfc1e68c
SHA256: 07854d2fef297a06ba81685e660c332de36d5d18d546927d30daad6d7fda1541
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programs\accessories\desktop.ini 0.08 KB (79 bytes)MD5: 52b31354ef1082f6a5a2490dc80aabcd
SHA1: 571db4c0054bed9444336667556d81edbf3a9af8
SHA256: ede4a40a65f7e13e841d682880af3f1ca9263b4a25ba3f838aac7432092715a8
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programs\accessories\desktop.ini 0.08 KB (79 bytes)MD5: 52b31354ef1082f6a5a2490dc80aabcd
SHA1: 571db4c0054bed9444336667556d81edbf3a9af8
SHA256: ede4a40a65f7e13e841d682880af3f1ca9263b4a25ba3f838aac7432092715a8
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidbatt.pnf 7.17 KB (7344 bytes)MD5: 1500cba16750cb4d2fa78cb6e00d1008
SHA1: dd65f8795cc656196169b2a43e77a5f4c387c1d0
SHA256: 0e5e82ddc46e5a338a9e9cb575030db90d08e521ba2e58cf362389a6ed8d0587
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\uefi.pnf 8.15 KB (8348 bytes)MD5: 3432928245eac49ed9a6036c1c71bb5c
SHA1: 281065c2954be6e68b8d53e389ebb729adaed868
SHA256: bf633c814b1f3ffc8ea2fbe0974a16d98825ab9d2c50889c7f4ff4e00c8e229f
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\vdrvroot.pnf 7.38 KB (7556 bytes)MD5: ca21e9ffd1c74354929e5c27f05a0c18
SHA1: 056ae20a7f3513137c1bc4c9c8901f1ea97dc5b2
SHA256: 99e4316f2ef81afbf4a7d61ee485d19c230edd50af63177fd113181b28a8c013
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programs\accessories\notepad.lnk 1.13 KB (1158 bytes)MD5: ee27db3652032a3498c54a12407b0cb5
SHA1: c4d29c8a67c81c1ada0323ac7c857b113cf5271b
SHA256: 5e7a26e2d64f644e159a6bd5bceb5736c5c71fefe3d648425338b22dc840cbc2
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programs\accessories\notepad.lnk 1.13 KB (1158 bytes)MD5: ee27db3652032a3498c54a12407b0cb5
SHA1: c4d29c8a67c81c1ada0323ac7c857b113cf5271b
SHA256: 5e7a26e2d64f644e159a6bd5bceb5736c5c71fefe3d648425338b22dc840cbc2
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\start menu\programs\system tools\desktop.ini 0.08 KB (86 bytes)MD5: 68fa444f95dda594dac226f7f13d7e95
SHA1: bc136a7b4bcb9b59c0f51b23c4df7e183cbd02f4
SHA256: 68b6dec0ef20bc8c955650b420432458d808c24dcc4c5126b33618bbf30152a6
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\start menu\programs\system tools\desktop.ini 0.08 KB (86 bytes)MD5: 68fa444f95dda594dac226f7f13d7e95
SHA1: bc136a7b4bcb9b59c0f51b23c4df7e183cbd02f4
SHA256: 68b6dec0ef20bc8c955650b420432458d808c24dcc4c5126b33618bbf30152a6
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf 26.42 KB (27052 bytes)MD5: 6ab6fdc53b047c790294ae9ba40c8692
SHA1: 41c97e16204dacc9994244c9a82632099975ce71
SHA256: 6ac37fa9a68a1bbc40178bba0f783ed30b243f03f0673cf7cf31674f169f59c3
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sdstor.pnf 9.31 KB (9532 bytes)MD5: 07ab5f7222e3f030ab9bec198bbc3f9f
SHA1: 13fd6c63a60c32ad7d4e6626b71e3197178494ce
SHA256: 7d611c389cd4941bc6f31dec27a2bead46ed5271dc2e1d6e3f72ace0d616bc20
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\flpydisk.pnf 9.44 KB (9668 bytes)MD5: 174b470c234bed33613e1a0c499e62d9
SHA1: 952c0d6b42dfdfa76bf3db186cc6cf7fcaed0c17
SHA256: 8a25902fdd4ef7a743eb6af1aca4a1aaee4d2befe4e5651ea4f72400b6149230
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\volmgr.pnf 8.20 KB (8396 bytes)MD5: 2570146c184248ae2a7bf41327c74fc7
SHA1: 8333c9a15ad7b8a79237b924df9005812b0b27ec
SHA256: b53b5e4323877a2a243df43b3f3b5eeb02748ee80e0d9f010a0e9585f35e1271
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql40xx2i.pnf 9.68 KB (9908 bytes)MD5: 58e98db83fbfeb7301792321db60ebe5
SHA1: c4ef56ad20d1f9392c50e77ede58e13157cbaad9
SHA256: a3f29b82117dfd1893da2c52ee90f1a9d1ae6228bcc3e98b06e3e5a33568fb9f
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cmbatt.pnf 9.41 KB (9636 bytes)MD5: 72d5f7706d946face710b3384a3bd5fe
SHA1: 2ad1d13ad664bb106c4dde8a14533a337f1dcb69
SHA256: 0bf020671615d7909e5ca709c4e3a14bcf8db949a354629736380bfd5e5b9477
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\input.pnf 142.47 KB (145892 bytes)MD5: ceea6a3a28e766277dcc2c754c3da7a9
SHA1: 02ffa9f41834ffe4f9f369c20ff194b7e784c392
SHA256: 10e62a39d7413a87eddc1805832f4336aa2eb5879d22370913995f00d797b861
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\networkservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000001.regtrans-ms 512.00 KB (524288 bytes)MD5: 78bb580446808b4e17992b29c68d308d
SHA1: cf8877eba13b2790149871abec5411acb89d0a56
SHA256: 5d0af58700c3ee7d81d98e13b19010c31933b2cdcedf4465ad53e89d98017597
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\serviceprofiles\localservice\ntuser.dat{42b82178-0b2e-11e3-93f4-90b11c2eb9f2}.tmcontainer00000000000000000001.regtrans-ms 512.00 KB (524288 bytes)MD5: 78bb580446808b4e17992b29c68d308d
SHA1: cf8877eba13b2790149871abec5411acb89d0a56
SHA256: 5d0af58700c3ee7d81d98e13b19010c31933b2cdcedf4465ad53e89d98017597
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umbus.pnf 9.67 KB (9904 bytes)MD5: 810010be4ec7fdf9cd46350e4b278355
SHA1: 9dca7edecd59ec388b0e3b9dbd2bc1def1113c37
SHA256: cbd177ca1695dda5bbfa8082fae78491ced69a9001cf6939be2468c9ee03480e
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf 12.30 KB (12596 bytes)MD5: a085f574aa7085b8cf7d1d13fc24f14d
SHA1: b5ebb92c5d30912ed9f7383a8235c4c79c346d9e
SHA256: 535b410d5d758acbea71f9780449757a6fd2ed1be045912a1f63d8113e711057
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbhub3.pnf 17.40 KB (17816 bytes)MD5: fa88958f77c7b06b94b903b0c167c826
SHA1: 74dbdcbdd769e9c6ab528045e1d6f2b8ecd2680e
SHA256: 4d8771840b44e8c79074508d539ceee708e34e71ae66bafa05138565ad458419
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ehstortcgdrv.pnf 7.59 KB (7768 bytes)MD5: ec0e144c257d1818500e7860a5eb6e53
SHA1: 1ad8c2bdf7df6eb7a84261d2c02760ca15cc36fe
SHA256: 00ea279d6c049fc4a5a4876fdea0ac4b7cd21f08e3117ffaa40ca614308fac72
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ql2300.pnf 11.91 KB (12200 bytes)MD5: 0c1c17ad4c67889a3cd3f0d9ba124a63
SHA1: 6e4884d2b91266a68891646cc03f3bf2d67eba00
SHA256: 3fb0c9bd9f291dab031551f8dfefc33c09e626ffa6b06a3789fcd86832013152
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbstor.pnf 56.27 KB (57620 bytes)MD5: fa256ba8288fdd9d4fd8162ca35e1204
SHA1: df575db7846bf2f26caffb9c7c875f47897aef9e
SHA256: 356c923cf7b4f53881c981754712302cba73fcd7889f0ffce77a02b190015b16
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\volume.pnf 6.19 KB (6336 bytes)MD5: 0661cf512d8bc38ca3ddb2edffa4a3af
SHA1: 9e871f12040f831051bd83112aa571db63575ba8
SHA256: 2f5c1b56f232e564a8aedc000a07c168c806ddd241e8c2428ca11080fe916c4c
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\tpm.pnf 14.66 KB (15008 bytes)MD5: b3ddd68f33b4fc84e4e6e00c4c4977e3
SHA1: 12393985de8a52706bed6ad17f2d276a12bcde4f
SHA256: a4564d3defb32c11f9d621821de8a1734f9ce79f22c4e2583a0c59db5a2714a8
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\msports.pnf 36.00 KB (36860 bytes)MD5: 4649eaec14108d770fcde9a63d470a03
SHA1: d486645998ac9896cd311f0a24e7cb9e04bcf36c
SHA256: c4003a02d27d896b0efa8134d32a58038e6fd2354f2521ca9f06beffdc95ae1d
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\usbport.pnf 136.06 KB (139324 bytes)MD5: 4c5f2d79ccadbcc6dc5ec96b8a9785e1
SHA1: a6692d6622b1e37017201de04229ead3ef27e403
SHA256: 969db08d55563962e5226e57d0ae9188b013c8ab8bfe2f5661c83507ca23ad9d
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\vstxraid.pnf 10.34 KB (10592 bytes)MD5: 7304944d73f7bab4df1ea31e198dc2c6
SHA1: 5175936c0b57e82939a6d740470a65badb8944eb
SHA256: 5383cab81ccdf2a0e5c010bfb95f1f73fee5aa206f28b547656f4cd2ab278f86
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf 9.90 KB (10140 bytes)MD5: b88aafdf5775449a5b6b77e3f56c737b
SHA1: feec758c3539200971e8429d803cf6af5d9070d7
SHA256: 9c017cdcdb3974f749f2c8b07a175823b06cf57e8e3f78d6b021e237a4fc535f
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf 67.99 KB (69624 bytes)MD5: dfd0ed3867d3a43ebcd24849386913d1
SHA1: 66b965c6d3be21c9edc769cbee8b330cd6206289
SHA256: 7b4b6012c373fc102c2b3943de0b4e13bdad3481d61b8213a57efb8925fa4366
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf 18.35 KB (18792 bytes)MD5: adc6b6528b885ff957911839db69cbe2
SHA1: bdb7044b54158b005129b9b10486079c4e060955
SHA256: b8f065a0894707522da3b497e90c7e3bf57501afcf16c1e1c96e26a4b1cce06e
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf 894.85 KB (916324 bytes)MD5: 61dc874f6580aae1b40dd05679045d62
SHA1: c3672715f73e246f087b57208783da4036df96ca
SHA256: c72d05f60617277399eac46647904a80da6b3b9c7151767809e2f88c2b699335
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mtconfig.pnf 7.45 KB (7632 bytes)MD5: 41a00f76e25ec68f62f260919889f87b
SHA1: eb6dffff887bda06ff7545a4521898773ba03590
SHA256: 5c8b8a82091220df55fff7836baeb9a11ea2eb18e8e76438324e03b1bc929b52
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\iastorv.pnf 15.80 KB (16180 bytes)MD5: 71803429cd83bf1324dbdf64d09cfc64
SHA1: 8b2c2fc6c0ca8dd27dddb4f5efe5dfb16c9539cd
SHA256: 08902ee95a4fc39d1ba16c798b43f0e63ab8e82b3b1425e758c3cac61d725b02
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\fdc.pnf 6.00 KB (6148 bytes)MD5: f296bb6a6d5c830d0e3a9e3f7b26a4b9
SHA1: 760704b53ef2642cbfae94693ae02dc4f9786396
SHA256: 9bccfeb66d7b2428138b43aa3a72543f51a54ba304af0688ba5e1ae666098a02
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ialpssi_gpio.pnf 7.89 KB (8084 bytes)MD5: 5e62f93fcc24f65c987a687dc9c32f9f
SHA1: d0bae0b2bade8584b1f47f0746381a735aaf1db9
SHA256: 899d4ae378e16e445cd2911fdc27e4de554675d6362e291397f701fe1072e355
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\umpass.pnf 6.11 KB (6252 bytes)MD5: 6724aff7377facac08c967bbc98d5b6a
SHA1: e87187f06fe172334709c73f5b176d58edec6092
SHA256: 99c63cd3dd78bd79255978303989ecabaa2267f365d5fbcc2413978c0950fe1f
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bxfcoe.pnf 11.47 KB (11744 bytes)MD5: 24407f7a809b08200bc3856b6ead38f2
SHA1: b7c973701240542f039a04b9d23c7b47f5e0e0f0
SHA256: 6a1bbfe839df2553b8a5c907a51bbf8c1875695604600642f903f9bbbd842f29
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\swenum.pnf 7.34 KB (7520 bytes)MD5: 4a40c5a21aaa9570778e2100f05905a4
SHA1: 7ba6ff6944dd2f74c198186aaf0e0878392ed03a
SHA256: bc3e973d1bf0dafefd9e3bfb71c363dd9b674b80efeeb04cba0ea688fbb0a1ef
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\disk.pnf 16.29 KB (16680 bytes)MD5: 1250eea5907f483d94f504b50e92b78c
SHA1: e7de6c9341f50037d763ff0b5368fdb9bfb3c5dd
SHA256: 3958a558ecaffb60ccadaad7cab012c262c4754bb5965451f00c62b5afec0154
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netevbda.pnf 119.88 KB (122760 bytes)MD5: 5e1a3bd4845a9ccbe630838693db7587
SHA1: 4dc87fc04ea071f7bece13d22acb6c22c3f050a2
SHA256: ff1794ea19970060dd75f59401d7ab738276f5f7d43504b19107e247a68eff65
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\spaceport.pnf 7.19 KB (7360 bytes)MD5: df62091305a3e5c5d244203a18a89dca
SHA1: 506ab944fb7e751cf9cfff7239dd487b63738a03
SHA256: 16f77bbb478f02db1c973df558a2b4fe6232adeb4a408d9035da99734998cd9c
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\hidi2c.pnf 8.84 KB (9048 bytes)MD5: d399e897be0e66932326f9740aa8807d
SHA1: 84e7e8cd02ad22b3c9cd32811770197a3afeeae9
SHA256: 6e6b0daf89cc03960a8f8f6f02c2f2dda57ee12e4008ccb5be1d70cfc9c073ba
Threads
Thread 0x1b0
(Host: 10637, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
SYSGET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue3
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x390008True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGOPEN_KEYFalse2
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\logfiles\scm\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTFalse1
Fn
FILECREATE_DIRFalse1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\logfiles, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATE_DIRTrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\logfiles\scm\, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = OOBEInProgressFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = SystemSetupInProgressTrue1
Fn
REGOPEN_KEYTrue1
Fn
MODLOADbase_address = 0x7ffb70a10000True1
Fn
MODLOADmodule_name = X:\windows\system32\scext.dllFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\VersionsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versions, value_name = 639144026960True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RpcCacheTimeoutFalse1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70a14450True1
Fn
USERSET_PRIVILEGEserver_name = LocalhostTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableTakeOwnershipEventFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RpcOverTcpKeepAliveTimesFalse1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exeTrue1
Fn
MODGET_HANDLEmodule_name = rpcrt4.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb73af9360True1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exeTrue1
Fn
MODGET_HANDLEmodule_name = rpcrt4.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb73a7f1a0True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName, value_name = ComputerNameTrue1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exeTrue1
Fn
MODGET_HANDLEmodule_name = kernelbase.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb7177b660True1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exeTrue1
Fn
MODGET_HANDLEmodule_name = ntdll.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb7415d1b0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb7416bc00True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTFalse1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exeTrue1
Fn
MODGET_HANDLEmodule_name = ntdll.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb74174670True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATEFalse1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1ac, address = 0x94cfff0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1acTrue1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\1394.inf_loc, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\1394.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1ac, address = 0x94cfff0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1acTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocaleTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocale, value_name = en-USFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocaleTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocale, value_name = en-USFalse1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versions, value_name = 000602xxTrue1
Fn
MODLOADmodule_name = kernel32.dll, base_address = 0x0True1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d01c0000True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\IdsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Ids, value_name = en-USFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Ids, value_name = enFalse1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, size = 96True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, size = 22True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, size = 12True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, size = 14192True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, size = 246True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, size = 400True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, size = 1188True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, size = 1312True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\1394.pnf, size = 1312True1
Fn
Data
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue2
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True2
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATEFalse1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1ac, address = 0x94cfff0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1acTrue1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\acpi.inf_loc, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\acpi.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1ac, address = 0x94cfff0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1acTrue1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 96True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 22True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 12True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 7056True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 250True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 304True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 744True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 812True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 812True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpi.pnf, size = 12True1
Fn
Data
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue2
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True2
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATEFalse1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1ac, address = 0x94cfff0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1acTrue1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\acpipagr.inf_loc, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\acpipagr.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1ac, address = 0x94cfff0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1acTrue1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 96True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 22True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 12True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 4972True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 250True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 208True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 396True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 420True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpipagr.pnf, size = 420True1
Fn
Data
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue2
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True2
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATEFalse1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1ac, address = 0x94cfff0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1acTrue1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\acpitime.inf_loc, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\acpitime.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1ac, address = 0x94cfff0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1acTrue1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 96True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 22True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 12True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 5448True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 250True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 208True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 444True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 468True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\acpitime.pnf, size = 468True1
Fn
Data
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue2
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DisplayNameTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettingsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings, value_name = StringCacheGenerationTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7EFalse1
Fn
REGCREATE_KEYreg_name = \Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1\52C64B7EFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCacheTrue1
Fn
REGCREATE_KEYreg_name = \Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\1True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\Software\Classes\Local Settings\MuiCache\1\52C64B7EFalse1
Fn
REGCREATE_KEYreg_name = \Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\Software\Classes\Local Settings\MuiCache\1\52C64B7ETrue1
Fn
REGWRITE_VALUEreg_name = \Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\Software\Classes\Local Settings\MuiCache\1\52C64B7E, value_name = LanguageList, data = en-USTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\Software\Classes\Local Settings\MuiCache\1\52C64B7E, value_name = @%systemroot%\system32\drivers\afd.sys,-1000False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\afd.sys, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\drivers\afd.sys, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xfe90000False1
Fn
REGWRITE_VALUEreg_name = \Registry\Machine\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings\Software\Classes\Local Settings\MuiCache\Software\Classes\Local Settings\MuiCache\1\52C64B7E, value_name = @%systemroot%\system32\drivers\afd.sys,-1000, data = Ancillary Function Driver for WinsockTrue1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, base_address = 0xfe90000True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True2
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATEFalse1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1ac, address = 0x94d04a0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94d04a0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1acTrue1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\machine.inf_loc, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\machine.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1ac, address = 0x94cfff0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1acTrue1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 96True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 22True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 12True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 741276True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 250True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 2176True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 53292True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 59588True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\machine.pnf, size = 59588True1
Fn
Data
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue2
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True2
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATEFalse1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1ac, address = 0x94cfff0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1acTrue1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\cpu.inf_loc, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\cpu.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1ac, address = 0x94cfff0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1acTrue1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 96True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 22True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 12True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 17988True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 256True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 848True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 2304True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 2756True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, size = 2756True1
Fn
Data
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue2
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True2
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\cpu.pnf, maximum_size = 639144024192, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1ac, address = 0x94cfff0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
REGOPEN_KEYreg_name = Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\InternationalFalse1
Fn
REGREAD_VALUEreg_name = Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\International, value_name = sCurrencyOverrideFalse1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue2
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1acTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True2
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATEFalse1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1ac, address = 0x94cfff0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1acTrue1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\arcsas.inf_loc, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\arcsas.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1ac, address = 0x94cfff0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1acTrue1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf, size = 96True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf, size = 22True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf, size = 12True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf, size = 43384True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf, size = 256True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf, size = 368True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf, size = 5052True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf, size = 5840True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\arcsas.pnf, size = 5840True1
Fn
Data
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue2
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True2
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATEFalse1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1ac, address = 0x94cfff0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1acTrue1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\mshdc.inf_loc, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\mshdc.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1ac, address = 0x94cfff0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1acTrue1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 96True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 22True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 12True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 48332True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 244True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 1312True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 5736True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 6928True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\mshdc.pnf, size = 6928True1
Fn
Data
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue2
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True2
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATEFalse1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1ac, address = 0x94cfff0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1acTrue1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\netbvbda.inf_loc, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\netbvbda.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1ac, address = 0x94cfff0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1acTrue1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 96True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 22True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 12True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 8044True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 250True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 544True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1068True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1268True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netbvbda.pnf, size = 1268True1
Fn
Data
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue2
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True2
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATEFalse1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.inf, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1ac, address = 0x94cfff0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1acTrue1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\bcmfn2.inf_loc, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\driverstore\en-us\bcmfn2.inf_loc, maximum_size = 639144024704, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1ac, address = 0x94cfff0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x94cfff0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe, os_pid = 0x1acTrue1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0True1
Fn
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 96True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 22True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 12True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 5004True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 250True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 208True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 432True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 484True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 1True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\bcmfn2.pnf, size = 484True1
Fn
Data
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
For performance reasons, the remaining 9069 entries are omitted.
Click to download all 10069 entries as text file (6.98 MB).
Thread 0x208
(Host: 17, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
DRVCONTROLcontrol_code = 0x110008False1
Fn
SVCOPEN_MGRdatabase_name = SERVICES_ACTIVE_DATABASE, host = LocalhostTrue1
Fn
SVCOPENTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEvalue_name = SQMServiceListTrue1
Fn
SVCGET_INFOtype = StatusTrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 639153338176 milliseconds (639153338.176 seconds)True1
Fn
SVCGET_INFOtype = StatusTrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 639153338176 milliseconds (639153338.176 seconds)False1
Fn
SVCGET_INFOtype = StatusTrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 639153338176 milliseconds (639153338.176 seconds)True1
Fn
SVCGET_INFOtype = StatusTrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 639153338176 milliseconds (639153338.176 seconds)False1
Fn
Thread 0x20c
(Host: 20, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
DRVCONTROLcontrol_code = 0x110008False1
Fn
PROCGET_INFOTrue1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exeTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR, value_name = DisableTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exeTrue2
Fn
PROCGET_INFOreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySideTrue1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exeTrue2
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
PROCGET_INFOreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySideTrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
Thread 0x260
(Host: 2, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exeTrue2
Fn
Thread 0x2d4
(Host: 1, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exeTrue1
Fn
Process #11: lsass.exe
(Host: 1720, Network: 2)
+
InformationValue
ID / OS PID#11 / 0x1b4
OS Parent PID0x164 (c:\windows\system32\csrss.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe
Command LineX:\windows\system32\lsass.exe -setup
MonitorStart Time: 00:01:36, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:31
OS Thread IDs
#69
0x1B8
#71
0x1C0
#72
0x1C4
#73
0x1C8
#74
0x1CC
#75
0x1D0
#76
0x1D4
#77
0x1D8
#78
0x1DC
#79
0x1E0
#80
0x1E4
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x0000006b29a300000x6b29a300000x6b29a4ffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000006b29a300000x6b29a300000x6b29a3ffffPagefile Backed FileReadable, WritableTrue
pagefile_0x0000006b29a400000x6b29a400000x6b29a40fffPagefile Backed FileReadable, WritableTrue
pagefile_0x0000006b29a500000x6b29a500000x6b29a5efffPagefile Backed FileReadableTrue
private_0x0000006b29a600000x6b29a600000x6b29adffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000006b29ae00000x6b29ae00000x6b29ae3fffPagefile Backed FileReadableTrue
pagefile_0x0000006b29af00000x6b29af00000x6b29af0fffPagefile Backed FileReadableTrue
private_0x0000006b29b000000x6b29b000000x6b29b01fffPrivate MemoryReadable, WritableTrue
private_0x0000006b29b100000x6b29b100000x6b29c0ffffPrivate MemoryReadable, WritableTrue
locale.nls0x6b29c100000x6b29c8dfffMemory Mapped FileReadableFalse
private_0x0000006b29c900000x6b29c900000x6b29d0ffffPrivate MemoryReadable, WritableTrue
private_0x0000006b29d100000x6b29d100000x6b29d16fffPrivate MemoryReadable, WritableTrue
private_0x0000006b29d200000x6b29d200000x6b29d2ffffPrivate MemoryReadable, WritableTrue
private_0x0000006b29d300000x6b29d300000x6b29d36fffPrivate MemoryReadable, WritableTrue
private_0x0000006b29d400000x6b29d400000x6b29dbffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000006b29dc00000x6b29dc00000x6b29dcffffPagefile Backed FileReadable, WritableTrue
pagefile_0x0000006b29dd00000x6b29dd00000x6b29ddffffPagefile Backed FileReadable, WritableTrue
private_0x0000006b29de00000x6b29de00000x6b29e5ffffPrivate MemoryReadable, WritableTrue
private_0x0000006b29e600000x6b29e600000x6b29edffffPrivate MemoryReadable, WritableTrue
lsasrv.dll.mui0x6b29ee00000x6b29eeafffMemory Mapped FileReadableFalse
pagefile_0x0000006b29ef00000x6b29ef00000x6b29efffffPagefile Backed FileReadable, WritableTrue
sortdefault.nls0x6b29f000000x6b2a1d4fffMemory Mapped FileReadableFalse
c_28591.nls0x6b2a1e00000x6b2a1f0fffMemory Mapped FileReadableFalse
private_0x0000006b2a2000000x6b2a2000000x6b2a200fffPrivate MemoryReadable, WritableTrue
private_0x0000006b2a2100000x6b2a2100000x6b2a28ffffPrivate MemoryReadable, WritableTrue
private_0x0000006b2a2900000x6b2a2900000x6b2a290fffPrivate MemoryReadable, WritableTrue
private_0x0000006b2a2a00000x6b2a2a00000x6b2a2a0fffPrivate MemoryReadable, WritableTrue
private_0x0000006b2a2b00000x6b2a2b00000x6b2a2b0fffPrivate MemoryReadable, WritableTrue
private_0x0000006b2a2c00000x6b2a2c00000x6b2a2c0fffPrivate MemoryReadable, WritableTrue
private_0x0000006b2a2d00000x6b2a2d00000x6b2a2d0fffPrivate MemoryReadable, WritableTrue
private_0x0000006b2a2e00000x6b2a2e00000x6b2a35ffffPrivate MemoryReadable, WritableTrue
private_0x0000006b2a3600000x6b2a3600000x6b2a3dffffPrivate MemoryReadable, WritableTrue
private_0x0000006b2a3e00000x6b2a3e00000x6b2a3e0fffPrivate MemoryReadable, WritableTrue
private_0x0000006b2a3e00000x6b2a3e00000x6b2a45ffffPrivate MemoryReadable, WritableTrue
samsrv.dll.mui0x6b2a4600000x6b2a471fffMemory Mapped FileReadableFalse
private_0x0000006b2a4800000x6b2a4800000x6b2a4fffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007df5ff8c00000x7df5ff8c00000x7ff5ff8bffffPagefile Backed File-True
private_0x00007ff6769f80000x7ff6769f80000x7ff6769f9fffPrivate MemoryReadable, WritableTrue
private_0x00007ff6769fa0000x7ff6769fa0000x7ff6769fbfffPrivate MemoryReadable, WritableTrue
private_0x00007ff6769fc0000x7ff6769fc0000x7ff6769fdfffPrivate MemoryReadable, WritableTrue
private_0x00007ff6769fe0000x7ff6769fe0000x7ff6769fffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007ff676a000000x7ff676a000000x7ff676afffffPagefile Backed FileReadableTrue
pagefile_0x00007ff676b000000x7ff676b000000x7ff676b22fffPagefile Backed FileReadableTrue
private_0x00007ff676b230000x7ff676b230000x7ff676b24fffPrivate MemoryReadable, WritableTrue
private_0x00007ff676b250000x7ff676b250000x7ff676b26fffPrivate MemoryReadable, WritableTrue
private_0x00007ff676b270000x7ff676b270000x7ff676b27fffPrivate MemoryReadable, WritableTrue
private_0x00007ff676b280000x7ff676b280000x7ff676b29fffPrivate MemoryReadable, WritableTrue
private_0x00007ff676b2a0000x7ff676b2a0000x7ff676b2bfffPrivate MemoryReadable, WritableTrue
private_0x00007ff676b2c0000x7ff676b2c0000x7ff676b2dfffPrivate MemoryReadable, WritableTrue
private_0x00007ff676b2e0000x7ff676b2e0000x7ff676b2ffffPrivate MemoryReadable, WritableTrue
lsass.exe0x7ff6775e00000x7ff6775edfffMemory Mapped FileReadable, Writable, ExecutableFalse
winsta.dll0x7ffb709400000x7ffb70999fffMemory Mapped FileReadable, Writable, ExecutableFalse
dsrole.dll0x7ffb70a400000x7ffb70a49fffMemory Mapped FileReadable, Writable, ExecutableFalse
scecli.DLL0x7ffb70a500000x7ffb70a97fffMemory Mapped FileReadable, Writable, ExecutableFalse
dpapisrv.dll0x7ffb70aa00000x7ffb70ad2fffMemory Mapped FileReadable, Writable, ExecutableFalse
efslsaext.dll0x7ffb70ae00000x7ffb70af2fffMemory Mapped FileReadable, Writable, ExecutableFalse
rsaenh.dll0x7ffb70b000000x7ffb70b35fffMemory Mapped FileReadable, Writable, ExecutableFalse
wdigest.DLL0x7ffb70b400000x7ffb70b7bfffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPT32.dll0x7ffb70b800000x7ffb70d5efffMemory Mapped FileReadable, Writable, ExecutableFalse
schannel.DLL0x7ffb70d600000x7ffb70dccfffMemory Mapped FileReadable, Writable, ExecutableFalse
USERENV.dll0x7ffb70dd00000x7ffb70df0fffMemory Mapped FileReadable, Writable, ExecutableFalse
logoncli.dll0x7ffb70e000000x7ffb70e3efffMemory Mapped FileReadable, Writable, ExecutableFalse
DNSAPI.dll0x7ffb70e400000x7ffb70ee3fffMemory Mapped FileReadable, Writable, ExecutableFalse
netlogon.DLL0x7ffb70ef00000x7ffb70fc0fffMemory Mapped FileReadable, Writable, ExecutableFalse
msv1_0.DLL0x7ffb70fd00000x7ffb7103bfffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTSP.dll0x7ffb710400000x7ffb7105ffffMemory Mapped FileReadable, Writable, ExecutableFalse
cryptdll.dll0x7ffb710600000x7ffb71079fffMemory Mapped FileReadable, Writable, ExecutableFalse
kerberos.DLL0x7ffb710800000x7ffb71172fffMemory Mapped FileReadable, Writable, ExecutableFalse
netjoin.dll0x7ffb711800000x7ffb711d0fffMemory Mapped FileReadable, Writable, ExecutableFalse
msprivs.DLL0x7ffb711e00000x7ffb711e1fffMemory Mapped FileReadable, Writable, ExecutableFalse
NTASN1.dll0x7ffb711f00000x7ffb71226fffMemory Mapped FileReadable, Writable, ExecutableFalse
ncrypt.dll0x7ffb712300000x7ffb71254fffMemory Mapped FileReadable, Writable, ExecutableFalse
bcrypt.dll0x7ffb712600000x7ffb71285fffMemory Mapped FileReadable, Writable, ExecutableFalse
samsrv.dll0x7ffb712900000x7ffb7135ffffMemory Mapped FileReadable, Writable, ExecutableFalse
MSASN1.dll0x7ffb713600000x7ffb71370fffMemory Mapped FileReadable, Writable, ExecutableFalse
lsasrv.dll0x7ffb713800000x7ffb714e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
SspiSrv.dll0x7ffb714f00000x7ffb714fafffMemory Mapped FileReadable, Writable, ExecutableFalse
SspiCli.dll0x7ffb715000000x7ffb7152dfffMemory Mapped FileReadable, Writable, ExecutableFalse
powrprof.dll0x7ffb715300000x7ffb71575fffMemory Mapped FileReadable, Writable, ExecutableFalse
bcryptPrimitives.dll0x7ffb715800000x7ffb715e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTBASE.dll0x7ffb715f00000x7ffb715fafffMemory Mapped FileReadable, Writable, ExecutableFalse
profapi.dll0x7ffb716b00000x7ffb716c4fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
CFGMGR32.dll0x7ffb718800000x7ffb718cefffMemory Mapped FileReadable, Writable, ExecutableTrue
WS2_32.dll0x7ffb733600000x7ffb733b9fffMemory Mapped FileReadable, Writable, ExecutableTrue
sechost.dll0x7ffb733c00000x7ffb73418fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
advapi32.dll0x7ffb736900000x7ffb73739fffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
NSI.dll0x7ffb73e800000x7ffb73e88fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSVCRT.dll0x7ffb740500000x7ffb740f9fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Injection Information
+
Injection TypeSource ProcessSource Os Thread IDInjection InfoSuccessAmountLogfile
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wininit.exe0x168address = 0x6b29b00000, size = 4704True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wininit.exe0x168address = 0x7ff676b272d8, size = 8True1
Fn
Data
Created or Modified Files
+
FilenameFile SizeHash Values
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\microsoft\protect\s-1-5-18\user\968b739e-d207-46ed-a53d-aed260dbc1d6 0.46 KB (468 bytes)MD5: d04b3035912004a5cb295bcb9530453e
SHA1: 7303d29121a871487d9aa10620829061b29d7a3b
SHA256: 8a93024371ca325399b2e2d3793194779dd4e10aecc2d7dfbc4f8cd21748381b
\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\microsoft\protect\s-1-5-18\user\preferred 0.02 KB (24 bytes)MD5: 0f0b3948f429deda2ed5b504c705b9e7
SHA1: 29def00392c60f70f7102aeab134f79241ff01a0
SHA256: 0b1a1c7eb3734a03ee8f58bed7ef11b6fc98909f7c5c480a05ab3d879a617a8d
Threads
Thread 0x1b8
(Host: 1058, Network: 2)
+
CategoryOperationInformationSuccessAmountLogfile
SYSGET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue2
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
THREADCREATEprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, proc_address = 0x7ff6775e1250, desired_access = THREAD_ALL_ACCESSTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ExtensionsTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ExtensionsTrue1
Fn
MODLOADbase_address = 0x7ffb71380000True1
Fn
MODLOADmodule_name = lsasrv.dll, base_address = 0x0True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\VersionsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versions, value_name = 460260763712True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATEfile_name = \device\deviceapi\cmapi, desired_access = GENERIC_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb713f4880True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb713f6a00True1
Fn
REGOPEN_KEYTrue1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEvalue_name = LsaPid, data = 436True1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = GeneralThreadLifespanFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DedicatedThreadLifespanFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = HighPriorityFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CritSecSpinCountFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
THREADCREATEprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, proc_address = 0x7ffb713f2020, desired_access = THREAD_ALL_ACCESSTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Debug.Memory.v2.1b4, module_name = lsasrv.dll, maximum_size = 460260768064, protection = PAGE_READWRITETrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe, os_pid = 0x1b4, address = 0x6b29dc0000True1
Fn
MODMAPmodule_name = Debug.Memory.v2.1b4, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x6b29dc0000True1
Fn
INIREADfile_name = Win.iniFalse1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\win.ini, desired_access = SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\win.ini, size = 92True1
Fn
Data
PROCOPEN_TOKENTrue1
Fn
INIREADfile_name = Win.iniFalse1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\win.ini, desired_access = SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\win.ini, size = 92True1
Fn
Data
INIREADfile_name = Win.iniFalse1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\win.ini, desired_access = SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\win.ini, size = 92True1
Fn
Data
INIREADfile_name = Win.iniFalse1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\win.ini, desired_access = SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\win.ini, size = 92True1
Fn
Data
INIREADfile_name = Win.iniFalse1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\win.ini, desired_access = SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\win.ini, size = 92True1
Fn
Data
REGOPEN_KEYFalse1
Fn
MODLOADmodule_name = rpcrt4.dll, base_address = 0x0True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
REGREAD_VALUEvalue_name = MaxRpcSizeFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = OOBEInProgressFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = SystemSetupInProgressTrue1
Fn
SYSGET_INFOTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEvalue_name = IdleTimerWindowFalse1
Fn
PROCOPEN_TOKENTrue2
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableRestrictedAdminOutboundCredsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableRestrictedAdminFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = TokenLeakDetectDelaySecsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = IdCacheEntryLifeSpanFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamWaitNoTimeoutFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SuppressExtendedProtectionFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LogToFileFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SendOptionalMechlistMICFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AcceptUnsafeUnprotectedNegotiationFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = CrashOnAuditFailTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = NegEventMaskFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SPMInfoLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableCredManFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableDomainCredsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = HourlyLogLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AuthenticateAnonymousOnlineIDsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = TurnOffAnonymousBlockFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EveryoneIncludesAnonymousFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableAutomaticRestartSignOnFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableConnectedNTLMPasswordFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = NoConnectedUserFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ApplyPolicyToAnonymousLogonFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableLocalLogonSidFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableLinkedConnectionsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = FilterAdministratorTokenFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisplayLastLogonInfoFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = FilterNetworkAuthenticationTokensFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LocalAccountTokenFilterPolicyFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableRestrictionTraversalFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ScForceOptionFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = EnableVirtualizationTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableDebugCheckFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableRestrictedAdminOutboundCredsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableRestrictedAdminFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = TokenLeakDetectDelaySecsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = IdCacheEntryLifeSpanFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamWaitNoTimeoutFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SuppressExtendedProtectionFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LogToFileFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SendOptionalMechlistMICFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AcceptUnsafeUnprotectedNegotiationFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = CrashOnAuditFailTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = NegEventMaskFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SPMInfoLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableCredManFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableDomainCredsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = HourlyLogLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AuthenticateAnonymousOnlineIDsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = TurnOffAnonymousBlockFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EveryoneIncludesAnonymousFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableAutomaticRestartSignOnFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableConnectedNTLMPasswordFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = NoConnectedUserFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ApplyPolicyToAnonymousLogonFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableLocalLogonSidFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableLinkedConnectionsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = FilterAdministratorTokenFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisplayLastLogonInfoFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = FilterNetworkAuthenticationTokensFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LocalAccountTokenFilterPolicyFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableRestrictionTraversalFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ScForceOptionFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = EnableVirtualizationTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = PreferredFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = Security PackagesTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = Security PackagesTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = Security PackagesTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = Security PackagesTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = Security PackagesTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = Security PackagesTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = Authentication PackagesTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = Authentication PackagesTrue1
Fn
REGOPEN_KEYFalse1
Fn
MODLOADbase_address = 0x7ffb71380000True1
Fn
MODLOADmodule_name = LSASRV.DLL, base_address = 0x0True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR, value_name = DisableTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR, value_name = lspdbginfolevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR, value_name = LsaDbExtPtFalse1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x390008True1
Fn
REGOPEN_KEYTrue2
Fn
REGDELETE_KEYTrue8
Fn
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = JDTrue1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEreg_name = JD, value_name = LookupTrue1
Fn
Data
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = Skew1True1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEreg_name = Skew1, value_name = SkewMatrixTrue1
Fn
Data
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = GBGTrue1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEreg_name = GBG, value_name = GrafBlumGroupTrue1
Fn
Data
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = DataTrue1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEreg_name = Data, value_name = PatternTrue1
Fn
Data
REGOPEN_KEYTrue1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEvalue_name = SecureBoot, data = 1True1
Fn
REGOPEN_KEYTrue1
Fn
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = System\CurrentControlSet\Control\Lsa\AuditTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\Lsa\Audit, value_name = SpecialGroupsFalse1
Fn
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = Software\Microsoft\Windows\CurrentVersion\Policies\System\AuditTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeTrue1
Fn
MODGET_HANDLEmodule_name = lsasrv.dllTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
MODLOADbase_address = 0x0False1
Fn
MODLOADmodule_name = negoexts, base_address = 0xc0000135False1
Fn
MODLOADbase_address = 0x7ffb71080000True1
Fn
MODLOADmodule_name = kerberos, base_address = 0x0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb710c5d28True1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeTrue1
Fn
MODGET_HANDLEmodule_name = kerberos.dllTrue1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeTrue1
Fn
MODGET_HANDLEmodule_name = kerberos.dllTrue1
Fn
REGOPEN_KEYTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Debug.Trace.Memory.1b4, module_name = kerberos, maximum_size = 460260765872, protection = PAGE_READWRITETrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe, os_pid = 0x1b4, address = 0x6b29ef0000True1
Fn
MODMAPmodule_name = Debug.Trace.Memory.1b4, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x6b29ef0000True1
Fn
DBGCHECK_FOR_PRESENCEtype = DEBUGGER, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe, os_pid = 0x1b4True1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = KerbDebugLevelFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Services\Tcpip\ParametersTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters, value_name = HostnameFalse1
Fn
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = System\CurrentControlSet\Control\Lsa\Kerberos\DomainsTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = KerbControlLevelFalse1
Fn
REGOPEN_KEYFalse2
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SupportedEncryptionTypesFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MaxTokenSizeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DHDomainParametersFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse2
Fn
REGREAD_VALUEvalue_name = WinSock_Registry_VersionTrue2
Fn
REGREAD_VALUEvalue_name = AppFullPathTrue2
Fn
REGREAD_VALUEvalue_name = PermittedLspCategoriesTrue1
Fn
REGREAD_VALUEvalue_name = NameSpace_CalloutTrue2
Fn
REGREAD_VALUEvalue_name = Serial_Access_NumTrue2
Fn
REGREAD_VALUEvalue_name = Next_Catalog_Entry_IDTrue1
Fn
REGREAD_VALUEvalue_name = Num_Catalog_Entries64False1
Fn
REGREAD_VALUEvalue_name = Num_Catalog_EntriesTrue1
Fn
REGREAD_VALUEvalue_name = Serial_Access_NumTrue1
Fn
REGCREATE_KEYreg_name = 00000001True1
Fn
REGCREATE_KEYreg_name = Catalog_Entries64True1
Fn
REGWRITE_VALUEvalue_name = Num_Catalog_Entries64, data = 0True1
Fn
REGWRITE_VALUEvalue_name = Next_Catalog_Entry_ID, data = 1001True1
Fn
REGWRITE_VALUEvalue_name = Serial_Access_Num, data = 2True1
Fn
REGDELETE_KEYreg_name = Catalog_Entries64True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEreg_name = Catalog_Entries64, value_name = Serial_Access_NumTrue2
Fn
REGREAD_VALUEreg_name = Catalog_Entries64, value_name = Num_Catalog_Entries64False1
Fn
REGREAD_VALUEreg_name = Catalog_Entries64, value_name = Num_Catalog_EntriesTrue1
Fn
REGREAD_VALUEvalue_name = LibraryPathTrue2
Fn
REGREAD_VALUEvalue_name = DisplayStringTrue4
Fn
REGREAD_VALUEvalue_name = ProviderIdTrue1
Fn
REGREAD_VALUEvalue_name = AddressFamilyFalse1
Fn
REGREAD_VALUEvalue_name = SupportedNameSpaceTrue1
Fn
REGREAD_VALUEvalue_name = EnabledTrue1
Fn
REGREAD_VALUEvalue_name = VersionTrue1
Fn
REGREAD_VALUEvalue_name = StoresServiceClassInfoTrue1
Fn
REGREAD_VALUEvalue_name = ProviderInfoFalse1
Fn
REGREAD_VALUEreg_name = Catalog_Entries64, value_name = Serial_Access_NumTrue1
Fn
REGCREATE_KEYreg_name = Catalog_Entries64\00000001True1
Fn
REGCREATE_KEYreg_name = Catalog_Entries64\Catalog_Entries64True1
Fn
REGCREATE_KEYreg_name = Catalog_Entries64\Catalog_Entries64\000000000001True1
Fn
REGWRITE_VALUEreg_name = Catalog_Entries64\Catalog_Entries64\000000000001, value_name = LibraryPath, data = X:\Windows\system32\mswsock.dllTrue1
Fn
REGWRITE_VALUEreg_name = Catalog_Entries64\Catalog_Entries64\000000000001, value_name = DisplayString, data = TcpipTrue1
Fn
REGWRITE_VALUEreg_name = Catalog_Entries64\Catalog_Entries64\000000000001, value_name = ProviderIdTrue1
Fn
Data
REGWRITE_VALUEreg_name = Catalog_Entries64\Catalog_Entries64\000000000001, value_name = SupportedNameSpace, data = 12True1
Fn
REGWRITE_VALUEreg_name = Catalog_Entries64\Catalog_Entries64\000000000001, value_name = Enabled, data = 1True1
Fn
REGWRITE_VALUEreg_name = Catalog_Entries64\Catalog_Entries64\000000000001, value_name = Version, data = 0True1
Fn
REGWRITE_VALUEreg_name = Catalog_Entries64\Catalog_Entries64\000000000001, value_name = StoresServiceClassInfo, data = 1True1
Fn
REGWRITE_VALUEreg_name = Catalog_Entries64\Catalog_Entries64\000000000001, value_name = ProviderInfoTrue1
Fn
REGWRITE_VALUEreg_name = Catalog_Entries64, value_name = Num_Catalog_Entries64, data = 1True1
Fn
REGWRITE_VALUEreg_name = Catalog_Entries64, value_name = Serial_Access_Num, data = 2True1
Fn
REGDELETE_KEYreg_name = Catalog_Entries64\Catalog_Entries64True1
Fn
REGREAD_VALUEreg_name = Catalog_Entries64, value_name = Serial_Access_NumTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEvalue_name = Ws2_32NumHandleBucketsFalse1
Fn
SCKCREATEFalse1
Fn
REGREAD_VALUEvalue_name = Serial_Access_NumTrue1
Fn
REGREAD_VALUEvalue_name = Next_Catalog_Entry_IDTrue1
Fn
REGREAD_VALUEvalue_name = Num_Catalog_Entries64True1
Fn
REGREAD_VALUEvalue_name = Serial_Access_NumTrue1
Fn
REGREAD_VALUEvalue_name = Next_Catalog_Entry_IDTrue1
Fn
REGREAD_VALUEvalue_name = Num_Catalog_Entries64True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe, os_pid = 0x1b4, address = 0x6b29f00000True1
Fn
MODMAPreg_name = Catalog_Entries64\00000001, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x6b29f00000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe, os_pid = 0x1b4True1
Fn
INIREADfile_name = Win.iniFalse1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\win.ini, desired_access = SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\win.ini, size = 92True1
Fn
Data
INIREADfile_name = Win.iniFalse1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\win.ini, desired_access = SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\win.ini, size = 92True1
Fn
Data
INIREADfile_name = Win.iniFalse1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\win.ini, desired_access = SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\win.ini, size = 92True1
Fn
Data
SCKCREATEFalse1
Fn
REGOPEN_KEYFalse2
Fn
MODLOADbase_address = 0x7ffb70fd0000True1
Fn
MODLOADmodule_name = msv1_0, base_address = 0x0True1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeTrue1
Fn
MODGET_HANDLEmodule_name = msv1_0.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70ff78a0True1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeTrue1
Fn
MODGET_HANDLEmodule_name = msv1_0.dllTrue1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeTrue1
Fn
MODGET_HANDLEmodule_name = msv1_0.dllTrue1
Fn
REGOPEN_KEYTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe, os_pid = 0x1b4, address = 0x6b29f00000True1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x6b29f00000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe, os_pid = 0x1b4True1
Fn
DBGCHECK_FOR_PRESENCEtype = DEBUGGER, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe, os_pid = 0x1b4True1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Catalog_Entries64\Catalog_Entries64\000000000001, value_name = NtLmInfoLevelFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Services\Tcpip\ParametersTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters, value_name = HostnameFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LmCompatibilityLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = UseMachineIdFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ForceGuestFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisallowMsvChapv2False1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = LimitBlankPasswordUseTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableLoopbackCheckFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugBreakIfDebuggedFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = OldPasswordAllowedPeriodFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AllowLegacySrvCallFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SendNt2ResponseOnlyFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = NtlmMinClientSecTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = NtlmMinServerSecTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = BackConnectionHostNamesFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RestrictSendingNTLMTrafficFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RestrictReceivingNTLMTrafficFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AuditReceivingNTLMTrafficFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ClientAllowedNTLMServersFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = NTLMInfoEventFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = allownullsessionfallbackFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AllowS4UForDomainUsersFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MappedDomainFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = PreferredDomainFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = IPAddressRefreshIntervalFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Services\Tcpip\ParametersTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters, value_name = HostnameFalse1
Fn
FILECREATEFalse1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\debug\passwd.log, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_MAXIMUM_DISPOSITION, ea_buffer = 0, ea_length = 0False1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
MODLOADbase_address = 0x7ffb70ef0000True1
Fn
MODLOADmodule_name = netlogonFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SystemSetupInProgressTrue1
Fn
MODLOADbase_address = 0x7ffb70d60000True1
Fn
MODLOADmodule_name = schannel, base_address = 0x0True1
Fn
REGOPEN_KEYFalse1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeTrue1
Fn
MODGET_HANDLEmodule_name = schannel.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70d838c0True1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeTrue1
Fn
MODGET_HANDLEmodule_name = schannel.dllTrue1
Fn
REGOPEN_KEYTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe, os_pid = 0x1b4, address = 0x6b29f00000True1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x6b29f00000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe, os_pid = 0x1b4True1
Fn
DBGCHECK_FOR_PRESENCEtype = DEBUGGER, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe, os_pid = 0x1b4True1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LogLevelFalse1
Fn
MODLOADbase_address = 0x7ffb70b40000True1
Fn
MODLOADmodule_name = wdigest, base_address = 0x0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b45480True1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeTrue1
Fn
MODGET_HANDLEmodule_name = wdigest.dllTrue1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeTrue1
Fn
MODGET_HANDLEmodule_name = wdigest.dllTrue1
Fn
REGOPEN_KEYTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe, os_pid = 0x1b4, address = 0x6b29f00000True1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x6b29f00000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe, os_pid = 0x1b4True1
Fn
DBGCHECK_FOR_PRESENCEtype = DEBUGGER, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe, os_pid = 0x1b4True1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DebuglevelTrue1
Fn
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigestTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = NegotiateTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = UTF8HTTPTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = UTF8SASLTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = ServerCompatFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = ClientCompatFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = DigestEncryptionAlgorithmsFalse1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEvalue_name = DigestEncryptionAlgorithms, data = 3des,rc4True1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = UseLogonCredentialFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = DisableNameRealmValidationFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = DebuglevelTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = NameTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = NameTrue2
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = TypeTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = Image PathTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = Image PathTrue2
Fn
MODLOADbase_address = 0x7ffb70b00000True1
Fn
MODLOADmodule_name = X:\windows\system32\rsaenh.dll, base_address = 0x0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b01570True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b01080True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b06090True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b1e1d0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b02ce0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b0af70True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b03880True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b03a30True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b03260True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b06be0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b04ea0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b027d0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b02b00True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b1d8d0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b024f0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b06830True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b03c50True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b01030True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b05bb0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b0f290True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b0f750True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b03f50True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b02630True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b0d330True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b1d6e0True1
Fn
REGOPEN_KEYFalse1
Fn
PROCOPEN_TOKENTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MachineGuidFalse1
Fn
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = Software\Microsoft\CryptographyTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Cryptography, value_name = MachineGuidFalse1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEreg_name = Software\Microsoft\Cryptography, value_name = MachineGuid, data = 4510eeb9-2c9e-4e5e-bb64-8d8e190b646fTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versions, value_name = 000602xxTrue1
Fn
MODLOADmodule_name = kernel32.dll, base_address = 0x0True1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x6b29f00000True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\IdsTrue1
Fn
PROCOPEN_TOKENTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = NameTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = NameTrue2
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = TypeTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = Image PathTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = Image PathTrue2
Fn
MODLOADbase_address = 0x7ffb70b00000True1
Fn
MODLOADmodule_name = X:\windows\system32\rsaenh.dll, base_address = 0x0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b01570True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b01080True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b06090True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b1e1d0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b02ce0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b0af70True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b03880True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b03a30True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b03260True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b06be0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b04ea0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b027d0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b02b00True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b1d8d0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b024f0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b06830True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b03c50True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b01030True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b05bb0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b0f290True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b0f750True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b03f50True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b02630True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b0d330True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b1d6e0True1
Fn
PROCOPEN_TOKENTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = MachineGuidTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = MachineGuidTrue2
Fn
REGOPEN_KEYFalse1
Fn
PROCOPEN_TOKENTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = NegotiateTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = UTF8HTTPTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = UTF8SASLTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = ServerCompatFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = ClientCompatFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = DigestEncryptionAlgorithmsTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = DigestEncryptionAlgorithmsTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = UseLogonCredentialFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = DisableNameRealmValidationFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = DebuglevelTrue1
Fn
MODLOADbase_address = 0x0False1
Fn
MODLOADmodule_name = "", base_address = 0xc0000135False1
Fn
MODLOADbase_address = 0x7ffb70fd0000True1
Fn
MODLOADmodule_name = msv1_0, base_address = 0x0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70ff56c0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70fe8a90True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70fdb500True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70fdb9f0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70fed400True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70fd10b0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x0False1
Fn
MODLOADbase_address = 0x7ffb71580000True1
Fn
MODLOADmodule_name = X:\windows\system32\bcryptprimitives.dll, base_address = 0x0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb71595b30True2
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb71584530True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MaxCredentialsSizeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = TargetInfoCacheSizeFalse1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeTrue1
Fn
MODGET_HANDLEmodule_name = lsasrv.dllTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = ComputerNameTrue1
Fn
PROCOPEN_TOKENTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsaLookupCacheRefreshTimeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsaLookupCacheExpireTimeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsaLookupCacheMaxSizeFalse1
Fn
REGOPEN_KEYFalse2
Fn
REGOPEN_KEYTrue1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEvalue_name = RNGAuxiliarySeed, data = 1477820023True1
Fn
MODLOADbase_address = 0x7ffb70ae0000True1
Fn
MODLOADmodule_name = efslsaext.dll, base_address = 0x0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70ae4980True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x0False1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ExtensionTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ExtensionTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ExtensionTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ExtensionTrue1
Fn
MODLOADbase_address = 0x7ffb70aa0000True1
Fn
MODLOADmodule_name = dpapisrv.dll, base_address = 0x0True1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeTrue1
Fn
MODGET_HANDLEmodule_name = dpapisrv.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70aad6c0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70aadb40True1
Fn
PROCOPEN_TOKENTrue1
Fn
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = System\CurrentControlSet\Control\Lsa\SspiCacheTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SecurityProvidersFalse1
Fn
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297ebFalse1
Fn
REGCREATE_KEYreg_name = SOFTWARETrue1
Fn
REGCREATE_KEYreg_name = SOFTWARE\MicrosoftTrue1
Fn
REGCREATE_KEYreg_name = SOFTWARE\Microsoft\CryptographyTrue1
Fn
REGCREATE_KEYreg_name = SOFTWARE\Microsoft\Cryptography\ProtectTrue1
Fn
REGCREATE_KEYreg_name = SOFTWARE\Microsoft\Cryptography\Protect\ProvidersTrue1
Fn
REGCREATE_KEYreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297ebTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb, value_name = MasterKeyIterationCountFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb, value_name = MasterKeyLegacyComplianceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb, value_name = MasterKeyLegacyNt4DomainFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb, value_name = DistributeBackupKeyFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb, value_name = ProtectionPolicyFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb, value_name = Recovery VersionFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb, value_name = Encr AlgFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb, value_name = Encr Alg Key SizeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb, value_name = MAC AlgFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb, value_name = MAC Alg Key SizeFalse1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeTrue1
Fn
MODGET_HANDLEmodule_name = ntdll.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb741801b0True1
Fn
THREADCREATEprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, proc_address = 0x7ffb713f2d90, desired_access = THREAD_ALL_ACCESSTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MiniSetupInProgressFalse1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeTrue1
Fn
MODGET_HANDLEmodule_name = LSASRV.DLLTrue1
Fn
THREADCREATE_WORKITEMTrue1
Fn
MODLOADbase_address = 0x7ffb71500000True1
Fn
MODLOADmodule_name = sspicli.dll, base_address = 0x0True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LookupLogLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsaLookupReturnSidTypeDeletedFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsaLookupRestrictIsolatedNameLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsarpcServerAllowRemotedSecretOperationsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsaLookupCacheRefreshTimeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsaLookupCacheExpireTimeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsaLookupCacheMaxSizeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsaAllowReturningUnencryptedSecretsFalse1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeTrue1
Fn
MODGET_HANDLEmodule_name = ntdll.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb741b0fa0True1
Fn
REGOPEN_KEYFalse1
Fn
THREADCREATEprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, proc_address = 0x7ffb713fa570, desired_access = THREAD_ALL_ACCESSTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = NoLmHashTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamReplicatePasswordsUrgentlyFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ForceGuestFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = LimitBlankPasswordUseTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamAccountLockoutTestModeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamDisableListenOnTCPFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = IgnoreGCFailuresFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamNoGcLogonEnforceKerberosIpCheckFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamNoGcLogonEnforceNTLMCheckFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamDisableSingleObjectReplFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamDisableRSOOnPDCForwardFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamDisableResetBadPwdCountForwardFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamConnectedAccountsExistFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamDisableOutboundRSOFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RestrictAnonymousFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RestrictAnonymousSamFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ExtendedSidEmulationModeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamLogSizeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamLogLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamRestrictOwfPasswordChangeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MaxSamConnectionsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = dsrmAdminLogonBehaviorFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamMaxQueueLengthForPDCForwardFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableClaimsTransformationEchoFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnumerationCachePurgeIntervalFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnumerationCacheEntryLifetimeFalse1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeTrue1
Fn
MODGET_HANDLEmodule_name = SAMSRV.DLLTrue1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeTrue1
Fn
MODGET_HANDLEmodule_name = SAMSRV.DLLTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Services\Tcpip\ParametersTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters, value_name = HostnameFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEvalue_name = ProductType, data = 1True1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
MODLOADbase_address = 0x7ffb70a50000True1
Fn
MODLOADmodule_name = scecli, base_address = 0x0True1
Fn
THREADCREATE_WORKITEMTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
THREADCREATEprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, proc_address = 0x7ffb712c7c30, desired_access = THREAD_ALL_ACCESSTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGOPEN_KEYFalse4
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGOPEN_KEYFalse4
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
MODLOADbase_address = 0x7ffb71290000True1
Fn
MODLOADmodule_name = SAMSRV.DLL, base_address = 0x0True1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeTrue1
Fn
MODGET_HANDLEmodule_name = ntdll.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb741b0fa0True1
Fn
MODLOADbase_address = 0x7ffb71290000True1
Fn
MODLOADmodule_name = SAMSRV.DLL, base_address = 0x0True1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
MODLOADbase_address = 0x7ffb71290000True1
Fn
MODLOADmodule_name = SAMSRV.DLL, base_address = 0x0True1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
MODLOADbase_address = 0x7ffb71290000True1
Fn
MODLOADmodule_name = SAMSRV.DLL, base_address = 0x0True1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
MODLOADbase_address = 0x7ffb71290000True1
Fn
MODLOADmodule_name = SAMSRV.DLL, base_address = 0x0True1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
MODLOADbase_address = 0x7ffb71290000True1
Fn
MODLOADmodule_name = SAMSRV.DLL, base_address = 0x0True1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = PolicyFilterOffFalse1
Fn
THREADCREATE_WORKITEMTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
MODLOADbase_address = 0x7ffb71290000True1
Fn
MODLOADmodule_name = SAMSRV.DLL, base_address = 0x0True1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
MODLOADbase_address = 0x7ffb71290000True1
Fn
MODLOADmodule_name = SAMSRV.DLL, base_address = 0x0True1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
MODLOADbase_address = 0x7ffb71290000True1
Fn
MODLOADmodule_name = SAMSRV.DLL, base_address = 0x0True1
Fn
REGREAD_VALUEFalse1
Fn
For performance reasons, the remaining 16 entries are omitted.
Click to download all 1016 entries as text file (0.40 MB).
Thread 0x1c8
(Host: 332, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableRestrictedAdminOutboundCredsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableRestrictedAdminFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = TokenLeakDetectDelaySecsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = IdCacheEntryLifeSpanFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamWaitNoTimeoutFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SuppressExtendedProtectionFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LogToFileFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SendOptionalMechlistMICFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AcceptUnsafeUnprotectedNegotiationFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = CrashOnAuditFailTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = NegEventMaskFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SPMInfoLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableCredManFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableDomainCredsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = HourlyLogLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AuthenticateAnonymousOnlineIDsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = TurnOffAnonymousBlockFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EveryoneIncludesAnonymousFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableRestrictedAdminOutboundCredsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableRestrictedAdminFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = TokenLeakDetectDelaySecsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = IdCacheEntryLifeSpanFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamWaitNoTimeoutFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SuppressExtendedProtectionFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LogToFileFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SendOptionalMechlistMICFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AcceptUnsafeUnprotectedNegotiationFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = CrashOnAuditFailTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = NegEventMaskFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SPMInfoLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableCredManFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableDomainCredsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = HourlyLogLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AuthenticateAnonymousOnlineIDsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = TurnOffAnonymousBlockFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EveryoneIncludesAnonymousFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableAutomaticRestartSignOnFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableConnectedNTLMPasswordFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = NoConnectedUserFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ApplyPolicyToAnonymousLogonFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableLocalLogonSidFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableLinkedConnectionsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = FilterAdministratorTokenFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisplayLastLogonInfoFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = FilterNetworkAuthenticationTokensFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LocalAccountTokenFilterPolicyFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableRestrictionTraversalFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ScForceOptionFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = EnableVirtualizationTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DebuglevelTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableRestrictedAdminOutboundCredsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableRestrictedAdminFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = TokenLeakDetectDelaySecsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = IdCacheEntryLifeSpanFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamWaitNoTimeoutFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SuppressExtendedProtectionFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LogToFileFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SendOptionalMechlistMICFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AcceptUnsafeUnprotectedNegotiationFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = CrashOnAuditFailTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = NegEventMaskFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SPMInfoLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableCredManFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableDomainCredsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = HourlyLogLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AuthenticateAnonymousOnlineIDsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = TurnOffAnonymousBlockFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EveryoneIncludesAnonymousFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableRestrictedAdminOutboundCredsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableRestrictedAdminFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = TokenLeakDetectDelaySecsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = IdCacheEntryLifeSpanFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamWaitNoTimeoutFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SuppressExtendedProtectionFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LogToFileFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SendOptionalMechlistMICFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AcceptUnsafeUnprotectedNegotiationFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = CrashOnAuditFailTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = NegEventMaskFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SPMInfoLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableCredManFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableDomainCredsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = HourlyLogLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AuthenticateAnonymousOnlineIDsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = TurnOffAnonymousBlockFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EveryoneIncludesAnonymousFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LmCompatibilityLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = UseMachineIdFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ForceGuestFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisallowMsvChapv2False1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = LimitBlankPasswordUseTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableLoopbackCheckFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugBreakIfDebuggedFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = OldPasswordAllowedPeriodFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AllowLegacySrvCallFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SendNt2ResponseOnlyFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = NtlmMinClientSecTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = NtlmMinServerSecTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = BackConnectionHostNamesFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RestrictSendingNTLMTrafficFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RestrictReceivingNTLMTrafficFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AuditReceivingNTLMTrafficFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ClientAllowedNTLMServersFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = NTLMInfoEventFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = allownullsessionfallbackFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AllowS4UForDomainUsersFalse1
Fn
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = System\CurrentControlSet\Control\Lsa\AuditTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\Lsa\Audit, value_name = SpecialGroupsFalse1
Fn
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = Software\Microsoft\Windows\CurrentVersion\Policies\System\AuditTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\Policies\System\Audit, value_name = ProcessCreationIncludeCmdLine_EnabledFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = KerbDebugLevelFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Catalog_Entries64\Catalog_Entries64\000000000001, value_name = NtLmInfoLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LogLevelFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = NegotiateTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = UTF8HTTPTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = UTF8SASLTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = ServerCompatFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = ClientCompatFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = DigestEncryptionAlgorithmsTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = DigestEncryptionAlgorithmsTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = UseLogonCredentialFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = DisableNameRealmValidationFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\SecurityProviders\WDigest, value_name = DebuglevelTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LmCompatibilityLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = UseMachineIdFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ForceGuestFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisallowMsvChapv2False1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = LimitBlankPasswordUseTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableLoopbackCheckFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugBreakIfDebuggedFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = OldPasswordAllowedPeriodFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AllowLegacySrvCallFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SendNt2ResponseOnlyFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = NtlmMinClientSecTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = NtlmMinServerSecTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = BackConnectionHostNamesFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RestrictSendingNTLMTrafficFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RestrictReceivingNTLMTrafficFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AuditReceivingNTLMTrafficFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ClientAllowedNTLMServersFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = NTLMInfoEventFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = allownullsessionfallbackFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AllowS4UForDomainUsersFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableRestrictedAdminOutboundCredsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableRestrictedAdminFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = TokenLeakDetectDelaySecsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = IdCacheEntryLifeSpanFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamWaitNoTimeoutFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SuppressExtendedProtectionFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LogToFileFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SendOptionalMechlistMICFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AcceptUnsafeUnprotectedNegotiationFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = CrashOnAuditFailTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = NegEventMaskFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SPMInfoLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableCredManFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableDomainCredsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = HourlyLogLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AuthenticateAnonymousOnlineIDsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = TurnOffAnonymousBlockFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EveryoneIncludesAnonymousFalse1
Fn
Thread 0x1cc
(Host: 134, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = lspdbginfolevelFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = lspdbginfolevelFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = lspdbginfolevelFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = lspdbginfolevelFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Services\Tcpip\ParametersTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters, value_name = HostnameFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ComputerName, value_name = ComputerNameTrue1
Fn
MODLOADbase_address = 0x7ffb70fd0000True1
Fn
MODLOADmodule_name = msv1_0.dll, base_address = 0x0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70fe1120True1
Fn
DRVCONTROLcontrol_code = 0x110008False2
Fn
FILEREADsize = 1024True1
Fn
Data
DRVCONTROLcontrol_code = 0x110024True1
Fn
FILEWRITEsize = 116, offset = 0True1
Fn
Data
FILEREADsize = 1024True1
Fn
Data
DRVCONTROLcontrol_code = 0x11001cTrue1
Fn
FILEREADsize = 1024False1
Fn
DRVCONTROLcontrol_code = 0x11001cTrue4
Fn
FILEWRITEsize = 92, offset = 0True1
Fn
Data
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = lspdbginfolevelFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = KerbControlLevelFalse1
Fn
REGOPEN_KEYFalse2
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SupportedEncryptionTypesFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MaxTokenSizeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DHDomainParametersFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse2
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LookupLogLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsaLookupReturnSidTypeDeletedFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsaLookupRestrictIsolatedNameLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsarpcServerAllowRemotedSecretOperationsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsaLookupCacheRefreshTimeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsaLookupCacheExpireTimeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsaLookupCacheMaxSizeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsaAllowReturningUnencryptedSecretsFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = NoLmHashTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamReplicatePasswordsUrgentlyFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ForceGuestFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = LimitBlankPasswordUseTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamAccountLockoutTestModeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamDisableListenOnTCPFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = IgnoreGCFailuresFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamNoGcLogonEnforceKerberosIpCheckFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamNoGcLogonEnforceNTLMCheckFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamDisableSingleObjectReplFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamDisableRSOOnPDCForwardFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamDisableResetBadPwdCountForwardFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamConnectedAccountsExistFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamDisableOutboundRSOFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RestrictAnonymousFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RestrictAnonymousSamFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ExtendedSidEmulationModeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamLogSizeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamLogLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamRestrictOwfPasswordChangeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MaxSamConnectionsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = dsrmAdminLogonBehaviorFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamMaxQueueLengthForPDCForwardFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableClaimsTransformationEchoFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnumerationCachePurgeIntervalFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnumerationCacheEntryLifetimeFalse1
Fn
PROCOPEN_TOKENTrue2
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName, value_name = ComputerNameTrue1
Fn
PROCOPEN_TOKENTrue4
Fn
Thread 0x1d0
(Host: 122, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = lspdbginfolevelFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = KerbControlLevelFalse1
Fn
REGOPEN_KEYFalse2
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SupportedEncryptionTypesFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MaxTokenSizeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DHDomainParametersFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse2
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = lspdbginfolevelFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = KerbControlLevelFalse1
Fn
REGOPEN_KEYFalse2
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SupportedEncryptionTypesFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MaxTokenSizeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DHDomainParametersFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse2
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LookupLogLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsaLookupReturnSidTypeDeletedFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsaLookupRestrictIsolatedNameLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsarpcServerAllowRemotedSecretOperationsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsaLookupCacheRefreshTimeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsaLookupCacheExpireTimeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsaLookupCacheMaxSizeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LsaAllowReturningUnencryptedSecretsFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = NoLmHashTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamReplicatePasswordsUrgentlyFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ForceGuestFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = LimitBlankPasswordUseTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamAccountLockoutTestModeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamDisableListenOnTCPFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = IgnoreGCFailuresFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamNoGcLogonEnforceKerberosIpCheckFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamNoGcLogonEnforceNTLMCheckFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamDisableSingleObjectReplFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamDisableRSOOnPDCForwardFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamDisableResetBadPwdCountForwardFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamConnectedAccountsExistFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamDisableOutboundRSOFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RestrictAnonymousFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RestrictAnonymousSamFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ExtendedSidEmulationModeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamLogSizeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamLogLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamRestrictOwfPasswordChangeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MaxSamConnectionsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = dsrmAdminLogonBehaviorFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SamMaxQueueLengthForPDCForwardFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableClaimsTransformationEchoFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnumerationCachePurgeIntervalFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnumerationCacheEntryLifetimeFalse1
Fn
SVCOPEN_MGRdatabase_name = SERVICES_ACTIVE_DATABASE, host = LocalhostTrue1
Fn
SVCOPENTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEvalue_name = SQMServiceListTrue1
Fn
SVCGET_INFOtype = ConfigFalse1
Fn
SVCGET_INFOtype = ConfigTrue1
Fn
SVCGET_INFOtype = StatusTrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 460268828672 milliseconds (460268828.672 seconds)False1
Fn
SVCGET_INFOtype = StatusTrue1
Fn
DRVCONTROLcontrol_code = 0x110004True1
Fn
DRVCONTROLcontrol_code = 0x110008False1
Fn
REGREAD_VALUEvalue_name = Serial_Access_NumTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
Thread 0x1d4
(Host: 48, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = System\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\SystemTrue1
Fn
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = System\CurrentControlSet\Control\Lsa\Audit\AuditPolicyTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\Lsa\Audit\AuditPolicy, value_name = AuditPolicySDFalse1
Fn
PROCOPEN_TOKENTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb71595b30True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb715848b0True2
Fn
FILECREATEFalse1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\microsoft\protect\s-1-5-18\user\preferred, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_HIDDEN, FILE_ATTRIBUTE_SYSTEM, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEFalse1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\microsoft\protect\s-1-5-18\user\preferred, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_HIDDEN, FILE_ATTRIBUTE_SYSTEM, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0False1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x390008True1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb, value_name = MasterKeyIterationCountFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb, value_name = MasterKeyLegacyComplianceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb, value_name = MasterKeyLegacyNt4DomainFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb, value_name = DistributeBackupKeyFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb, value_name = ProtectionPolicyFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb, value_name = Recovery VersionFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb, value_name = Encr AlgFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb, value_name = Encr Alg Key SizeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb, value_name = MAC AlgFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = SOFTWARE\Microsoft\Cryptography\Protect\Providers\df9d8cd0-1501-11d1-8c7a-00c04fc297eb, value_name = MAC Alg Key SizeFalse1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb715848b0True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\microsoft\protect\s-1-5-18\user\968b739e-d207-46ed-a53d-aed260dbc1d6, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_HIDDEN, FILE_ATTRIBUTE_SYSTEM, create_disposition = FILE_OPEN_IF, ea_buffer = 0, ea_length = 0True1
Fn
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\microsoft\protect\s-1-5-18\user\968b739e-d207-46ed-a53d-aed260dbc1d6, size = 468True1
Fn
Data
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\microsoft\protect\s-1-5-18\user\preferred, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_HIDDEN, FILE_ATTRIBUTE_SYSTEM, create_disposition = FILE_OPEN_IF, ea_buffer = 0, ea_length = 0True1
Fn
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\microsoft\protect\s-1-5-18\user\preferred, size = 24True1
Fn
Data
MODGET_PROC_ADDRESSaddress_out = 0x7ffb715848b0True1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEreg_name = System\CurrentControlSet\Control\Lsa\Audit\AuditPolicy, value_name = AuditPolicySDTrue1
Fn
Data
Thread 0x1d8
(Host: 12, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
MODLOADbase_address = 0x7ffb70a40000True1
Fn
MODLOADmodule_name = dsrole.dll, base_address = 0x0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70a41550True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70a41530True1
Fn
FILECREATEfile_name = \device\namedpipe\lsarpc, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
FILEWRITEfile_name = \device\namedpipe\lsarpc, size = 160, offset = 0True1
Fn
Data
FILEREADfile_name = \device\namedpipe\lsarpc, size = 1024True1
Fn
Data
DRVCONTROLfile_name = \device\namedpipe\lsarpc, control_code = 0x11c017False1
Fn
PROCOPEN_TOKENTrue2
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName, value_name = ComputerNameTrue1
Fn
Thread 0x1dc
(Host: 2, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeTrue1
Fn
MODGET_HANDLEmodule_name = lsasrv.dllTrue1
Fn
Thread 0x1e0
(Host: 10, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectoryServiceExtPtFalse1
Fn
Thread 0x1e4
(Host: 2, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exeTrue1
Fn
MODGET_HANDLEmodule_name = samsrv.dllTrue1
Fn
Process #12: svchost.exe
(Host: 27926, Network: 0)
+
InformationValue
ID / OS PID#12 / 0x210
OS Parent PID0x1ac (c:\windows\system32\csrss.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exe
Command LineX:\windows\system32\svchost.exe -k DcomLaunch
MonitorStart Time: 00:01:47, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:20
OS Thread IDs
#92
0x214
#93
0x218
#94
0x21C
#95
0x220
#98
0x228
#99
0x22C
#100
0x230
#101
0x234
#106
0x24C
#109
0x258
#110
0x25C
#117
0x280
#119
0x284
#120
0x288
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x000000aee69800000xaee69800000xaee699ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000aee69800000xaee69800000xaee698ffffPagefile Backed FileReadable, WritableTrue
private_0x000000aee69900000xaee69900000xaee6996fffPrivate MemoryReadable, WritableTrue
pagefile_0x000000aee69a00000xaee69a00000xaee69aefffPagefile Backed FileReadableTrue
private_0x000000aee69b00000xaee69b00000xaee6a2ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000aee6a300000xaee6a300000xaee6a33fffPagefile Backed FileReadableTrue
pagefile_0x000000aee6a400000xaee6a400000xaee6a40fffPagefile Backed FileReadableTrue
private_0x000000aee6a500000xaee6a500000xaee6a51fffPrivate MemoryReadable, WritableTrue
locale.nls0xaee6a600000xaee6addfffMemory Mapped FileReadableFalse
private_0x000000aee6ae00000xaee6ae00000xaee6b5ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee6b600000xaee6b600000xaee6b66fffPrivate MemoryReadable, WritableTrue
private_0x000000aee6b700000xaee6b700000xaee6c6ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee6c700000xaee6c700000xaee6ceffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000aee6c700000xaee6c700000xaee6c70fffPagefile Backed FileReadable, WritableTrue
pagefile_0x000000aee6c800000xaee6c800000xaee6c80fffPagefile Backed FileReadableTrue
pagefile_0x000000aee6c900000xaee6c900000xaee6c90fffPagefile Backed FileReadable, WritableTrue
private_0x000000aee6ca00000xaee6ca00000xaee6caffffPrivate MemoryReadable, WritableTrue
private_0x000000aee6cb00000xaee6cb00000xaee6cb0fffPrivate MemoryReadable, WritableTrue
sortdefault.nls0xaee6cf00000xaee6fc4fffMemory Mapped FileReadableFalse
private_0x000000aee6fd00000xaee6fd00000xaee704ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee6fd00000xaee6fd00000xaee704ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee6fd00000xaee6fd00000xaee704ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee70900000xaee70900000xaee709ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee70a00000xaee70a00000xaee711ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee71200000xaee71200000xaee719ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee71a00000xaee71a00000xaee721ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee72200000xaee72200000xaee729ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee72a00000xaee72a00000xaee731ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee72a00000xaee72a00000xaee731ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee73200000xaee73200000xaee741ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee74200000xaee74200000xaee749ffffPrivate MemoryReadable, WritableTrue
private_0x000000aee75c00000xaee75c00000xaee75cffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007df5ffd400000x7df5ffd400000x7ff5ffd3ffffPagefile Backed File-True
private_0x00007ff7c97780000x7ff7c97780000x7ff7c9779fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c977a0000x7ff7c977a0000x7ff7c977bfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c977a0000x7ff7c977a0000x7ff7c977bfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c977c0000x7ff7c977c0000x7ff7c977dfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c977e0000x7ff7c977e0000x7ff7c977ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007ff7c97800000x7ff7c97800000x7ff7c987ffffPagefile Backed FileReadableTrue
pagefile_0x00007ff7c98800000x7ff7c98800000x7ff7c98a2fffPagefile Backed FileReadableTrue
private_0x00007ff7c98a40000x7ff7c98a40000x7ff7c98a5fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c98a60000x7ff7c98a60000x7ff7c98a6fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c98a80000x7ff7c98a80000x7ff7c98a9fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c98a80000x7ff7c98a80000x7ff7c98a9fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c98aa0000x7ff7c98aa0000x7ff7c98abfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c98aa0000x7ff7c98aa0000x7ff7c98abfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c98aa0000x7ff7c98aa0000x7ff7c98abfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c98ac0000x7ff7c98ac0000x7ff7c98adfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c98ae0000x7ff7c98ae0000x7ff7c98affffPrivate MemoryReadable, WritableTrue
svchost.exe0x7ff7ca8100000x7ff7ca81cfffMemory Mapped FileReadable, Writable, ExecutableFalse
DAB.dll0x7ffb701900000x7ffb701abfffMemory Mapped FileReadable, Writable, ExecutableFalse
SystemEventsBrokerServer.dll0x7ffb703000000x7ffb7034bfffMemory Mapped FileReadable, Writable, ExecutableFalse
DEVOBJ.dll0x7ffb705b00000x7ffb705d7fffMemory Mapped FileReadable, Writable, ExecutableFalse
pcwum.dll0x7ffb706000000x7ffb7060dfffMemory Mapped FileReadable, Writable, ExecutableFalse
WMsgAPI.dll0x7ffb706100000x7ffb70618fffMemory Mapped FileReadable, Writable, ExecutableFalse
SYSNTFY.dll0x7ffb706200000x7ffb7062bfffMemory Mapped FileReadable, Writable, ExecutableFalse
lsm.dll0x7ffb706300000x7ffb706f5fffMemory Mapped FileReadable, Writable, ExecutableFalse
rpcss.dll0x7ffb707400000x7ffb7080bfffMemory Mapped FileReadable, Writable, ExecutableFalse
umpo.dll0x7ffb708100000x7ffb70827fffMemory Mapped FileReadable, Writable, ExecutableFalse
umpnpmgr.dll0x7ffb708300000x7ffb70851fffMemory Mapped FileReadable, Writable, ExecutableFalse
USERENV.dll0x7ffb70dd00000x7ffb70df0fffMemory Mapped FileReadable, Writable, ExecutableFalse
SspiCli.dll0x7ffb715000000x7ffb7152dfffMemory Mapped FileReadable, Writable, ExecutableFalse
powrprof.dll0x7ffb715300000x7ffb71575fffMemory Mapped FileReadable, Writable, ExecutableFalse
bcryptPrimitives.dll0x7ffb715800000x7ffb715e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTBASE.dll0x7ffb715f00000x7ffb715fafffMemory Mapped FileReadable, Writable, ExecutableFalse
profapi.dll0x7ffb716b00000x7ffb716c4fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
CFGMGR32.dll0x7ffb718800000x7ffb718cefffMemory Mapped FileReadable, Writable, ExecutableTrue
sechost.dll0x7ffb733c00000x7ffb73418fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
combase.dll0x7ffb737400000x7ffb73950fffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSVCRT.dll0x7ffb740500000x7ffb740f9fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Injection Information
+
Injection TypeSource ProcessSource Os Thread IDInjection InfoSuccessAmountLogfile
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe0x1b0address = 0xaee6a50000, size = 4704True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe0x1b0address = 0x7ff7c98a62d8, size = 8True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Threads
Thread 0x214
(Host: 31, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
SYSGET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue2
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\VersionsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versions, value_name = 751193748928True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DcomLaunchTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DcomLaunchTrue1
Fn
REGOPEN_KEYFalse2
Fn
MODLOADmodule_name = rpcrt4.dll, base_address = 0x0True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
REGREAD_VALUEvalue_name = MaxRpcSizeFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = OOBEInProgressFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = SystemSetupInProgressTrue1
Fn
SYSGET_INFOTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEvalue_name = IdleTimerWindowFalse1
Fn
THREADCREATEprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, proc_address = 0x7ffb733c7ef0, desired_access = THREAD_ALL_ACCESSTrue2
Fn
THREADCREATEprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, proc_address = 0x7ffb733c7ef0, desired_access = THREAD_ALL_ACCESSTrue1
Fn
THREADCREATEprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, proc_address = 0x7ffb733c7ef0, desired_access = THREAD_ALL_ACCESSTrue1
Fn
THREADCREATEprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, proc_address = 0x7ffb733c7ef0, desired_access = THREAD_ALL_ACCESSTrue1
Fn
Thread 0x218
(Host: 1649, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
SVCOPENTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
SVCGET_INFOtype = StatusTrue1
Fn
PROCOPENTrue1
Fn
PROCOPENprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exe, os_pid = 0x238, desired_access = PROCESS_ALL_ACCESSTrue1
Fn
PROCOPEN_TOKENTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Global\RotHintTable, module_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exe, maximum_size = 751194992064, protection = PAGE_READWRITETrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exe, os_pid = 0x210, address = 0xaee6c90000True1
Fn
MODMAPmodule_name = Global\RotHintTable, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xaee6c90000True1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEmutex_name = Global\{A3BD3259-3E4F-428a-84C8-F0463A9D3EB5}, initial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
REGOPEN_KEYFalse1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Global\{A64C7F33-DA35-459b-96CA-63B51FB0CDB9}, module_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exe, maximum_size = 751194992320, protection = PAGE_READWRITETrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exe, os_pid = 0x210, address = 0xaee6cb0000True1
Fn
MODMAPmodule_name = Global\{A64C7F33-DA35-459b-96CA-63B51FB0CDB9}, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xaee6cb0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exe, os_pid = 0x210True1
Fn
PROCOPENprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCGET_INFOTrue1
Fn
PROCOPENprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCGET_INFOTrue1
Fn
PROCOPENprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCGET_INFOTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEvalue_name = GlassSessionId, data = 1True1
Fn
DRVCONTROLcontrol_code = 0x110008False1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DelayConMgrTimeoutTrue1
Fn
FILECREATEfile_name = \device\deviceapi\cmapi, desired_access = GENERIC_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470803True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True42
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x47081bTrue1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SystemSetupInProgressTrue1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPSrvFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPSrvFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPSrvLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPSrvToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
SVCOPEN_MGRdatabase_name = SERVICES_ACTIVE_DATABASE, host = LocalhostTrue1
Fn
SVCOPENFalse1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SystemSetupInProgressTrue1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPSrvFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPSrvFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPSrvLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPSrvToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
SVCOPEN_MGRdatabase_name = SERVICES_ACTIVE_DATABASE, host = LocalhostTrue1
Fn
SVCOPENFalse1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SystemSetupInProgressTrue1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
For performance reasons, the remaining 566 entries are omitted.
Click to download all 1566 entries as text file (0.46 MB).
Thread 0x21c
(Host: 43, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
REGOPEN_KEYreg_name = Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\InternationalFalse1
Fn
REGREAD_VALUEreg_name = Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\International, value_name = sCurrencyOverrideFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocaleTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocale, value_name = en-USFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocaleTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocale, value_name = en-USFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versions, value_name = 000602xxTrue1
Fn
MODLOADmodule_name = kernel32.dll, base_address = 0x0True1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xaee6cf0000True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\IdsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Ids, value_name = en-USFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Ids, value_name = enFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ServiceDllTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ServiceManifestFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ServiceMainTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ServiceMainTrue1
Fn
MODLOADbase_address = 0x7ffb70830000True1
Fn
MODLOADmodule_name = x:\windows\system32\umpnpmgr.dll, base_address = 0x0True1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb708390b0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb708310a0True1
Fn
SVCREGISTER_HANDLERTrue1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ServiceDllUnloadOnStopFalse1
Fn
Thread 0x220
(Host: 12645, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
REGREAD_VALUEreg_name = Control Panel\InternationalFalse1
Fn
REGREAD_VALUEreg_name = Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\International, value_name = sCurrencyOverrideFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ServiceDllTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ServiceManifestFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ServiceMainTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ServiceMainTrue1
Fn
MODLOADbase_address = 0x7ffb70810000True1
Fn
MODLOADmodule_name = x:\windows\system32\umpo.dll, base_address = 0x0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb708170f0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x0False1
Fn
SVCREGISTER_HANDLERTrue1
Fn
REGOPEN_KEYTrue2
Fn
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = System\CurrentControlSet\Control\Power\SecurityDescriptorsTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ActivePowerSchemeTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ActivePowerSchemeTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
For performance reasons, the remaining 10935 entries are omitted.
Click to download all 11935 entries as text file (3.18 MB).
Thread 0x228
(Host: 139, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
REGREAD_VALUEreg_name = Control Panel\InternationalFalse1
Fn
REGREAD_VALUEreg_name = Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\International, value_name = sCurrencyOverrideFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ServiceDllTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ServiceManifestFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ServiceMainFalse1
Fn
MODLOADbase_address = 0x7ffb70740000True1
Fn
MODLOADmodule_name = x:\windows\system32\rpcss.dllFalse1
Fn
REGREAD_VALUEvalue_name = PageAllocatorUseSystemHeapFalse1
Fn
REGREAD_VALUEvalue_name = PageAllocatorSystemHeapIsPrivateFalse1
Fn
REGREAD_VALUEvalue_name = AggressiveMTATestingFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODGET_HANDLEmodule_name = rpcrt4.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb7078a100True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x0False1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
SVCREGISTER_HANDLERTrue1
Fn
SVCOPEN_MGRdatabase_name = SERVICES_ACTIVE_DATABASE, host = LocalhostTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ActivationFailureLoggingLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CallFailureLoggingLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = InvalidSecurityDescriptorLoggingLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableActivationSecurityCheckFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = UseRunAsTokenCacheFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = IssueActivationRpcAtIdentifyFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ResumeTimeoutFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DoNotAddAllApplicationPackagesToRestrictionsFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DefaultLaunchPermissionTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DefaultLaunchPermissionTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MachineLaunchRestrictionFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MachineLaunchRestrictionFalse1
Fn
REGREAD_VALUEvalue_name = MachineLaunchRestrictionTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MachineAccessRestrictionFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MachineAccessRestrictionFalse1
Fn
REGREAD_VALUEvalue_name = MachineAccessRestrictionTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RemoteHandleCacheMaxSizeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RemoteHandleCacheMaxLifetimeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RemoteHandleCacheMaxIdleTimeoutFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = StaleMidTimeoutFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SRPRunningObjectChecksFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SRPActivateAsActivatorChecksFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableSystemDynamicIPTrackingFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableEELoggingFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LogEEInfoAsNativeFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODLOADbase_address = 0x7ffb71500000True1
Fn
MODLOADmodule_name = sspicli.dll, base_address = 0x0True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SecurityProvidersFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DCOM SecurityFalse1
Fn
REGOPEN_KEYTrue4
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = EnableDCOMTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = OleModalLoopBehaviorFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DCOMSCMRemoteCallFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = BreakOnUnexpectedActivationErrorsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableDCOMHTTPFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = IgnoreServerExceptionsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = BreakOnSilencedServerExceptionsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LegacyAuthenticationServiceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LegacyAuthenticationLevelFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = LegacyImpersonationLevelTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LegacyMutualAuthenticationFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LegacySecureReferencesFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MaxActivationRetriesPerServerFalse1
Fn
REGOPEN_KEYFalse1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Global\__ComCatalogCache__, module_name = sspicli.dll, maximum_size = 751200171792, protection = PAGE_READWRITETrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exe, os_pid = 0x210, address = 0xaee6c70000True1
Fn
MODMAPmodule_name = Global\__ComCatalogCache__, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xaee6c70000True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = REGDBVersionFalse1
Fn
REGOPEN_KEYTrue5
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ServiceDllUnloadOnStopFalse1
Fn
Thread 0x22c
(Host: 81, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableEELoggingFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LogEEInfoAsNativeFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ActivationFailureLoggingLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CallFailureLoggingLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = InvalidSecurityDescriptorLoggingLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableActivationSecurityCheckFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = UseRunAsTokenCacheFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = IssueActivationRpcAtIdentifyFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ResumeTimeoutFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DoNotAddAllApplicationPackagesToRestrictionsFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DefaultLaunchPermissionTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DefaultLaunchPermissionTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MachineLaunchRestrictionFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MachineLaunchRestrictionFalse1
Fn
REGREAD_VALUEvalue_name = MachineLaunchRestrictionTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MachineAccessRestrictionFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MachineAccessRestrictionFalse1
Fn
REGREAD_VALUEvalue_name = MachineAccessRestrictionTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DCOM SecurityFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = EnableDCOMTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = OleModalLoopBehaviorFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DCOMSCMRemoteCallFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = BreakOnUnexpectedActivationErrorsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableDCOMHTTPFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = IgnoreServerExceptionsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = BreakOnSilencedServerExceptionsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LegacyAuthenticationServiceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LegacyAuthenticationLevelFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = LegacyImpersonationLevelTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LegacyMutualAuthenticationFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LegacySecureReferencesFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MaxActivationRetriesPerServerFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DefaultLaunchPermissionTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DefaultLaunchPermissionTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MachineLaunchRestrictionFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MachineLaunchRestrictionFalse1
Fn
REGREAD_VALUEvalue_name = MachineLaunchRestrictionTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MachineAccessRestrictionFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MachineAccessRestrictionFalse1
Fn
REGREAD_VALUEvalue_name = MachineAccessRestrictionTrue1
Fn
Thread 0x230
(Host: 3, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = REGDBVersionFalse1
Fn
Thread 0x24c
(Host: 28, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
PROCOPENprocess_name = c:\windows\system32\wermgr.exe, os_pid = 0x16c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wermgr.exe, os_pid = 0x16c, desired_access = PROCESS_QUERY_LIMITED_INFORMATIONTrue1
Fn
PROCGET_INFOTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\5c9a4cd7-ba75-45d2-9898-1773b3d1e5f1False1
Fn
REGCREATE_KEYreg_name = SoftwareTrue1
Fn
REGCREATE_KEYreg_name = Software\MicrosoftTrue1
Fn
REGCREATE_KEYreg_name = Software\Microsoft\WindowsTrue1
Fn
REGCREATE_KEYreg_name = Software\Microsoft\Windows\CurrentVersionTrue1
Fn
REGCREATE_KEYreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggersTrue1
Fn
REGCREATE_KEYreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\TriggersTrue1
Fn
REGCREATE_KEYreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74dTrue1
Fn
REGCREATE_KEYreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\5c9a4cd7-ba75-45d2-9898-1773b3d1e5f1True1
Fn
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076True1
Fn
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86True1
Fn
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\9B008953-F195-4BF9-BDE0-4471971E58EDTrue1
Fn
PROCOPENprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe, os_pid = 0x1b4, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCGET_INFOreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74dTrue1
Fn
PROCOPENprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe, os_pid = 0x1b4, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCGET_INFOTrue1
Fn
PROCOPENprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wallpaperhost.exe, os_pid = 0x290, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCGET_INFOTrue1
Fn
PROCOPENprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wallpaperhost.exe, os_pid = 0x290, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCGET_INFOTrue1
Fn
Thread 0x258
(Host: 12640, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
PROCOPENprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, desired_access = PROCESS_QUERY_LIMITED_INFORMATIONTrue1
Fn
PROCGET_INFOTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ActivePowerSchemeTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ActivePowerSchemeTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\Power\SecurityDescriptors, value_name = ActivePowerSchemeFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\Power\SecurityDescriptors, value_name = DefaultFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\Power\SecurityDescriptors, value_name = ActivePowerSchemeFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\Power\SecurityDescriptors, value_name = DefaultFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\Power\SecurityDescriptors, value_name = DefaultFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Control\Power\SecurityDescriptors, value_name = DefaultTrue1
Fn
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemesTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ActivePowerScheme, data = 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635cTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ActivePowerSchemeTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ActivePowerSchemeTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ACSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = DCSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ACSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = DCSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\2EB08E3E-639F-4fba-97B1-14F878961076\Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d\b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86\System\CurrentControlSet\Control\Power\User\PowerSchemes, value_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ACSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = SettingValueTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = DCSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SettingValueTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ValueMinFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = Software\Microsoft\Windows\CurrentVersion\NetworkServiceTriggers\Triggers\bc90d167-9470-4139-a9ba-be0bbbf5b74d, value_name = ACSettingIndexTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMaxTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueIncrementTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ValueMinTrue1
Fn
For performance reasons, the remaining 10935 entries are omitted.
Click to download all 11935 entries as text file (5.10 MB).
Thread 0x25c
(Host: 632, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
REGREAD_VALUEreg_name = Control Panel\InternationalFalse1
Fn
REGREAD_VALUEreg_name = Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\International, value_name = sCurrencyOverrideFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ServiceDllTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ServiceManifestFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ServiceMainFalse1
Fn
MODLOADbase_address = 0x7ffb70630000True1
Fn
MODLOADmodule_name = x:\windows\system32\lsm.dll, base_address = 0x0True1
Fn
REGOPEN_KEYreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySideTrue1
Fn
REGREAD_VALUEreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide, value_name = PreferExternalManifestFalse1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsm.dll, desired_access = FILE_READ_DATA, FILE_READ_EA, FILE_READ_ATTRIBUTES, READ_CONTROL, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebuglsmToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtermsrvToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsdclientToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugwinstaToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugtsrpcToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse2
Fn
REGREAD_VALUEvalue_name = DebugsessionenvLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionenvToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugsessionmsgToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPSrvFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPSrvFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPSrvLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPSrvToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPSrvFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPSrvFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPSrvLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPSrvToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPCliToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPSrvFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CaptureStackTraceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPSrvFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPSrvLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSVIPSrvToDebuggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugToDebuggerFalse1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exeFalse1
Fn
MODGET_HANDLEmodule_name = advapi32.dllFalse1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exeTrue1
Fn
MODGET_HANDLEmodule_name = api-ms-win-eventing-provider-l1-1-0.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb741751c0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb7413b300True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb7413c360True1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exeTrue1
Fn
MODGET_HANDLEmodule_name = ntdll.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb7413b300True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb7413c360True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb74175650True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb741751c0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70672ee0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x0False1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = TSAppCompatFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DebugTSFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LSMBreakOnStartFalse1
Fn
SVCREGISTER_HANDLERTrue1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x390008True1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ConsoleSecurityFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ConsoleSecurityFalse1
Fn
REGREAD_VALUEvalue_name = ConsoleSecurityTrue1
Fn
PROCOPENTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x164, desired_access = SYNCHRONIZETrue1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x164, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCGET_INFOTrue1
Fn
PROCOPENTrue1
Fn
PROCOPENprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, desired_access = PROCESS_QUERY_LIMITED_INFORMATION, SYNCHRONIZETrue1
Fn
PROCGET_INFOTrue2
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ConsoleSecurityFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ConsoleSecurityFalse1
Fn
REGREAD_VALUEvalue_name = ConsoleSecurityTrue1
Fn
PROCOPENTrue1
Fn
PROCOPENprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe, os_pid = 0x194, desired_access = SYNCHRONIZETrue1
Fn
PROCOPENprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCGET_INFOTrue1
Fn
PROCOPENTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wermgr.exe, os_pid = 0x16c, desired_access = PROCESS_QUERY_LIMITED_INFORMATION, SYNCHRONIZETrue1
Fn
PROCGET_INFOTrue2
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LSMGlobalSettingFalse1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEvalue_name = InstanceID, data = 4b2993a7-bd9a-4070-9e94-6969c10True1
Fn
REGREAD_VALUEvalue_name = 9True1
Fn
MODLOADmodule_name = sspicli.dll, base_address = 0x0True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DelayReadyEventTimeoutFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
MODLOADbase_address = 0x7ffb70dd0000True1
Fn
MODLOADmodule_name = X:\windows\System32\Userenv.dll, base_address = 0x0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70dd1d60True1
Fn
REGOPEN_KEYTrue1
Fn
REGWRITE_VALUETrue1
Fn
REGWRITE_VALUEvalue_name = WinStationsDisabled, data = 0True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = TSServerDrainModeFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ServiceDllUnloadOnStopFalse1
Fn
Thread 0x280
(Host: 33, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
REGREAD_VALUEreg_name = Control Panel\InternationalFalse1
Fn
REGREAD_VALUEreg_name = Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\International, value_name = sCurrencyOverrideFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ServiceDllTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ServiceManifestFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ServiceMainFalse1
Fn
MODLOADbase_address = 0x7ffb70300000True1
Fn
MODLOADmodule_name = x:\windows\system32\systemeventsbrokerserver.dll, base_address = 0x0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb7030f080True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb7030ed50True1
Fn
SVCREGISTER_HANDLERTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = NoParamValidationFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RegisterPrivateEnabledFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_TIME_OF_DAY_INFORMATIONTrue1
Fn
THREADCREATEprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, proc_address = 0x7ffb701a1e00, desired_access = THREAD_ALL_ACCESSTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGDELETE_TREETrue1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ServiceDllUnloadOnStopTrue1
Fn
Thread 0x288
(Host: 2, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
SYSSLEEPFalse1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)False1
Fn
Process #13: svchost.exe
(Host: 310, Network: 0)
+
InformationValue
ID / OS PID#13 / 0x238
OS Parent PID0x1ac (c:\windows\system32\csrss.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exe
Command LineX:\windows\system32\svchost.exe -k RPCSS
MonitorStart Time: 00:01:52, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:15
OS Thread IDs
#102
0x23C
#103
0x240
#104
0x244
#105
0x248
#107
0x250
#108
0x254
#112
0x264
#129
0x2C0
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x000000f0520000000xf0520000000xf05201ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000f0520000000xf0520000000xf05200ffffPagefile Backed FileReadable, WritableTrue
private_0x000000f0520100000xf0520100000xf052016fffPrivate MemoryReadable, WritableTrue
pagefile_0x000000f0520200000xf0520200000xf05202efffPagefile Backed FileReadableTrue
private_0x000000f0520300000xf0520300000xf0520affffPrivate MemoryReadable, WritableTrue
pagefile_0x000000f0520b00000xf0520b00000xf0520b3fffPagefile Backed FileReadableTrue
pagefile_0x000000f0520c00000xf0520c00000xf0520c0fffPagefile Backed FileReadableTrue
private_0x000000f0520d00000xf0520d00000xf0520d1fffPrivate MemoryReadable, WritableTrue
locale.nls0xf0520e00000xf05215dfffMemory Mapped FileReadableFalse
private_0x000000f0521600000xf0521600000xf05225ffffPrivate MemoryReadable, WritableTrue
private_0x000000f0522600000xf0522600000xf0522dffffPrivate MemoryReadable, WritableTrue
private_0x000000f0522e00000xf0522e00000xf05235ffffPrivate MemoryReadable, WritableTrue
private_0x000000f0522e00000xf0522e00000xf0522e6fffPrivate MemoryReadable, WritableTrue
sortdefault.nls0xf0523600000xf052634fffMemory Mapped FileReadableFalse
private_0x000000f0526400000xf0526400000xf0526bffffPrivate MemoryReadable, WritableTrue
private_0x000000f0526c00000xf0526c00000xf05273ffffPrivate MemoryReadable, WritableTrue
private_0x000000f0527c00000xf0527c00000xf0527cffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007df5ffd300000x7df5ffd300000x7ff5ffd2ffffPagefile Backed File-True
pagefile_0x00007ff7ca1e00000x7ff7ca1e00000x7ff7ca2dffffPagefile Backed FileReadableTrue
pagefile_0x00007ff7ca2e00000x7ff7ca2e00000x7ff7ca302fffPagefile Backed FileReadableTrue
private_0x00007ff7ca3030000x7ff7ca3030000x7ff7ca303fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7ca3080000x7ff7ca3080000x7ff7ca309fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7ca30a0000x7ff7ca30a0000x7ff7ca30bfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7ca30a0000x7ff7ca30a0000x7ff7ca30bfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7ca30c0000x7ff7ca30c0000x7ff7ca30dfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7ca30e0000x7ff7ca30e0000x7ff7ca30ffffPrivate MemoryReadable, WritableTrue
svchost.exe0x7ff7ca8100000x7ff7ca81cfffMemory Mapped FileReadable, Writable, ExecutableFalse
RpcRtRemote.dll0x7ffb707000000x7ffb70712fffMemory Mapped FileReadable, Writable, ExecutableFalse
RpcEpMap.dll0x7ffb707200000x7ffb70735fffMemory Mapped FileReadable, Writable, ExecutableFalse
rpcss.dll0x7ffb707400000x7ffb7080bfffMemory Mapped FileReadable, Writable, ExecutableFalse
rsaenh.dll0x7ffb70b000000x7ffb70b35fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTSP.dll0x7ffb710400000x7ffb7105ffffMemory Mapped FileReadable, Writable, ExecutableFalse
bcrypt.dll0x7ffb712600000x7ffb71285fffMemory Mapped FileReadable, Writable, ExecutableFalse
SspiCli.dll0x7ffb715000000x7ffb7152dfffMemory Mapped FileReadable, Writable, ExecutableFalse
powrprof.dll0x7ffb715300000x7ffb71575fffMemory Mapped FileReadable, Writable, ExecutableFalse
bcryptPrimitives.dll0x7ffb715800000x7ffb715e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTBASE.dll0x7ffb715f00000x7ffb715fafffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
WS2_32.dll0x7ffb733600000x7ffb733b9fffMemory Mapped FileReadable, Writable, ExecutableTrue
sechost.dll0x7ffb733c00000x7ffb73418fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
combase.dll0x7ffb737400000x7ffb73950fffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
NSI.dll0x7ffb73e800000x7ffb73e88fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSVCRT.dll0x7ffb740500000x7ffb740f9fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Injection Information
+
Injection TypeSource ProcessSource Os Thread IDInjection InfoSuccessAmountLogfile
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe0x1b0address = 0xf0520d0000, size = 4704True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe0x1b0address = 0x7ff7ca3032d8, size = 8True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1ccNo corresponding api call detected. Probably injected code via shellcode.True1
Threads
Thread 0x23c
(Host: 28, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
SYSGET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue2
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\VersionsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versions, value_name = 1032168601360True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = RPCSSTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = RPCSSTrue1
Fn
REGOPEN_KEYFalse2
Fn
MODLOADmodule_name = rpcrt4.dll, base_address = 0x0True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
REGREAD_VALUEvalue_name = MaxRpcSizeFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = OOBEInProgressFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = SystemSetupInProgressTrue1
Fn
SYSGET_INFOTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEvalue_name = IdleTimerWindowFalse1
Fn
THREADCREATEprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, proc_address = 0x7ffb733c7ef0, desired_access = THREAD_ALL_ACCESSTrue1
Fn
THREADCREATEprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, proc_address = 0x7ffb733c7ef0, desired_access = THREAD_ALL_ACCESSTrue1
Fn
Thread 0x240
(Host: 4, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
DRVCONTROLcontrol_code = 0x110004True1
Fn
DRVCONTROLcontrol_code = 0x110008False2
Fn
REGOPEN_KEYFalse1
Fn
Thread 0x244
(Host: 71, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
REGOPEN_KEYreg_name = Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\InternationalFalse1
Fn
REGREAD_VALUEreg_name = Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\International, value_name = sCurrencyOverrideFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocaleTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocale, value_name = en-USFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocaleTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocale, value_name = en-USFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versions, value_name = 000602xxTrue1
Fn
MODLOADmodule_name = kernel32.dll, base_address = 0x0True1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xf052360000True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\IdsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Ids, value_name = en-USFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Ids, value_name = enFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ServiceDllTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ServiceManifestFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ServiceMainFalse1
Fn
MODLOADbase_address = 0x7ffb70720000True1
Fn
MODLOADmodule_name = x:\windows\system32\rpcepmap.dll, base_address = 0x0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70727e90True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x0False1
Fn
SVCREGISTER_HANDLERTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ListenOnInternetFalse1
Fn
REGOPEN_KEYFalse1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ndis, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLfile_name = \device\ndis, control_code = 0x170010True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName, value_name = ComputerNameTrue1
Fn
SYSGET_INFOTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = c:\, desired_access = SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_FREE_SPACE_QUERYTrue1
Fn
REGREAD_VALUEvalue_name = 9True1
Fn
MODLOADmodule_name = sspicli.dll, base_address = 0x0True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODLOADbase_address = 0x7ffb71500000True1
Fn
MODLOADmodule_name = sspicli.dll, base_address = 0x0True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SecurityProvidersFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = RemoteRpcDllTrue1
Fn
MODLOADbase_address = 0x7ffb70700000True1
Fn
MODLOADmodule_name = RpcRtRemote.dll, base_address = 0x0True1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exeTrue1
Fn
MODGET_HANDLEmodule_name = rpcrt4.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb73ab8f70True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb73ab9000True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb73b07230True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70701860True1
Fn
REGOPEN_KEYTrue4
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ServiceDllUnloadOnStopFalse1
Fn
Thread 0x248
(Host: 207, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
REGREAD_VALUEreg_name = Control Panel\InternationalFalse1
Fn
REGREAD_VALUEreg_name = Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\International, value_name = sCurrencyOverrideFalse1
Fn
REGOPEN_KEYTrue3
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ServiceDllTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ServiceManifestFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ServiceMainFalse1
Fn
MODLOADbase_address = 0x7ffb70740000True1
Fn
MODLOADmodule_name = x:\windows\system32\rpcss.dll, base_address = 0x0True1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = PageAllocatorUseSystemHeapFalse1
Fn
REGREAD_VALUEvalue_name = PageAllocatorSystemHeapIsPrivateFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = AggressiveMTATestingFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODGET_HANDLEmodule_name = rpcrt4.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb7078a100True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x0False1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
SVCREGISTER_HANDLERTrue1
Fn
SVCOPEN_MGRdatabase_name = SERVICES_ACTIVE_DATABASE, host = LocalhostTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ActivationFailureLoggingLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CallFailureLoggingLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = InvalidSecurityDescriptorLoggingLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableActivationSecurityCheckFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = UseRunAsTokenCacheFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = IssueActivationRpcAtIdentifyFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ResumeTimeoutFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DoNotAddAllApplicationPackagesToRestrictionsFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DefaultLaunchPermissionTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DefaultLaunchPermissionTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MachineLaunchRestrictionFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MachineLaunchRestrictionFalse1
Fn
REGREAD_VALUEvalue_name = MachineLaunchRestrictionTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MachineAccessRestrictionFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MachineAccessRestrictionFalse1
Fn
REGREAD_VALUEvalue_name = MachineAccessRestrictionTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RemoteHandleCacheMaxSizeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RemoteHandleCacheMaxLifetimeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RemoteHandleCacheMaxIdleTimeoutFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = StaleMidTimeoutFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SRPRunningObjectChecksFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SRPActivateAsActivatorChecksFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableSystemDynamicIPTrackingFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableEELoggingFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LogEEInfoAsNativeFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DCOM SecurityFalse1
Fn
REGOPEN_KEYTrue4
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = EnableDCOMTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = OleModalLoopBehaviorFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DCOMSCMRemoteCallFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = BreakOnUnexpectedActivationErrorsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableDCOMHTTPFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = IgnoreServerExceptionsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = BreakOnSilencedServerExceptionsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LegacyAuthenticationServiceFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LegacyAuthenticationLevelFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = LegacyImpersonationLevelTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LegacyMutualAuthenticationFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = LegacySecureReferencesFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = PingIntervalFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = UserPingSetQuotaFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MaxActivationRetriesPerServerFalse1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = TypeTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = Image PathTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = Image PathTrue2
Fn
MODLOADbase_address = 0x7ffb70b00000True1
Fn
MODLOADmodule_name = X:\windows\system32\rsaenh.dll, base_address = 0x0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b01570True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b01080True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b06090True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b1e1d0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b02ce0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b0af70True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b03880True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b03a30True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b03260True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b06be0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b04ea0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b027d0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b02b00True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b1d8d0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b024f0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b06830True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b03c50True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b01030True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b05bb0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b0f290True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b0f750True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b03f50True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b02630True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b0d330True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb70b1d6e0True1
Fn
REGOPEN_KEYFalse1
Fn
PROCOPEN_TOKENTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MachineGuidTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MachineGuidTrue2
Fn
REGOPEN_KEYFalse1
Fn
PROCOPEN_TOKENTrue1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x390008True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DCOM ProtocolsTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName, value_name = ComputerNameTrue1
Fn
REGREAD_VALUEvalue_name = WinSock_Registry_VersionTrue2
Fn
REGREAD_VALUEvalue_name = NameSpace_CalloutTrue2
Fn
REGREAD_VALUEvalue_name = Serial_Access_NumTrue2
Fn
REGREAD_VALUEvalue_name = Next_Catalog_Entry_IDTrue1
Fn
REGREAD_VALUEvalue_name = Num_Catalog_Entries64True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEvalue_name = Serial_Access_NumTrue2
Fn
REGREAD_VALUEvalue_name = Num_Catalog_Entries64True1
Fn
REGREAD_VALUEvalue_name = LibraryPathTrue2
Fn
REGREAD_VALUEvalue_name = DisplayStringTrue4
Fn
REGREAD_VALUEvalue_name = ProviderIdTrue1
Fn
REGREAD_VALUEvalue_name = AddressFamilyFalse1
Fn
REGREAD_VALUEvalue_name = SupportedNameSpaceTrue1
Fn
REGREAD_VALUEvalue_name = EnabledTrue1
Fn
REGREAD_VALUEvalue_name = VersionTrue1
Fn
REGREAD_VALUEvalue_name = StoresServiceClassInfoTrue1
Fn
REGREAD_VALUEvalue_name = ProviderInfoTrue2
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEvalue_name = Ws2_32NumHandleBucketsFalse1
Fn
PROCOPEN_TOKENTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGCREATE_KEYreg_name = \REGISTRY\MACHINE\SOFTWARE\CLASSESTrue1
Fn
Process #14: winpeshl.exe
(Host: 641, Network: 0)
+
InformationValue
ID / OS PID#14 / 0x278
OS Parent PID0x194 (\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe
Command Linewinpeshl.exe
MonitorStart Time: 00:01:54, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:13
OS Thread IDs
#116
0x27C
#121
0x28C
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x000000a3b7c800000xa3b7c800000xa3b7c9ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000a3b7c800000xa3b7c800000xa3b7c8ffffPagefile Backed FileReadable, WritableTrue
private_0x000000a3b7c900000xa3b7c900000xa3b7c96fffPrivate MemoryReadable, WritableTrue
pagefile_0x000000a3b7ca00000xa3b7ca00000xa3b7caefffPagefile Backed FileReadableTrue
private_0x000000a3b7cb00000xa3b7cb00000xa3b7d2ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000a3b7d300000xa3b7d300000xa3b7d33fffPagefile Backed FileReadableTrue
private_0x000000a3b7d400000xa3b7d400000xa3b7d41fffPrivate MemoryReadable, WritableTrue
pagefile_0x000000a3b7d500000xa3b7d500000xa3b7d51fffPagefile Backed FileReadableTrue
private_0x000000a3b7d600000xa3b7d600000xa3b7e5ffffPrivate MemoryReadable, WritableTrue
locale.nls0xa3b7e600000xa3b7eddfffMemory Mapped FileReadableFalse
private_0x000000a3b7ee00000xa3b7ee00000xa3b7ee6fffPrivate MemoryReadable, WritableTrue
winpeshl.exe.mui0xa3b7ef00000xa3b7ef0fffMemory Mapped FileReadableFalse
private_0x000000a3b7f000000xa3b7f000000xa3b7f00fffPrivate MemoryReadable, WritableTrue
private_0x000000a3b7f100000xa3b7f100000xa3b7f10fffPrivate MemoryReadable, WritableTrue
SETUPAPI.dll.mui0xa3b7f200000xa3b7f2bfffMemory Mapped FileReadableFalse
newdev.dll.mui0xa3b7f300000xa3b7f36fffMemory Mapped FileReadableFalse
private_0x000000a3b7f900000xa3b7f900000xa3b7f9ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000a3b7fa00000xa3b7fa00000xa3b8127fffPagefile Backed FileReadableTrue
pagefile_0x000000a3b81300000xa3b81300000xa3b82b0fffPagefile Backed FileReadableTrue
pagefile_0x000000a3b82c00000xa3b82c00000xa3b96bffffPagefile Backed FileReadableTrue
private_0x000000a3b96c00000xa3b96c00000xa3b973ffffPrivate MemoryReadable, WritableTrue
private_0x000000a3b98700000xa3b98700000xa3b987ffffPrivate MemoryReadable, WritableTrue
sortdefault.nls0xa3b98800000xa3b9b54fffMemory Mapped FileReadableFalse
pagefile_0x00007ff74d7a00000x7ff74d7a00000x7ff74d89ffffPagefile Backed FileReadableTrue
pagefile_0x00007ff74d8a00000x7ff74d8a00000x7ff74d8c2fffPagefile Backed FileReadableTrue
private_0x00007ff74d8ca0000x7ff74d8ca0000x7ff74d8cafffPrivate MemoryReadable, WritableTrue
private_0x00007ff74d8cc0000x7ff74d8cc0000x7ff74d8cdfffPrivate MemoryReadable, WritableTrue
private_0x00007ff74d8ce0000x7ff74d8ce0000x7ff74d8cffffPrivate MemoryReadable, WritableTrue
winpeshl.exe0x7ff74e4100000x7ff74e498fffMemory Mapped FileReadable, Writable, ExecutableFalse
drvstore.dll0x7ffb6fe500000x7ffb6ff0afffMemory Mapped FileReadable, Writable, ExecutableFalse
SHCORE.DLL0x7ffb701b00000x7ffb70261fffMemory Mapped FileReadable, Writable, ExecutableFalse
MPR.dll0x7ffb702700000x7ffb7028dfffMemory Mapped FileReadable, Writable, ExecutableFalse
wkscli.dll0x7ffb702900000x7ffb702a6fffMemory Mapped FileReadable, Writable, ExecutableFalse
WpeUtil.dll0x7ffb702b00000x7ffb702cefffMemory Mapped FileReadable, Writable, ExecutableFalse
devrtl.DLL0x7ffb702d00000x7ffb702e5fffMemory Mapped FileReadable, Writable, ExecutableFalse
WINNSI.DLL0x7ffb702f00000x7ffb702f9fffMemory Mapped FileReadable, Writable, ExecutableFalse
FLTLIB.DLL0x7ffb703500000x7ffb70359fffMemory Mapped FileReadable, Writable, ExecutableFalse
UNATTEND.DLL0x7ffb703600000x7ffb7039ffffMemory Mapped FileReadable, Writable, ExecutableFalse
Input.dll0x7ffb703a00000x7ffb703e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
newdev.dll0x7ffb703f00000x7ffb70445fffMemory Mapped FileReadable, Writable, ExecutableFalse
IPHLPAPI.DLL0x7ffb704500000x7ffb70479fffMemory Mapped FileReadable, Writable, ExecutableFalse
UxTheme.dll0x7ffb704800000x7ffb705a8fffMemory Mapped FileReadable, Writable, ExecutableFalse
DEVOBJ.dll0x7ffb705b00000x7ffb705d7fffMemory Mapped FileReadable, Writable, ExecutableFalse
spinf.dll0x7ffb709a00000x7ffb709bdfffMemory Mapped FileReadable, Writable, ExecutableFalse
USERENV.dll0x7ffb70dd00000x7ffb70df0fffMemory Mapped FileReadable, Writable, ExecutableFalse
DNSAPI.dll0x7ffb70e400000x7ffb70ee3fffMemory Mapped FileReadable, Writable, ExecutableFalse
profapi.dll0x7ffb716b00000x7ffb716c4fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
CFGMGR32.dll0x7ffb718800000x7ffb718cefffMemory Mapped FileReadable, Writable, ExecutableTrue
Setupapi.dll0x7ffb718d00000x7ffb71aa9fffMemory Mapped FileReadable, Writable, ExecutableTrue
gdi32.dll0x7ffb71ad00000x7ffb71c20fffMemory Mapped FileReadable, Writable, ExecutableTrue
SHELL32.dll0x7ffb71c300000x7ffb73148fffMemory Mapped FileReadable, Writable, ExecutableTrue
SHLWAPI.dll0x7ffb733000000x7ffb73353fffMemory Mapped FileReadable, Writable, ExecutableTrue
WS2_32.dll0x7ffb733600000x7ffb733b9fffMemory Mapped FileReadable, Writable, ExecutableTrue
sechost.dll0x7ffb733c00000x7ffb73418fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
OLEAUT32.dll0x7ffb735c00000x7ffb73680fffMemory Mapped FileReadable, Writable, ExecutableTrue
advapi32.dll0x7ffb736900000x7ffb73739fffMemory Mapped FileReadable, Writable, ExecutableTrue
combase.dll0x7ffb737400000x7ffb73950fffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSCTF.dll0x7ffb73b800000x7ffb73cd2fffMemory Mapped FileReadable, Writable, ExecutableTrue
ole32.dll0x7ffb73ce00000x7ffb73e73fffMemory Mapped FileReadable, Writable, ExecutableTrue
NSI.dll0x7ffb73e800000x7ffb73e88fffMemory Mapped FileReadable, Writable, ExecutableTrue
user32.dll0x7ffb73e900000x7ffb74006fffMemory Mapped FileReadable, Writable, ExecutableTrue
IMM32.dll0x7ffb740100000x7ffb74045fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSVCRT.dll0x7ffb740500000x7ffb740f9fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Injection Information
+
Injection TypeSource ProcessSource Os Thread IDInjection InfoSuccessAmountLogfile
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8address = 0xd9cbf50000, size = 16384True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe0x198address = 0xa3b7d40000, size = 4704True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe0x198address = 0x7ff74d8ca2d8, size = 8True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8address = 0xd9cbf60000, size = 8192True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8No corresponding api call detected. Probably injected code via shellcode.True1
Threads
Thread 0x27c
(Host: 164, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
SYSGET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue2
Fn
REGOPEN_KEYreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySideTrue1
Fn
REGREAD_VALUEreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide, value_name = PreferExternalManifestFalse1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\newdev.dll, desired_access = FILE_READ_DATA, FILE_READ_EA, FILE_READ_ATTRIBUTES, READ_CONTROL, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\VersionsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versions, value_name = 703163720896True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
MODGET_HANDLEmodule_name = X:\windows\system32\IMM32.DLLTrue2
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Error Message Instrument\False1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_InitializeTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize, value_name = DisableMetaFilesFalse1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEvalue_name = LoadAppInit_DLLsTrue1
Fn
REGREAD_VALUEvalue_name = PageAllocatorUseSystemHeapFalse1
Fn
REGREAD_VALUEvalue_name = PageAllocatorSystemHeapIsPrivateFalse1
Fn
REGREAD_VALUEvalue_name = AggressiveMTATestingFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODGET_HANDLEmodule_name = rpcrt4.dllTrue1
Fn
REGOPEN_KEYTrue1
Fn
FILECREATEfile_name = \device\deviceapi\cmapi, desired_access = GENERIC_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR, value_name = DisableTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR, value_name = SourcePathFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR, value_name = DevicePathTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocaleTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocale, value_name = en-USFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocaleTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocale, value_name = en-USFalse1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue2
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SystemSetupInProgressTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODGET_HANDLEmodule_name = X:\windows\system32\oleaut32.dllTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODGET_HANDLEmodule_name = ext-ms-win-ole32-oleautomation-l1-1-0.dllTrue1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exeTrue1
Fn
MODGET_HANDLEmodule_name = advapi32.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb741751c0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb7413b300True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb7413c360True1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exeTrue1
Fn
MODGET_HANDLEmodule_name = ntdll.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb7413b300True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb7413c360True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb74175650True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb741751c0True1
Fn
REGOPEN_KEYTrue1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exeTrue1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN_IF, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 2True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 50True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 20True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 72True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 4True1
Fn
Data
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = InstRootTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = InstRootTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableExtraFontsFalse1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True2
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = CustomBackgroundTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = CustomBackgroundTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = CustomBackgroundTrue1
Fn
THREADCREATEprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, proc_address = 0x7ff74e412780, desired_access = THREAD_ALL_ACCESSTrue1
Fn
PROCCREATEprocess_name = True1
Fn
PROCCREATEprocess_name = , desired_access = MAXIMUM_ALLOWED, creation_flags = CREATE_NEW_PROCESS_GROUPTrue1
Fn
REGOPEN_KEYreg_name = \Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDllsFalse1
Fn
REGOPEN_KEYreg_name = \Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\OptionFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = 140717948767312False1
Fn
PROCGET_INFOprocess_name = True1
Fn
REGOPEN_KEYreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySideTrue1
Fn
REGREAD_VALUEreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide, value_name = PreferExternalManifestFalse1
Fn
MEMALLOCaddress = 0xa3b7d2f2e8, process_name = , size = 703163724872, allocation_type = MEM_COMMIT, protection = PAGE_READWRITETrue1
Fn
MEMWRITEaddress = 0x6356410000, process_name = , size = 4704True1
Fn
Data
MEMWRITEaddress = 0x7ff618a9a2d8, process_name = , size = 8True1
Fn
Data
THREADRESUMETrue1
Fn
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 50True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 20True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 246True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 4True1
Fn
Data
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exeTrue1
Fn
MODGET_HANDLEmodule_name = kernel32.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb73483210True1
Fn
MODLOADbase_address = 0x7ffb73e90000True1
Fn
MODLOADmodule_name = user32.dll, base_address = 0x0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb73e91700True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb73e91b00True1
Fn
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 50True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 20True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 44True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 4True1
Fn
Data
INIREADfile_name = Win.iniTrue1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.ini, desired_access = SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
FILEREADfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.ini, size = 53True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 50True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 20True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 110True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 4True1
Fn
Data
PROCCREATEprocess_name = True1
Fn
PROCCREATEprocess_name = , desired_access = MAXIMUM_ALLOWED, creation_flags = CREATE_NEW_PROCESS_GROUPTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = ShimEnableFalse1
Fn
PROCGET_INFOprocess_name = True1
Fn
REGOPEN_KEYreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySideTrue1
Fn
REGREAD_VALUEreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide, value_name = PreferExternalManifestFalse1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xa3b9740000False1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, base_address = 0xa3b9740000True1
Fn
MEMALLOCaddress = 0xa3b7d2f2b8, process_name = , size = 703163724824, allocation_type = MEM_COMMIT, protection = PAGE_READWRITETrue1
Fn
MEMWRITEaddress = 0xe5e5420000, process_name = , size = 4704True1
Fn
Data
MEMWRITEaddress = 0x7ff72999c2d8, process_name = , size = 8True1
Fn
Data
THREADRESUMETrue1
Fn
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 50True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 20True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 170True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 4True1
Fn
Data
Thread 0x28c
(Host: 477, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 50True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 20True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 58True1
Fn
Data
FILEWRITETrue1
Fn
FILEWRITEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.log, size = 4True1
Fn
Data
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableRemovableStorageInitFalse1
Fn
MODLOADbase_address = 0x7ffb74120000True1
Fn
MODLOADmodule_name = ntdll.dll, base_address = 0x0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb74190030True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb741e0720True1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINETrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINE\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \REGISTRY\MACHINE\System\Setup, value_name = SystemSetupInProgressTrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINETrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Control\MiniNTTrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINETrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\SetupTrue1
Fn
REGREAD_VALUEreg_name = \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Setup, value_name = MinimizeFootprintTrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINETrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINE\Software\Microsoft\EmbeddedNT\SecurityFalse1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470803True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True2
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINETrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\SetupTrue1
Fn
REGREAD_VALUEreg_name = \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Setup, value_name = LogLevelTrue1
Fn
REGREAD_VALUEreg_name = \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Setup, value_name = LogMaskFalse1
Fn
REGREAD_VALUEreg_name = \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Setup, value_name = LogMaxFileSizeFalse1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
MUTEXRELEASETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versions, value_name = 000602xxTrue1
Fn
MODLOADmodule_name = kernel32.dll, base_address = 0x0True1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xa3b9880000True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\IdsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Ids, value_name = en-USFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Ids, value_name = enFalse1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINETrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\DeviceInstallFalse1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\InternationalFalse1
Fn
REGREAD_VALUEreg_name = Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\International, value_name = sCurrencyOverrideFalse1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x47086bTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\apps.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\apps.inf, maximum_size = 703191041456, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe, os_pid = 0x278, address = 0xa3b7f40000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xa3b7f40000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe, os_pid = 0x278True1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x47086bTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\defltbase.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\defltbase.inf, maximum_size = 703191041456, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe, os_pid = 0x278, address = 0xa3b7f40000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xa3b7f40000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe, os_pid = 0x278True1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
Process #15: winlogon.exe
+
InformationValue
ID / OS PID#15 / 0x26c
OS Parent PID0x194 (\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winlogon.exe
Command Linewinlogon.exe
MonitorStart Time: 00:01:54, Reason: Child Process
UnmonitorEnd Time: 00:01:54, Reason: Terminated
Monitor Duration00:00:00
OS Thread IDs
RemarksNo high level activity detected in monitored regions
Process #16: wallpaperhost.exe
(Host: 1938, Network: 0)
+
InformationValue
ID / OS PID#16 / 0x290
OS Parent PID0x278 (\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wallpaperhost.exe
Command LineX:\windows\system32\WallpaperHost.exe
MonitorStart Time: 00:01:55, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:12
OS Thread IDs
#122
0x294
#124
0x2A0
#125
0x2A4
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x00000063563400000x63563400000x635635ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000063563400000x63563400000x635634ffffPagefile Backed FileReadable, WritableTrue
private_0x00000063563500000x63563500000x6356356fffPrivate MemoryReadable, WritableTrue
pagefile_0x00000063563600000x63563600000x635636efffPagefile Backed FileReadableTrue
private_0x00000063563700000x63563700000x63563effffPrivate MemoryReadable, WritableTrue
pagefile_0x00000063563f00000x63563f00000x63563f3fffPagefile Backed FileReadableTrue
pagefile_0x00000063564000000x63564000000x6356402fffPagefile Backed FileReadableTrue
private_0x00000063564100000x63564100000x6356411fffPrivate MemoryReadable, WritableTrue
locale.nls0x63564200000x635649dfffMemory Mapped FileReadableFalse
private_0x00000063564a00000x63564a00000x63564affffPrivate MemoryReadable, WritableTrue
private_0x00000063564b00000x63564b00000x63564b6fffPrivate MemoryReadable, WritableTrue
private_0x00000063564c00000x63564c00000x63564c0fffPrivate MemoryReadable, WritableTrue
private_0x00000063564c00000x63564c00000x63564c0fffPrivate MemoryReadable, WritableTrue
private_0x00000063564d00000x63564d00000x63564d0fffPrivate MemoryReadable, WritableTrue
pagefile_0x00000063564e00000x63564e00000x63564e0fffPagefile Backed FileReadableTrue
pagefile_0x00000063564f00000x63564f00000x63564f0fffPagefile Backed FileReadable, WritableTrue
SETUPAPI.dll.mui0x63565000000x635650bfffMemory Mapped FileReadableFalse
pagefile_0x00000063565100000x63565100000x6356510fffPagefile Backed FileReadable, WritableTrue
private_0x00000063565200000x63565200000x6356520fffPrivate MemoryReadable, WritableTrue
private_0x00000063565200000x63565200000x6356520fffPrivate MemoryReadable, WritableTrue
pagefile_0x00000063565300000x63565300000x6356530fffPagefile Backed FileReadable, WritableTrue
pagefile_0x00000063565300000x63565300000x6356530fffPagefile Backed FileReadable, WritableTrue
private_0x00000063565600000x63565600000x635665ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000063566600000x63566600000x63567e7fffPagefile Backed FileReadableTrue
pagefile_0x00000063567f00000x63567f00000x6356970fffPagefile Backed FileReadableTrue
pagefile_0x00000063569800000x63569800000x6357d7ffffPagefile Backed FileReadableTrue
sortdefault.nls0x6357d800000x6358054fffMemory Mapped FileReadableFalse
private_0x00000063580600000x63580600000x63580dffffPrivate MemoryReadable, WritableTrue
private_0x00000063580e00000x63580e00000x635815ffffPrivate MemoryReadable, WritableTrue
private_0x00000063581600000x63581600000x635825ffffPrivate MemoryReadable, WritableTrue
private_0x00000063581600000x63581600000x635825ffffPrivate MemoryReadable, WritableTrue
private_0x00000063581600000x63581600000x635825ffffPrivate MemoryReadable, WritableTrue
private_0x00000063582600000x63582600000x635855ffffPrivate MemoryReadable, WritableTrue
shell32.dll.mui0x63585600000x63585c5fffMemory Mapped FileReadableFalse
pagefile_0x00007df5ff8e00000x7df5ff8e00000x7ff5ff8dffffPagefile Backed File-True
pagefile_0x00007ff6189700000x7ff6189700000x7ff618a6ffffPagefile Backed FileReadableTrue
pagefile_0x00007ff618a700000x7ff618a700000x7ff618a92fffPagefile Backed FileReadableTrue
private_0x00007ff618a980000x7ff618a980000x7ff618a99fffPrivate MemoryReadable, WritableTrue
private_0x00007ff618a9a0000x7ff618a9a0000x7ff618a9afffPrivate MemoryReadable, WritableTrue
private_0x00007ff618a9c0000x7ff618a9c0000x7ff618a9dfffPrivate MemoryReadable, WritableTrue
private_0x00007ff618a9e0000x7ff618a9e0000x7ff618a9ffffPrivate MemoryReadable, WritableTrue
WallpaperHost.exe0x7ff6198400000x7ff619846fffMemory Mapped FileReadable, Writable, ExecutableFalse
WindowsCodecs.dll0x7ffb6f9000000x7ffb6faadfffMemory Mapped FileReadable, Writable, ExecutableFalse
WindowsCodecs.dll0x7ffb6f9000000x7ffb6faadfffMemory Mapped FileReadable, Writable, ExecutableFalse
WINBRAND.dll0x7ffb6faa00000x7ffb6faadfffMemory Mapped FileReadable, Writable, ExecutableFalse
propsys.dll0x7ffb6fab00000x7ffb6fc2efffMemory Mapped FileReadable, Writable, ExecutableFalse
WLDP.DLL0x7ffb6fc300000x7ffb6fc3cfffMemory Mapped FileReadable, Writable, ExecutableFalse
kernel.appcore.dll0x7ffb6fe400000x7ffb6fe4afffMemory Mapped FileReadable, Writable, ExecutableFalse
SHCORE.DLL0x7ffb701b00000x7ffb70261fffMemory Mapped FileReadable, Writable, ExecutableFalse
winsta.dll0x7ffb709400000x7ffb70999fffMemory Mapped FileReadable, Writable, ExecutableFalse
bcryptPrimitives.dll0x7ffb715800000x7ffb715e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTBASE.dll0x7ffb715f00000x7ffb715fafffMemory Mapped FileReadable, Writable, ExecutableFalse
profapi.dll0x7ffb716b00000x7ffb716c4fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
CFGMGR32.dll0x7ffb718800000x7ffb718cefffMemory Mapped FileReadable, Writable, ExecutableTrue
Setupapi.dll0x7ffb718d00000x7ffb71aa9fffMemory Mapped FileReadable, Writable, ExecutableTrue
gdi32.dll0x7ffb71ad00000x7ffb71c20fffMemory Mapped FileReadable, Writable, ExecutableTrue
SHELL32.dll0x7ffb71c300000x7ffb73148fffMemory Mapped FileReadable, Writable, ExecutableTrue
SHLWAPI.dll0x7ffb733000000x7ffb73353fffMemory Mapped FileReadable, Writable, ExecutableTrue
sechost.dll0x7ffb733c00000x7ffb73418fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
OLEAUT32.dll0x7ffb735c00000x7ffb73680fffMemory Mapped FileReadable, Writable, ExecutableTrue
advapi32.dll0x7ffb736900000x7ffb73739fffMemory Mapped FileReadable, Writable, ExecutableTrue
combase.dll0x7ffb737400000x7ffb73950fffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSCTF.dll0x7ffb73b800000x7ffb73cd2fffMemory Mapped FileReadable, Writable, ExecutableTrue
ole32.dll0x7ffb73ce00000x7ffb73e73fffMemory Mapped FileReadable, Writable, ExecutableTrue
user32.dll0x7ffb73e900000x7ffb74006fffMemory Mapped FileReadable, Writable, ExecutableTrue
IMM32.dll0x7ffb740100000x7ffb74045fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSVCRT.dll0x7ffb740500000x7ffb740f9fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Injection Information
+
Injection TypeSource ProcessSource Os Thread IDInjection InfoSuccessAmountLogfile
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8address = 0xd9cbf60000, size = 12288True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe0x27caddress = 0x6356410000, size = 4704True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe0x27caddress = 0x7ff618a9a2d8, size = 8True1
Fn
Data
Threads
Thread 0x294
(Host: 1894, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
SYSGET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue2
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\VersionsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versions, value_name = 426648723168True1
Fn
REGREAD_VALUEvalue_name = PageAllocatorUseSystemHeapFalse1
Fn
REGREAD_VALUEvalue_name = PageAllocatorSystemHeapIsPrivateFalse1
Fn
REGREAD_VALUEvalue_name = AggressiveMTATestingFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODGET_HANDLEmodule_name = rpcrt4.dllTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
MODGET_HANDLEmodule_name = X:\windows\system32\IMM32.DLLFalse1
Fn
MODLOADmodule_name = X:\windows\system32\IMM32.DLL, base_address = 0x0True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
MODGET_HANDLEmodule_name = X:\windows\system32\IMM32.DLLTrue2
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Error Message Instrument\False1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_InitializeTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize, value_name = DisableMetaFilesFalse1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEvalue_name = LoadAppInit_DLLsTrue1
Fn
MODGET_HANDLEmodule_name = X:\windows\system32\oleaut32.dllFalse1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wallpaperhost.exeTrue1
Fn
MODGET_HANDLEmodule_name = X:\windows\system32\rpcss.dllFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x390008True1
Fn
COMCREATEinterface = None, True1
Fn
MODGET_HANDLEmodule_name = combase.dllTrue1
Fn
REGOPEN_KEYreg_name = HKEY_USERS\S-1-5-18_ClassesFalse1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x63564e0000True1
Fn
REGREAD_VALUEvalue_name = Com+EnabledFalse1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\CLSIDTrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINE\Software\Microsoft\WindowsRuntime\CLSID\{75048700-EF1F-11D0-9888-006097DEACF9}False1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINE\Software\Classes\ActivatableClasses\CLSIDTrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINE\Software\Classes\ActivatableClasses\CLSID\{75048700-EF1F-11D0-9888-006097DEACF9}False1
Fn
REGREAD_VALUEvalue_name = 426648726872True2
Fn
REGREAD_VALUEvalue_name = InprocServer32False1
Fn
REGREAD_VALUEvalue_name = 426648726760True1
Fn
REGREAD_VALUEvalue_name = 426648726632True1
Fn
REGREAD_VALUEvalue_name = 426648726760True1
Fn
REGREAD_VALUEvalue_name = ThreadingModelTrue1
Fn
REGREAD_VALUEvalue_name = MaxSxSHashCountFalse1
Fn
REGOPEN_KEYreg_name = HKEY_USERS\S-1-5-18_ClassesFalse1
Fn
MODLOADmodule_name = X:\windows\system32\shell32.dll, base_address = 0x0True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocaleTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocale, value_name = en-USFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocaleTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocale, value_name = en-USFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocale\Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocale\Control Panel\InternationalFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocale\Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocale\Control Panel\International, value_name = sCurrencyOverrideFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SystemSetupInProgressTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = OOBEInProgressFalse1
Fn
MODLOADmodule_name = rpcrt4.dll, base_address = 0x0True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
REGREAD_VALUEvalue_name = MaxRpcSizeFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = OOBEInProgressFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = SystemSetupInProgressTrue1
Fn
SYSGET_INFOTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEvalue_name = IdleTimerWindowFalse1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = windows_shell_global_counters, module_name = rpcrt4.dll, maximum_size = 426648726032, protection = PAGE_READWRITETrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wallpaperhost.exe, os_pid = 0x290, address = 0x63564f0000True1
Fn
MODMAPmodule_name = windows_shell_global_counters, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x63564f0000True1
Fn
REGREAD_VALUEvalue_name = CategoryTrue1
Fn
REGREAD_VALUEvalue_name = NameTrue1
Fn
REGREAD_VALUEvalue_name = ParentFolderFalse1
Fn
REGREAD_VALUEvalue_name = DescriptionFalse1
Fn
REGREAD_VALUEvalue_name = RelativePathTrue1
Fn
REGREAD_VALUEvalue_name = ParsingNameFalse1
Fn
REGREAD_VALUEvalue_name = InfoTipFalse1
Fn
REGREAD_VALUEvalue_name = LocalizedNameFalse1
Fn
REGREAD_VALUEvalue_name = IconFalse1
Fn
REGREAD_VALUEvalue_name = SecurityFalse1
Fn
REGREAD_VALUEvalue_name = StreamResourceFalse1
Fn
REGREAD_VALUEvalue_name = StreamResourceTypeFalse1
Fn
REGREAD_VALUEvalue_name = LocalRedirectOnlyFalse1
Fn
REGREAD_VALUEvalue_name = RoamableFalse1
Fn
REGREAD_VALUEvalue_name = PreCreateFalse1
Fn
REGREAD_VALUEvalue_name = StreamFalse1
Fn
REGREAD_VALUEvalue_name = PublishExpandedPathFalse1
Fn
REGREAD_VALUEvalue_name = DefinitionFlagsFalse1
Fn
REGREAD_VALUEvalue_name = AttributesFalse1
Fn
REGREAD_VALUEvalue_name = FolderTypeIDFalse1
Fn
REGREAD_VALUEvalue_name = InitFolderHandlerFalse1
Fn
REGREAD_VALUEvalue_name = AppDataTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versions, value_name = 000602xxTrue1
Fn
MODLOADmodule_name = kernel32.dll, base_address = 0x0True1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x6357d80000True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\IdsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Ids, value_name = en-USFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Ids, value_name = enFalse1
Fn
REGOPEN_KEYFalse2
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = CategoryTrue1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = NameTrue1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = ParentFolderFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = DescriptionFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = RelativePathFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = ParsingNameFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = InfoTipFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = LocalizedNameFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = IconFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = SecurityFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = StreamResourceFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = StreamResourceTypeFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = LocalRedirectOnlyFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = RoamableFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = PreCreateFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = StreamFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = PublishExpandedPathFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = DefinitionFlagsFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = AttributesFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = FolderTypeIDFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = InitFolderHandlerFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ProfileImagePathTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ProfileImagePathTrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = LastUpdatedFalse1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCountFalse1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_000False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_001False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_002False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_003False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_004False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_005False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_006False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_007False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_008False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_009False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_010False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_011False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_012False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_013False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_014False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_015False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_016False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_017False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_018False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_019False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_020False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_021False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_022False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_023False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_024False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_025False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_026False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_027False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_028False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_029False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_030False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_031False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_032False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_033False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_034False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_035False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_036False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_037False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_038False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_039False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_040False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_041False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_042False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_043False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_044False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_045False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_046False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_047False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_048False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_049False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_050False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_051False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_052False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_053False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_054False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_055False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_056False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_057False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_058False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_059False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_060False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_061False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_062False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_063False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_064False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_065False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_066False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_067False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_068False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_069False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_070False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_071False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_072False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_073False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_074False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_075False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_076False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_077False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_078False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_079False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_080False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_081False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_082False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_083False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_084False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_085False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_086False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_087False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_088False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_089False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_090False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_091False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_092False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_093False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_094False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_095False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_096False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_097False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_098False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_099False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_100False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_101False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_102False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_103False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_104False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_105False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_106False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_107False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_108False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_109False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_110False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_111False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_112False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_113False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_114False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_115False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_116False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_117False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_118False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_119False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_120False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_121False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_122False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_123False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_124False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_125False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_126False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_127False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_128False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_129False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_130False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_131False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_132False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_133False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_134False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_135False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_136False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_137False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_138False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_139False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_140False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_141False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_142False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_143False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_144False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_145False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_146False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_147False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_148False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_149False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_150False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_151False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_152False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_153False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_154False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_155False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_156False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_157False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_158False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_159False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_160False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_161False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_162False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_163False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_164False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_165False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_166False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_167False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_168False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_169False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_170False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_171False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_172False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_173False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_174False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_175False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_176False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_177False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_178False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_179False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_180False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_181False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_182False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_183False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_184False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_185False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_186False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_187False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_188False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_189False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_190False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_191False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_192False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_193False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_194False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_195False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_196False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_197False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_198False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_199False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_200False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_201False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_202False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_203False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_204False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_205False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_206False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_207False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_208False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_209False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_210False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_211False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_212False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_213False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\themes, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
REGREAD_VALUEvalue_name = TranscodedImageCache_214False1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\config\systemprofile, desired_access = FILE_READ_DATA, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_CREATE, create_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENT, FILE_OPEN_REPARSE_POINT, ea_buffer = 0, ea_length = 0False1
Fn
For performance reasons, the remaining 840 entries are omitted.
Click to download all 1840 entries as text file (2.56 MB).
Thread 0x2a0
(Host: 32, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
FILECREATEfile_name = \device\deviceapi\cmapi, desired_access = GENERIC_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR, value_name = DisableTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR, value_name = SourcePathFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR, value_name = DevicePathTrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue2
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470807True2
Fn
FILECREATEfile_name = \device\mountpointmanager, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
DRVCONTROLfile_name = \device\mountpointmanager, control_code = 0x6d0034False1
Fn
DRVCONTROLfile_name = \device\mountpointmanager, control_code = 0x6d0034True1
Fn
FILECREATEfile_name = \device\mountpointmanager, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
DRVCONTROLfile_name = \device\mountpointmanager, control_code = 0x6d0034False1
Fn
DRVCONTROLfile_name = \device\mountpointmanager, control_code = 0x6d0034True1
Fn
FILECREATEfile_name = \device\mountpointmanager, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
DRVCONTROLfile_name = \device\mountpointmanager, control_code = 0x6d0034False1
Fn
DRVCONTROLfile_name = \device\mountpointmanager, control_code = 0x6d0034True1
Fn
FILECREATEfile_name = \device\mountpointmanager, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
DRVCONTROLfile_name = \device\mountpointmanager, control_code = 0x6d0034False1
Fn
DRVCONTROLfile_name = \device\mountpointmanager, control_code = 0x6d0034True1
Fn
FILECREATEfile_name = \device\mountpointmanager, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
DRVCONTROLfile_name = \device\mountpointmanager, control_code = 0x6d0034False1
Fn
DRVCONTROLfile_name = \device\mountpointmanager, control_code = 0x6d0034True1
Fn
FILECREATEfile_name = \device\mountpointmanager, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
DRVCONTROLfile_name = \device\mountpointmanager, control_code = 0x6d0034False1
Fn
DRVCONTROLfile_name = \device\mountpointmanager, control_code = 0x6d0034True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
Thread 0x2a4
(Host: 12, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
FILEOPENfile_name = c:, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
FILEOPENfile_name = c:, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, open_options = FILE_SYNCHRONOUS_IO_ALERTTrue1
Fn
DRVCONTROLfile_name = c:, control_code = 0x4d0008True1
Fn
FILECREATEfile_name = \device\mountpointmanager, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
DRVCONTROLfile_name = \device\mountpointmanager, control_code = 0x6d0008False1
Fn
DRVCONTROLfile_name = \device\mountpointmanager, control_code = 0x6d0008True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, open_options = FILE_SYNCHRONOUS_IO_ALERTTrue1
Fn
DRVCONTROLfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}, control_code = 0x4d0008True1
Fn
FILECREATEfile_name = \device\mountpointmanager, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
DRVCONTROLfile_name = \device\mountpointmanager, control_code = 0x6d0008False1
Fn
DRVCONTROLfile_name = \device\mountpointmanager, control_code = 0x6d0008True1
Fn
Process #17: recenv.exe
(Host: 1112, Network: 0)
+
InformationValue
ID / OS PID#17 / 0x298
OS Parent PID0x278 (\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe
Command LineX:\sources\recovery\recenv.exe
MonitorStart Time: 00:01:55, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:12
OS Thread IDs
#123
0x29C
#126
0x2A8
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x000000e5e53500000xe5e53500000xe5e536ffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000e5e53500000xe5e53500000xe5e535ffffPagefile Backed FileReadable, WritableTrue
private_0x000000e5e53600000xe5e53600000xe5e5366fffPrivate MemoryReadable, WritableTrue
pagefile_0x000000e5e53700000xe5e53700000xe5e537efffPagefile Backed FileReadableTrue
private_0x000000e5e53800000xe5e53800000xe5e53fffffPrivate MemoryReadable, WritableTrue
pagefile_0x000000e5e54000000xe5e54000000xe5e5403fffPagefile Backed FileReadableTrue
pagefile_0x000000e5e54100000xe5e54100000xe5e5411fffPagefile Backed FileReadableTrue
private_0x000000e5e54200000xe5e54200000xe5e5421fffPrivate MemoryReadable, WritableTrue
pagefile_0x000000e5e54300000xe5e54300000xe5e5431fffPagefile Backed FileReadableTrue
pagefile_0x000000e5e54400000xe5e54400000xe5e5441fffPagefile Backed FileReadableTrue
private_0x000000e5e54500000xe5e54500000xe5e5456fffPrivate MemoryReadable, WritableTrue
recenv.exe.mui0xe5e54600000xe5e5465fffMemory Mapped FileReadableTrue
private_0x000000e5e54700000xe5e54700000xe5e547ffffPrivate MemoryReadable, WritableTrue
private_0x000000e5e54800000xe5e54800000xe5e5480fffPrivate MemoryReadable, WritableTrue
private_0x000000e5e54900000xe5e54900000xe5e558ffffPrivate MemoryReadable, WritableTrue
locale.nls0xe5e55900000xe5e560dfffMemory Mapped FileReadableFalse
pagefile_0x000000e5e56100000xe5e56100000xe5e5797fffPagefile Backed FileReadableTrue
pagefile_0x000000e5e57a00000xe5e57a00000xe5e5920fffPagefile Backed FileReadableTrue
pagefile_0x000000e5e59300000xe5e59300000xe5e6d2ffffPagefile Backed FileReadableTrue
private_0x000000e5e6d300000xe5e6d300000xe5e6d30fffPrivate MemoryReadable, WritableTrue
SETUPAPI.dll.mui0xe5e6d400000xe5e6d4bfffMemory Mapped FileReadableFalse
pagefile_0x000000e5e6d500000xe5e6d500000xe5e6d52fffPagefile Backed FileReadableTrue
newdev.dll.mui0xe5e6d600000xe5e6d66fffMemory Mapped FileReadableFalse
private_0x000000e5e6d700000xe5e6d700000xe5e6deffffPrivate MemoryReadable, WritableTrue
private_0x000000e5e6e500000xe5e6e500000xe5e6e5ffffPrivate MemoryReadable, WritableTrue
sortdefault.nls0xe5e6e600000xe5e7134fffMemory Mapped FileReadableFalse
private_0x000000e5e71400000xe5e71400000xe5e723ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007ff7298700000x7ff7298700000x7ff72996ffffPagefile Backed FileReadableTrue
pagefile_0x00007ff7299700000x7ff7299700000x7ff729992fffPagefile Backed FileReadableTrue
private_0x00007ff72999a0000x7ff72999a0000x7ff72999bfffPrivate MemoryReadable, WritableTrue
private_0x00007ff72999c0000x7ff72999c0000x7ff72999cfffPrivate MemoryReadable, WritableTrue
private_0x00007ff72999e0000x7ff72999e0000x7ff72999ffffPrivate MemoryReadable, WritableTrue
recenv.exe0x7ff729ec00000x7ff729f63fffMemory Mapped FileReadable, Writable, ExecutableTrue
DismApi.DLL0x7ffb6fc400000x7ffb6fce2fffMemory Mapped FileReadable, Writable, ExecutableFalse
WDSCORE.dll0x7ffb6fcf00000x7ffb6fd37fffMemory Mapped FileReadable, Writable, ExecutableFalse
ReAgent.dll0x7ffb6fd400000x7ffb6fe2ffffMemory Mapped FileReadable, Writable, ExecutableFalse
VERSION.dll0x7ffb6fe300000x7ffb6fe39fffMemory Mapped FileReadable, Writable, ExecutableFalse
drvstore.dll0x7ffb6fe500000x7ffb6ff0afffMemory Mapped FileReadable, Writable, ExecutableFalse
COMCTL32.dll0x7ffb6ff100000x7ffb7018afffMemory Mapped FileReadable, Writable, ExecutableFalse
SHCORE.DLL0x7ffb701b00000x7ffb70261fffMemory Mapped FileReadable, Writable, ExecutableFalse
MPR.dll0x7ffb702700000x7ffb7028dfffMemory Mapped FileReadable, Writable, ExecutableFalse
wkscli.dll0x7ffb702900000x7ffb702a6fffMemory Mapped FileReadable, Writable, ExecutableFalse
WpeUtil.dll0x7ffb702b00000x7ffb702cefffMemory Mapped FileReadable, Writable, ExecutableFalse
devrtl.DLL0x7ffb702d00000x7ffb702e5fffMemory Mapped FileReadable, Writable, ExecutableFalse
WINNSI.DLL0x7ffb702f00000x7ffb702f9fffMemory Mapped FileReadable, Writable, ExecutableFalse
FLTLIB.DLL0x7ffb703500000x7ffb70359fffMemory Mapped FileReadable, Writable, ExecutableFalse
UNATTEND.DLL0x7ffb703600000x7ffb7039ffffMemory Mapped FileReadable, Writable, ExecutableFalse
Input.dll0x7ffb703a00000x7ffb703e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
newdev.dll0x7ffb703f00000x7ffb70445fffMemory Mapped FileReadable, Writable, ExecutableFalse
IPHLPAPI.DLL0x7ffb704500000x7ffb70479fffMemory Mapped FileReadable, Writable, ExecutableFalse
UxTheme.dll0x7ffb704800000x7ffb705a8fffMemory Mapped FileReadable, Writable, ExecutableFalse
DEVOBJ.dll0x7ffb705b00000x7ffb705d7fffMemory Mapped FileReadable, Writable, ExecutableFalse
spinf.dll0x7ffb709a00000x7ffb709bdfffMemory Mapped FileReadable, Writable, ExecutableFalse
USERENV.dll0x7ffb70dd00000x7ffb70df0fffMemory Mapped FileReadable, Writable, ExecutableFalse
DNSAPI.dll0x7ffb70e400000x7ffb70ee3fffMemory Mapped FileReadable, Writable, ExecutableFalse
powrprof.dll0x7ffb715300000x7ffb71575fffMemory Mapped FileReadable, Writable, ExecutableFalse
profapi.dll0x7ffb716b00000x7ffb716c4fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
CFGMGR32.dll0x7ffb718800000x7ffb718cefffMemory Mapped FileReadable, Writable, ExecutableTrue
Setupapi.dll0x7ffb718d00000x7ffb71aa9fffMemory Mapped FileReadable, Writable, ExecutableTrue
IMAGEHLP.dll0x7ffb71ab00000x7ffb71ac5fffMemory Mapped FileReadable, Writable, ExecutableTrue
gdi32.dll0x7ffb71ad00000x7ffb71c20fffMemory Mapped FileReadable, Writable, ExecutableTrue
SHELL32.dll0x7ffb71c300000x7ffb73148fffMemory Mapped FileReadable, Writable, ExecutableTrue
SHLWAPI.dll0x7ffb733000000x7ffb73353fffMemory Mapped FileReadable, Writable, ExecutableTrue
WS2_32.dll0x7ffb733600000x7ffb733b9fffMemory Mapped FileReadable, Writable, ExecutableTrue
sechost.dll0x7ffb733c00000x7ffb73418fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
OLEAUT32.dll0x7ffb735c00000x7ffb73680fffMemory Mapped FileReadable, Writable, ExecutableTrue
advapi32.dll0x7ffb736900000x7ffb73739fffMemory Mapped FileReadable, Writable, ExecutableTrue
combase.dll0x7ffb737400000x7ffb73950fffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSCTF.dll0x7ffb73b800000x7ffb73cd2fffMemory Mapped FileReadable, Writable, ExecutableTrue
ole32.dll0x7ffb73ce00000x7ffb73e73fffMemory Mapped FileReadable, Writable, ExecutableTrue
NSI.dll0x7ffb73e800000x7ffb73e88fffMemory Mapped FileReadable, Writable, ExecutableTrue
user32.dll0x7ffb73e900000x7ffb74006fffMemory Mapped FileReadable, Writable, ExecutableTrue
IMM32.dll0x7ffb740100000x7ffb74045fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSVCRT.dll0x7ffb740500000x7ffb740f9fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Injection Information
+
Injection TypeSource ProcessSource Os Thread IDInjection InfoSuccessAmountLogfile
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe0x27caddress = 0xe5e5420000, size = 4704True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\winpeshl.exe0x27caddress = 0x7ff72999c2d8, size = 8True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8address = 0xd9cbf90000, size = 12288True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x1e8No corresponding api call detected. Probably injected code via shellcode.True1
Threads
Thread 0x29c
(Host: 264, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
SYSGET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue2
Fn
REGOPEN_KEYreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySideTrue1
Fn
REGREAD_VALUEreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide, value_name = PreferExternalManifestFalse1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\reagent.dll, desired_access = FILE_READ_DATA, FILE_READ_EA, FILE_READ_ATTRIBUTES, READ_CONTROL, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
REGOPEN_KEYreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySideTrue1
Fn
REGREAD_VALUEreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide, value_name = PreferExternalManifestFalse1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\newdev.dll, desired_access = FILE_READ_DATA, FILE_READ_EA, FILE_READ_ATTRIBUTES, READ_CONTROL, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\VersionsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versions, value_name = 987393678784True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
MODGET_HANDLEmodule_name = X:\windows\system32\IMM32.DLLTrue2
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Error Message Instrument\False1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_InitializeTrue1
Fn
REGREAD_VALUEfile_name = STD_OUTPUT_HANDLE, value_name = DisableMetaFilesFalse1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEvalue_name = LoadAppInit_DLLsTrue1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\windowsshell.manifest, desired_access = FILE_READ_DATA, FILE_READ_EA, FILE_EXECUTE, FILE_READ_ATTRIBUTES, READ_CONTROL, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILETrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\windowsshell.manifest, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6d40000True1
Fn
REGOPEN_KEYreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySideTrue1
Fn
REGREAD_VALUEreg_name = \Registry\MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide, value_name = PreferExternalManifestFalse1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, base_address = 0xe5e6d40000True1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exeFalse1
Fn
MODGET_HANDLEmodule_name = LPK.dllFalse1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exeTrue1
Fn
MODGET_HANDLEmodule_name = GDI32.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb71bf7350True1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = PageAllocatorUseSystemHeapFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = PageAllocatorSystemHeapIsPrivateFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = AggressiveMTATestingFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODGET_HANDLEmodule_name = rpcrt4.dllTrue1
Fn
MODGET_HANDLEmodule_name = X:\windows\system32\oleaut32.dllTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODGET_HANDLEmodule_name = ext-ms-win-ole32-oleautomation-l1-1-0.dllTrue1
Fn
REGOPEN_KEYTrue1
Fn
FILECREATEfile_name = \device\deviceapi\cmapi, desired_access = GENERIC_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMRTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR, value_name = DisableTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR, value_name = SourcePathFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows\Windows Error Reporting\WMR, value_name = DevicePathTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocaleTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocale, value_name = en-USFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocaleTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocale, value_name = en-USFalse1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue2
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SystemSetupInProgressTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exeTrue1
Fn
MODGET_HANDLEmodule_name = advapi32.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb741751c0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb7413b300True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb7413c360True1
Fn
MODGET_HANDLEmodule_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exeTrue1
Fn
MODGET_HANDLEmodule_name = ntdll.dllTrue1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb7413b300True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb7413c360True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb74175650True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb741751c0True1
Fn
REGOPEN_KEYTrue1
Fn
MODLOADmodule_name = rpcrt4.dll, base_address = 0x0True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
REGREAD_VALUEvalue_name = MaxRpcSizeFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = OOBEInProgressFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = SystemSetupInProgressTrue1
Fn
SYSGET_INFOTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEvalue_name = IdleTimerWindowFalse1
Fn
THREADCREATEprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, proc_address = 0x7ff729ece3c4, desired_access = THREAD_ALL_ACCESSTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, privilege = SeRestorePrivilege, enable_privilege = 1True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SetComputerNameFalse1
Fn
REGCREATE_KEYTrue1
Fn
REGCREATE_KEYreg_name = System\CurrentControlSet\Services\Tcpip\ParametersTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGOPEN_KEYFalse2
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = QueryAdapterNameFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Services\Tcpip\Parameters, value_name = DisableAdapterDomainNameFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = UseDomainNameDevolutionFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Services\Tcpip\Parameters, value_name = UseDomainNameDevolutionFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DomainNameDevolutionLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = PrioritizeRecordDataFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Services\Tcpip\Parameters, value_name = PrioritizeRecordDataFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AllowUnqualifiedQueryFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Services\Tcpip\Parameters, value_name = AllowUnqualifiedQueryFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AppendToMultiLabelNameFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ScreenBadTldsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ScreenUnreachableServersFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ScreenDefaultServersFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DynamicServerQueryOrderFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = FilterClusterIpFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = WaitForNameErrorOnAllFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = UseEdnsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DnsSecureNameQueryFallbackFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableDAForAllNetworksFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectAccessQueryOrderFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = QueryIpMatchingFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = UseHostsFileFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AddrConfigControlFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableSmartNameResolutionFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = PreferLocalOverLowerBindingDNSFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = QueryNetBTFQDNFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableSmartProtocolReorderingFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = UdpRecvBufferSizeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableParallelAandAAAAFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableCoalescingFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = FilterVPNTriggerFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RegistrationEnabledFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Services\Tcpip\Parameters, value_name = DisableDynamicUpdateFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RegisterPrimaryNameFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RegisterAdapterNameFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Services\Tcpip\Parameters, value_name = EnableAdapterDomainNameRegistrationFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RegisterReverseLookupFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Services\Tcpip\Parameters, value_name = DisableReverseAddressRegistrationsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RegisterWanAdaptersFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Services\Tcpip\Parameters, value_name = DisableWanDynamicUpdateFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RegistrationTtlFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Services\Tcpip\Parameters, value_name = DefaultRegistrationTTLFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RegistrationRefreshIntervalFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Services\Tcpip\Parameters, value_name = DefaultRegistrationRefreshIntervalFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RegistrationMaxAddressCountFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Services\Tcpip\Parameters, value_name = MaxNumberOfAddressesToRegisterFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = UpdateSecurityLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Services\Tcpip\Parameters, value_name = UpdateSecurityLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = UpdateTopLevelDomainZonesFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DowncaseSpnCauseApiOwnerIsTooLazyFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RegistrationOverwriteFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MaxCacheSizeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MaxCacheTtlFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MaxNegativeCacheTtlFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AdapterTimeoutLimitFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ServerPriorityTimeLimitFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MaxCachedSocketsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableServerUnreachabilityFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableMulticastFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MulticastResponderFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MulticastSenderFlagsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MulticastSenderMaxTimeoutFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DnsTestFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = UseCompartmentsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CacheAllCompartmentsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = UseNewRegistrationFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ResolverRegistrationFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ResolverRegistrationOnlyFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = NewDhcpSrvRegistrationFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DirectAccessPreferLocalFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DisableIdnEncodingFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = EnableIdnMappingFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = TestMode_AdaptiveTimeoutHistoryLengthFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = TestMode_AdaptiveTimeoutRecalculationIntervalFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SystemSetupInProgressTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DnsQueryTimeoutsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Services\Tcpip\Parameters, value_name = DnsQueryTimeoutsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = DnsQuickQueryTimeoutsFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEreg_name = System\CurrentControlSet\Services\Tcpip\Parameters, value_name = DnsQuickQueryTimeoutsFalse1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEmutex_name = WinPEProfilingMutex, initial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
SVCOPEN_MGRdatabase_name = SERVICES_ACTIVE_DATABASE, host = LocalhostTrue1
Fn
SVCOPENTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEvalue_name = SQMServiceListTrue1
Fn
SVCSET_CONFIGTrue1
Fn
Thread 0x2a8
(Host: 848, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
MODLOADmodule_name = ntdll.dll, base_address = 0x0True1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINETrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINE\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \REGISTRY\MACHINE\System\Setup, value_name = SystemSetupInProgressTrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINETrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Control\MiniNTTrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINETrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\SetupTrue1
Fn
REGREAD_VALUEreg_name = \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Setup, value_name = MinimizeFootprintTrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINETrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINE\Software\Microsoft\EmbeddedNT\SecurityFalse1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470803True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470843True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470827True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True2
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXRELEASETrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINETrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\SetupTrue1
Fn
REGREAD_VALUEreg_name = \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Setup, value_name = LogLevelTrue1
Fn
REGREAD_VALUEreg_name = \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Setup, value_name = LogMaskFalse1
Fn
REGREAD_VALUEreg_name = \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Setup, value_name = LogMaxFileSizeFalse1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
MUTEXRELEASETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versions, value_name = 000602xxTrue1
Fn
MODLOADmodule_name = kernel32.dll, base_address = 0x0True1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6e60000True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\IdsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Ids, value_name = en-USFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Ids, value_name = enFalse1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINETrue1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\DeviceInstallFalse1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLfile_name = \device\deviceapi\cmapi, control_code = 0x470813True1
Fn
MUTEXRELEASETrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
REGOPEN_KEYreg_name = Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\InternationalFalse1
Fn
REGREAD_VALUEreg_name = Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\International, value_name = sCurrencyOverrideFalse1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x47086bTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\apps.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\apps.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298, address = 0xe5e6df0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6df0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298True1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x47086bTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\defltbase.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\defltbase.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298, address = 0xe5e6df0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6df0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298True1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x47086bTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\defltwk.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\defltwk.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298, address = 0xe5e6df0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6df0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298True1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x47086bTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\dwup.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\dwup.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298, address = 0xe5e6df0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6df0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298True1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x47086bTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\errata.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\errata.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298, address = 0xe5e6df0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6df0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298True1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x47086bTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\fontsetup.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\fontsetup.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298, address = 0xe5e7240000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e7240000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298True1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x47086bTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netnb.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\netnb.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298, address = 0xe5e6df0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6df0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298True1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x47086bTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\puwk.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\puwk.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298, address = 0xe5e6df0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6df0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298True1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x47086bTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ramdisk.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\ramdisk.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298, address = 0xe5e6df0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6df0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298True1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x47086bTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sceregvl.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\sceregvl.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298, address = 0xe5e6df0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6df0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298True1
Fn
MUTEXCREATETrue1
Fn
MUTEXCREATEinitial_owner = 0, desired_access = MUTEX_MODIFY_STATE, DELETE, READ_CONTROL, WRITE_DAC, WRITE_OWNER, SYNCHRONIZETrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x470813True1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x47086bTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILEOPENfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\, desired_access = FILE_READ_DATA, SYNCHRONIZE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, open_options = FILE_DIRECTORY_FILE, FILE_SYNCHRONOUS_IO_NONALERT, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
FILECREATETrue1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\secrecs.inf, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, create_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMappingTrue1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\inf\secrecs.inf, maximum_size = 987420871104, protection = PAGE_READONLYTrue1
Fn
MODMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298, address = 0xe5e6df0000True1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0xe5e6df0000True1
Fn
MODUNMAPprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\sources\recovery\recenv.exe, os_pid = 0x298True1
Fn
MUTEXCREATETrue1
Fn
Process #18: svchost.exe
(Host: 231, Network: 0)
+
InformationValue
ID / OS PID#18 / 0x2b0
OS Parent PID0x1ac (c:\windows\system32\csrss.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\svchost.exe
Command LineX:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
MonitorStart Time: 00:02:04, Reason: Child Process
UnmonitorEnd Time: 00:02:07, Reason: Terminated by Timeout
Monitor Duration00:00:03
OS Thread IDs
#127
0x2B4
#130
0x2C4
#131
0x2C8
#132
0x2CC
#133
0x2D0
Region
+
NameStart VAEnd VATypePermissionsMonitoredDump
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrue
private_0x00000020608b00000x20608b00000x20608cffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000020608b00000x20608b00000x20608bffffPagefile Backed FileReadable, WritableTrue
private_0x00000020608c00000x20608c00000x20608c6fffPrivate MemoryReadable, WritableTrue
pagefile_0x00000020608d00000x20608d00000x20608defffPagefile Backed FileReadableTrue
private_0x00000020608e00000x20608e00000x206095ffffPrivate MemoryReadable, WritableTrue
pagefile_0x00000020609600000x20609600000x2060963fffPagefile Backed FileReadableTrue
pagefile_0x00000020609700000x20609700000x2060970fffPagefile Backed FileReadableTrue
private_0x00000020609800000x20609800000x2060981fffPrivate MemoryReadable, WritableTrue
locale.nls0x20609900000x2060a0dfffMemory Mapped FileReadableFalse
private_0x0000002060a100000x2060a100000x2060a16fffPrivate MemoryReadable, WritableTrue
pagefile_0x0000002060a200000x2060a200000x2060adffffPagefile Backed FileReadableTrue
svchost.exe.mui0x2060ae00000x2060ae0fffMemory Mapped FileReadableFalse
private_0x0000002060af00000x2060af00000x2060af0fffPrivate MemoryReadable, WritableTrue
private_0x0000002060b000000x2060b000000x2060b00fffPrivate MemoryReadable, WritableTrue
private_0x0000002060b100000x2060b100000x2060b16fffPrivate MemoryReadable, WritableTrue
private_0x0000002060b200000x2060b200000x2060c1ffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000002060c200000x2060c200000x2060da7fffPagefile Backed FileReadableTrue
private_0x0000002060e000000x2060e000000x2060e0ffffPrivate MemoryReadable, WritableTrue
pagefile_0x0000002060e100000x2060e100000x2060f90fffPagefile Backed FileReadableTrue
private_0x0000002060fa00000x2060fa00000x206101ffffPrivate MemoryReadable, WritableTrue
private_0x00000020610200000x20610200000x206109ffffPrivate MemoryReadable, WritableTrue
sortdefault.nls0x20610a00000x2061374fffMemory Mapped FileReadableFalse
private_0x00000020613800000x20613800000x206147ffffPrivate MemoryReadable, WritableTrue
private_0x00000020614800000x20614800000x2061487fffPrivate MemoryReadable, WritableTrue
private_0x00000020614900000x20614900000x206150ffffPrivate MemoryReadable, WritableTrue
wevtapi.dll0x20615100000x2061579fffMemory Mapped FileReadableFalse
private_0x00000020615800000x20615800000x20615fffffPrivate MemoryReadable, WritableTrue
pagefile_0x00007df5ff1d00000x7df5ff1d00000x7ff5ff1cffffPagefile Backed File-True
pagefile_0x00007ff7c98c00000x7ff7c98c00000x7ff7c99bffffPagefile Backed FileReadableTrue
pagefile_0x00007ff7c99c00000x7ff7c99c00000x7ff7c99e2fffPagefile Backed FileReadableTrue
private_0x00007ff7c99e50000x7ff7c99e50000x7ff7c99e6fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c99e70000x7ff7c99e70000x7ff7c99e8fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c99e90000x7ff7c99e90000x7ff7c99e9fffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c99ea0000x7ff7c99ea0000x7ff7c99ebfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c99ec0000x7ff7c99ec0000x7ff7c99edfffPrivate MemoryReadable, WritableTrue
private_0x00007ff7c99ee0000x7ff7c99ee0000x7ff7c99effffPrivate MemoryReadable, WritableTrue
svchost.exe0x7ff7ca8100000x7ff7ca81cfffMemory Mapped FileReadable, Writable, ExecutableFalse
wevtsvc.dll0x7ffb6f8f00000x7ffb6fa91fffMemory Mapped FileReadable, Writable, ExecutableFalse
kernel.appcore.dll0x7ffb6fe400000x7ffb6fe4afffMemory Mapped FileReadable, Writable, ExecutableFalse
SspiCli.dll0x7ffb715000000x7ffb7152dfffMemory Mapped FileReadable, Writable, ExecutableFalse
powrprof.dll0x7ffb715300000x7ffb71575fffMemory Mapped FileReadable, Writable, ExecutableFalse
bcryptPrimitives.dll0x7ffb715800000x7ffb715e2fffMemory Mapped FileReadable, Writable, ExecutableFalse
CRYPTBASE.dll0x7ffb715f00000x7ffb715fafffMemory Mapped FileReadable, Writable, ExecutableFalse
kernelbase.dll0x7ffb717600000x7ffb71874fffMemory Mapped FileReadable, Writable, ExecutableTrue
gdi32.dll0x7ffb71ad00000x7ffb71c20fffMemory Mapped FileReadable, Writable, ExecutableTrue
sechost.dll0x7ffb733c00000x7ffb73418fffMemory Mapped FileReadable, Writable, ExecutableTrue
kernel32.dll0x7ffb734800000x7ffb735bdfffMemory Mapped FileReadable, Writable, ExecutableTrue
combase.dll0x7ffb737400000x7ffb73950fffMemory Mapped FileReadable, Writable, ExecutableTrue
rpcrt4.dll0x7ffb73a300000x7ffb73b70fffMemory Mapped FileReadable, Writable, ExecutableTrue
user32.dll0x7ffb73e900000x7ffb74006fffMemory Mapped FileReadable, Writable, ExecutableTrue
MSVCRT.dll0x7ffb740500000x7ffb740f9fffMemory Mapped FileReadable, Writable, ExecutableTrue
ntdll.dll0x7ffb741200000x7ffb742cbfffMemory Mapped FileReadable, Writable, ExecutableFalse
Injection Information
+
Injection TypeSource ProcessSource Os Thread IDInjection InfoSuccessAmountLogfile
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe0x188No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe0x1b0address = 0x2060980000, size = 4704True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\services.exe0x1b0address = 0x7ff7c99e92d8, size = 8True1
Fn
Data
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1d0No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1d0No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1d0No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1d0No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1d0No corresponding api call detected. Probably injected code via shellcode.True1
Modify Memory\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\lsass.exe0x1d0No corresponding api call detected. Probably injected code via shellcode.True1
Threads
Thread 0x2b4
(Host: 72, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
SYSGET_INFOtype = SYSTEM_CURRENT_TIME_ZONE_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue2
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\VersionsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versions, value_name = 139059393024True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = LocalServiceNetworkRestrictedTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = LocalServiceNetworkRestrictedTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = CoInitializeSecurityParamTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CoInitializeSecurityAllowLowBoxFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AuthenticationLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = ImpersonationLevelFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AuthenticationCapabilitiesFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CoInitializeSecurityAppIDFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = DefaultRpcStackSizeTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RpcExceptionFilterModeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SystemCriticalFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = NoGuiAccessFalse1
Fn
REGOPEN_KEYFalse1
Fn
PROCOPEN_TOKENTrue1
Fn
REGREAD_VALUEvalue_name = PageAllocatorUseSystemHeapFalse1
Fn
REGREAD_VALUEvalue_name = PageAllocatorSystemHeapIsPrivateFalse1
Fn
REGREAD_VALUEvalue_name = AggressiveMTATestingFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODGET_HANDLEmodule_name = rpcrt4.dllTrue1
Fn
MODGET_HANDLEmodule_name = X:\windows\system32\rpcss.dllFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
DRVCONTROLTrue1
Fn
DRVCONTROLcontrol_code = 0x390008True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Error Message Instrument\False1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_InitializeTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize, value_name = DisableMetaFilesFalse1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEvalue_name = LoadAppInit_DLLsTrue1
Fn
MODLOADmodule_name = rpcrt4.dll, base_address = 0x0True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
REGREAD_VALUEvalue_name = MaxRpcSizeFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = OOBEInProgressFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = SystemSetupInProgressTrue1
Fn
SYSGET_INFOTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGREAD_VALUEvalue_name = IdleTimerWindowFalse1
Fn
MODGET_HANDLEmodule_name = ntdll.dllTrue1
Fn
SYSGET_INFOFalse1
Fn
REGOPEN_KEYreg_name = HKEY_USERS\S-1-5-19_ClassesFalse1
Fn
COMCREATEinterface = None, True1
Fn
REGOPEN_KEYreg_name = \REGISTRY\MACHINE\Software\Microsoft\Rpc\ExtensionsTrue1
Fn
REGREAD_VALUEreg_name = \REGISTRY\MACHINE\Software\Microsoft\Rpc\Extensions, value_name = NdrOleExtDLLTrue1
Fn
MODGET_HANDLEmodule_name = combase.dllTrue1
Fn
THREADCREATEprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, proc_address = 0x7ffb733c7ef0, desired_access = THREAD_ALL_ACCESSTrue1
Fn
Thread 0x2c4
(Host: 1, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
DRVCONTROLcontrol_code = 0x110008False1
Fn
Thread 0x2c8
(Host: 144, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
REGOPEN_KEYreg_name = Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\InternationalFalse1
Fn
REGREAD_VALUEreg_name = Control Panel\InternationalTrue1
Fn
REGREAD_VALUEreg_name = Control Panel\International, value_name = sCurrencyOverrideFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocaleTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\CustomLocale, value_name = en-USFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocaleTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\ExtendedLocale, value_name = en-USFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Versions, value_name = 000602xxTrue1
Fn
MODLOADmodule_name = kernel32.dll, base_address = 0x0True1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\globalization\sorting\sortdefault.nls, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x20610a0000True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\IdsTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Ids, value_name = en-USFalse1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\Nls\Sorting\Ids, value_name = enFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGOPEN_KEYFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = ServiceDllTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = ServiceManifestFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = ServiceMainTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEmodule_name = Nameless FileMapping, value_name = ServiceMainTrue1
Fn
MODLOADbase_address = 0x7ffb6f8f0000True1
Fn
MODLOADmodule_name = x:\windows\system32\wevtsvc.dll, base_address = 0x0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb6f947ee0True1
Fn
MODGET_PROC_ADDRESSaddress_out = 0x7ffb6f94efc0True1
Fn
SVCREGISTER_HANDLERTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CompatFlagsFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MaxSizeTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = RetentionTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AutoBackupLogFilesFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CustomSDFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = MaxSizeFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = RetentionFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AutoBackupLogFilesFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = CustomSDTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = CustomSDTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MaxSizeTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = WarningLevelFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = RetentionTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AutoBackupLogFilesFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CustomSDFalse1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = MaxSizeTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = RetentionTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = AutoBackupLogFilesFalse1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = CustomSDFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SystemSetupInProgressTrue1
Fn
REGOPEN_KEYFalse1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = ProductNameTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = CurrentTypeTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = InstallDateTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = BuildLabTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Services\Tcpip\ParametersTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters, value_name = HostnameFalse1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGOPEN_KEYFalse1
Fn
SYSGET_INFOTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = CurrentTypeTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = CurrentTypeTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Services\Tcpip\ParametersTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters, value_name = HostnameFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerNameTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = OOBEInProgressFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\SetupTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\Setup, value_name = SystemSetupInProgressTrue1
Fn
REGOPEN_KEYreg_name = \Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\OptionFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Services\Tcpip\ParametersTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters, value_name = HostnameFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerNameTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName, value_name = SystemSetupInProgressTrue1
Fn
THREADCREATEprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, proc_address = 0x7ffb6f922a20, desired_access = THREAD_ALL_ACCESSTrue1
Fn
MODLOADbase_address = 0x2061510002True1
Fn
FILECREATEfile_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wevtapi.dll, desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE, create_disposition = FILE_OPEN, ea_buffer = 0, ea_length = 0True1
Fn
MODCREATE_MAPPINGmodule_name = Nameless FileMapping, file_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wevtapi.dll, maximum_size = 0, protection = PAGE_READONLYTrue1
Fn
MODMAPmodule_name = Nameless FileMapping, process_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134, address = 0x2061510000False1
Fn
MODLOADbase_address = 0x7ffb73480000True1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName, value_name = ComputerNameTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Services\Tcpip\ParametersTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters, value_name = HostnameFalse1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerNameTrue1
Fn
REGOPEN_KEYreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName, value_name = ComputerNameTrue1
Fn
REGREAD_VALUEreg_name = \Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName, value_name = 9True1
Fn
MODLOADmodule_name = sspicli.dll, base_address = 0x0True1
Fn
SYSGET_INFOtype = SYSTEM_BASIC_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESSOR_INFORMATIONTrue1
Fn
PROCGET_INFOprocess_name = \device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\csrss.exe, os_pid = 0x134True1
Fn
MODLOADbase_address = 0x7ffb71500000True1
Fn
MODLOADmodule_name = sspicli.dll, base_address = 0x0True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUEFalse1
Fn
REGREAD_VALUEvalue_name = SecurityProvidersFalse1
Fn
REGOPEN_KEYTrue2
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = crashonauditfailTrue1
Fn
Thread 0x2cc
(Host: 14, Network: 0)
+
CategoryOperationInformationSuccessAmountLogfile
REGOPEN_KEYTrue2
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SystemSetupInProgressTrue1
Fn
SYSSLEEPTrue1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)True1
Fn
REGOPEN_KEYTrue1
Fn
REGREAD_VALUETrue1
Fn
REGREAD_VALUEvalue_name = SystemSetupInProgressTrue1
Fn
SYSSLEEPFalse1
Fn
SYSSLEEPduration = 1 milliseconds (0.001 seconds)False1
Fn
Process #19: wallpaperhost.exe
+
InformationValue
ID / OS PID#19 / 0x2ac
OS Parent PID0x290 (\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wallpaperhost.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wallpaperhost.exe
Command LineX:\windows\system32\WallpaperHost.exe
MonitorStart Time: 00:02:04, Reason: Child Process
UnmonitorEnd Time: 00:02:04, Reason: Terminated
Monitor Duration00:00:00
OS Thread IDs
RemarksNo high level activity detected in monitored regions
Process #20: wallpaperhost.exe
+
InformationValue
ID / OS PID#20 / 0x2b8
OS Parent PID0x290 (\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wallpaperhost.exe)
Initial Working DirectoryX:\windows\system32
File Name\device\ramdisk{d9b257fc-684e-4dcb-ab79-03cfa2f6b750}\windows\system32\wallpaperhost.exe
Command LineX:\windows\system32\WallpaperHost.exe
MonitorStart Time: 00:02:04, Reason: Child Process
UnmonitorEnd Time: 00:02:04, Reason: Terminated
Monitor Duration00:00:00
OS Thread IDs
RemarksNo high level activity detected in monitored regions
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefox with deactivated setting "security.fileuri.strict_origin_policy".


Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image