VMRay Analyzer Report
Monitored Processes
Process Graph
Behavior Information - Sequential View
Process #1: tax tool.exe
(Host: 212, Network: 0)
+
InformationValue
ID / OS PID#1 / 0x990
OS Parent PID0x7cc (c:\windows\explorer.exe)
Initial Working DirectoryC:\Users\WI2yhmtI onvScY7Pe\Desktop
File Namec:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe
Command Line"C:\Users\WI2yhmtI onvScY7Pe\Desktop\Tax Tool.exe"
MonitorStart Time: 00:00:37, Reason: Analysis Target
UnmonitorEnd Time: 00:01:09, Reason: Terminated
Monitor Duration00:00:32
OS Thread IDs
#1
0x7BC
#2
0x9EC
Region
+
NameStart VAEnd VATypePermissionsMonitoredDumpYARA MatchActions
Tax Tool.exe0x001400000x00163fffMemory Mapped FileReadable, Writable, ExecutableTrueTrueFalse
private_0x00000000008200000x008200000x0083ffffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x00000000008200000x008200000x0082ffffPagefile Backed MemoryReadable, WritableTrueFalseFalse
private_0x00000000008300000x008300000x00833fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000008400000x008400000x00841fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000008400000x008400000x00840fffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x00000000008500000x008500000x00863fffPagefile Backed MemoryReadableTrueFalseFalse
private_0x00000000008700000x008700000x008affffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000008b00000x008b00000x009affffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x00000000009b00000x009b00000x009b3fffPagefile Backed MemoryReadableTrueFalseFalse
private_0x00000000009c00000x009c00000x009c1fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000009d00000x009d00000x00a0ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000000a100000x00a100000x00a10fffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x0000000000a200000x00a200000x00a20fffPagefile Backed MemoryReadable, WritableTrueFalseFalse
private_0x0000000000a700000x00a700000x00a7ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000000af00000x00af00000x00beffffPrivate MemoryReadable, WritableTrueFalseFalse
locale.nls0x00bf00000x00cadfffMemory Mapped FileReadableFalseFalseFalse
private_0x0000000000cb00000x00cb00000x00daffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000000dd00000x00dd00000x00e5ffffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x0000000000e600000x00e600000x00fe7fffPagefile Backed MemoryReadableTrueFalseFalse
private_0x00000000010500000x010500000x0105ffffPrivate MemoryReadable, WritableTrueFalseFalse
SortDefault.nls0x010600000x01396fffMemory Mapped FileReadableFalseFalseFalse
pagefile_0x00000000013a00000x013a00000x01520fffPagefile Backed MemoryReadableTrueFalseFalse
pagefile_0x00000000015300000x015300000x0292ffffPagefile Backed MemoryReadableTrueFalseFalse
private_0x00000000029300000x029300000x02a2ffffPrivate MemoryReadable, WritableTrueFalseFalse
wow64win.dll0x64da00000x64e12fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
wow64.dll0x64e200000x64e6efffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
wow64cpu.dll0x64e700000x64e77fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
ntmarta.dll0x743200000x74347fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
secur32.dll0x743500000x74359fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
rsaenh.dll0x743600000x7438efffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
bcrypt.dll0x743900000x743aafffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
cryptsp.dll0x743b00000x743c2fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
apphelp.dll0x743d00000x74460fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
bcryptprimitives.dll0x744700000x744c8fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
cryptbase.dll0x744d00000x744d9fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
sspicli.dll0x744e00000x744fdfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
msvcrt.dll0x745a00000x7465dfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
gdi32.dll0x746600000x747acfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
shell32.dll0x747b00000x75b6efffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
rpcrt4.dll0x75b700000x75c1bfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
user32.dll0x75dd00000x75f0ffffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
psapi.dll0x75f100000x75f15fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
windows.storage.dll0x75f200000x763fcfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
kernel32.dll0x764600000x7654ffffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
ole32.dll0x768000000x768e9fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
msctf.dll0x769c00000x76adffffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
shlwapi.dll0x76ae00000x76b23fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
advapi32.dll0x76d700000x76deafffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
SHCore.dll0x76df00000x76e7cfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
kernel.appcore.dll0x76e800000x76e8bfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
sechost.dll0x76e900000x76ed2fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
KernelBase.dll0x76fa00000x77115fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
combase.dll0x771200000x772d9fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
profapi.dll0x773400000x7734efffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
imm32.dll0x773500000x7737afffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
powrprof.dll0x773800000x773c3fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
ntdll.dll0x773d00000x77548fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
pagefile_0x000000007f7000000x7f7000000x7f7fffffPagefile Backed MemoryReadableTrueFalseFalse
pagefile_0x000000007f8000000x7f8000000x7f822fffPagefile Backed MemoryReadableTrueFalseFalse
private_0x000000007f8280000x7f8280000x7f82afffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007f82b0000x7f82b0000x7f82dfffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007f82e0000x7f82e0000x7f82efffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007f82f0000x7f82f0000x7f82ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrueFalseFalse
private_0x000000007fff00000x7fff00000x7ffd2ef5ffffPrivate MemoryReadableTrueFalseFalse
ntdll.dll0x7ffd2ef600000x7ffd2f121fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
private_0x00007ffd2f1220000x7ffd2f1220000x7ffffffeffffPrivate MemoryReadableTrueFalseFalse
Threads
Thread 0x7bc
(Host: 212, Network: 0)
+
CategoryOperationInformationSuccessCountLogfile
MODGET_HANDLEmodule_name = c:\windows\syswow64\kernel32.dll, base_address = 0x76460000True1
Fn
MODGET_HANDLEmodule_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, base_address = 0x140000True1
Fn
MODGET_HANDLEmodule_name = c:\windows\syswow64\ntdll.dll, base_address = 0x773d0000True1
Fn
MODLOADmodule_name = NTDLL, base_address = 0x773d0000True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\ntdll.dll, function = RtlAddVectoredExceptionHandler, address = 0x7742f090True1
Fn
MODGET_HANDLEmodule_name = advapi32.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = advapi32.dll, base_address = 0x76d70000True1
Fn
MODLOADmodule_name = NTDLL, base_address = 0x773d0000True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\ntdll.dll, function = RtlInitializeCriticalSection, address = 0x774295f0True1
Fn
MODGET_HANDLEmodule_name = shlwapi.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = shlwapi.dll, base_address = 0x76ae0000True1
Fn
REGOPEN_KEYreg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersionTrue1
Fn
REGREAD_VALUEreg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion, value_name = InstallDate, data_ident_out = 0True1
Fn
REGOPEN_KEYreg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersionTrue1
Fn
REGREAD_VALUEreg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion, value_name = DigitalProductIdFalse1
Fn
MODGET_HANDLEmodule_name = shell32.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = shell32.dll, base_address = 0x747b0000True1
Fn
MODGET_HANDLEmodule_name = ole32.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = ole32.dll, base_address = 0x76800000True1
Fn
MODLOADmodule_name = api-ms-win-core-com-l1-1-0, base_address = 0x77120000True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\combase.dll, function = CLSIDFromString, address = 0x771d1390True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_OPERATION, READ_CONTROL, desired_access = PROCESS_VM_OPERATION, READ_CONTROLTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
MODGET_HANDLEmodule_name = psapi.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = psapi.dll, base_address = 0x75f10000True1
Fn
MODGET_FILENAMEprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, file_name = C:\Users\WI2yhmtI onvScY7Pe\Desktop\Tax Tool.exe, module_name = psapi.dll, os_pid = 0x990True1
Fn
MODGET_HANDLEmodule_name = secur32.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = secur32.dll, base_address = 0x74350000True1
Fn
MODLOADmodule_name = SSPICLI, base_address = 0x744e0000True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\sspicli.dll, function = GetUserNameExW, address = 0x744ec5f0True1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
FILECREATE_DIRFalse1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEdesired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEdesired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALFalse1
Fn
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, desired_access = FILE_READ_EA, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_OPEN, create_options = FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
MODGET_FILENAMEprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, file_name = C:\Users\WI2yhmtI onvScY7Pe\Desktop\Tax Tool.exe, module_name = secur32.dll, os_pid = 0x990True1
Fn
MODGET_HANDLEmodule_name = c:\windows\syswow64\user32.dll, base_address = 0x75dd0000True1
Fn
KEYBOARDGET_INFOtype = KB_LOCALE_IDTrue2
Fn
FILECREATEfile_name = vmgenerationcounter, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = hgfs, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = vmci, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
REGOPEN_KEYreg_name = HKEY_LOCAL_MACHINE\SOFTWARE\VMware, Inc.\VMware ToolsFalse1
Fn
FILECREATEfile_name = vboxguest, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = vboxmouse, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = vboxvideo, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = vboxminirddn, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = vboxtrayipc, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
REGOPEN_KEYreg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Oracle\VirtualBox Guest AdditionsFalse1
Fn
REGOPEN_KEYreg_name = HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__False1
Fn
MUTEXCREATEmutex_name = MicrosoftVirtualPC7UserServiceMakeSureWe'reTheOnlyOneMutex, initial_owner = 0True1
Fn
FILECREATEfile_name = virtualmachineservices, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = prl_pv, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = prl_tg, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = prl_time, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
REGOPEN_KEYreg_name = HKEY_LOCAL_MACHINE\HARDWARE\Description\SystemTrue1
Fn
REGREAD_VALUEreg_name = HKEY_LOCAL_MACHINE\HARDWARE\Description\System, value_name = SystemBiosVersion, data_ident_out = 0True1
Fn
REGREAD_VALUEreg_name = HKEY_LOCAL_MACHINE\HARDWARE\Description\System, value_name = SystemBiosVersion, data_ident_out = PTLTD - 6040000True1
Fn
FILECREATEfile_name = c:\popupkiller.exe, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = c:\stimulator.exe, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = c:\tools\execute.exe, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
MODLOADmodule_name = SbieDll.dll, base_address = 0x0False1
Fn
MUTEXCREATEmutex_name = Sandboxie_SingleInstanceMutex_Control, initial_owner = 0True1
Fn
MUTEXCREATEmutex_name = Frz_State, initial_owner = 0True1
Fn
FILECREATEfile_name = npf_ndiswanip, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
MODGET_HANDLEmodule_name = c:\windows\syswow64\kernel32.dll, base_address = 0x76460000True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = wine_get_unix_file_name, address = 0x0False1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\Software\WINEFalse1
Fn
REGOPEN_KEYreg_name = HKEY_LOCAL_MACHINE\Software\WINEFalse1
Fn
FILECREATEfile_name = sice, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = siwvid, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = siwdebug, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = ntice, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = regvxg, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = filevxg, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = regsys, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = filem, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = trw, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = icext, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTINGFalse1
Fn
MUTEXCREATEmutex_name = 4B000000D586D2D8AB6E07EC44CC9183, initial_owner = 0True1
Fn
MUTEXOPENmutex_name = C0000000844EE6C40648470D345E7B65, desired_access = SYNCHRONIZEFalse1
Fn
SYSSLEEPduration = 0 milliseconds (0.000 seconds)True7
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, GENERIC_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
SYSSLEEPduration = 0 milliseconds (0.000 seconds)True7
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\desktop (create shortcut).igb, desired_access = GENERIC_WRITE, GENERIC_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
SYSSLEEPduration = 0 milliseconds (0.000 seconds)True7
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\windows powershell (x86).ezu, desired_access = GENERIC_WRITE, GENERIC_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
SYSSLEEPduration = 0 milliseconds (0.000 seconds)True7
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe, desired_access = GENERIC_WRITE, GENERIC_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\MicrosoftTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\NarratorTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\WABTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FeedsTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\WcmSvcTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\NarratorTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\SpeechTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaxTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\GameBarTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\KeyboardTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\WispTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FTPTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDriveTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\WindowsTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\SpeechTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDriveTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\UnistoreTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\WcmSvcTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\UserDataTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaxTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FTPTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\WindowsTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\SpeechTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\PeerNetTrue2
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\KeyboardTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\WABTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\PimTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDriveTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Java VMTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\PoomTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\PeerNetTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\WABTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\MSFTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\KeyboardTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\WispTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\WABTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\PeerNetTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\SkyDriveTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaxTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FTPTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\F12True1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FTPTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\WindowsTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\OskTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\WcmSvcTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\SkyDriveTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\CuxiyTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Java VMTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\HayfraTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\PoomTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\YgizgoTrue1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGOPEN_KEYreg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersionTrue1
Fn
REGREAD_VALUEreg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion, value_name = InstallDate, data_ident_out = 0True1
Fn
REGOPEN_KEYreg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersionTrue1
Fn
REGREAD_VALUEreg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion, value_name = DigitalProductIdFalse1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
FILECREATE_DIRFalse1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEdesired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEdesired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALFalse1
Fn
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, size = 124416True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe, size = 124416True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe, desired_access = FILE_WRITE_EA, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_OPEN, create_options = FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, create_disposition = OPEN_EXISTING, file_attributes = FILE_FLAG_BACKUP_SEMANTICSTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe, desired_access = FILE_WRITE_ATTRIBUTES, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java, desired_access = FILE_WRITE_ATTRIBUTES, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = FILE_WRITE_ATTRIBUTES, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player, desired_access = FILE_WRITE_ATTRIBUTES, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\desktop (create shortcut).igb, desired_access = FILE_WRITE_ATTRIBUTES, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player, desired_access = FILE_WRITE_ATTRIBUTES, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\windows powershell (x86).ezu, desired_access = FILE_WRITE_ATTRIBUTES, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player, desired_access = FILE_WRITE_ATTRIBUTES, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGFalse1
Fn
PROCCREATEprocess_name = "C:\Users\WI2yhmtI onvScY7Pe\AppData\Roaming\Sun\Java\Devices.exe", os_tid = 0xbcc, os_pid = 0x84, creation_flags = CREATE_DEFAULT_ERROR_MODE, current_directory = C:\Users\WI2yhmtI onvScY7Pe\AppData\Roaming, show_window = SW_HIDETrue1
Fn
SYSSLEEPduration = -1 (infinite)True1
Fn
MUTEXRELEASEmutex_name = 4B000000D586D2D8AB6E07EC44CC9183True1
Fn
FILECREATEfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.bat, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue2
Fn
FILEWRITEfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.bat, size = 208True1
Fn
Data
PROCCREATEprocess_name = "C:\Windows\system32\cmd.exe" \c "C:\Users\WI2YHM~1\AppData\Local\Temp\upd823d0e12.bat", os_tid = 0xcb0, os_pid = 0xcac, creation_flags = CREATE_DEFAULT_ERROR_MODE, startup_flags = STARTF_USESHOWWINDOW, show_window = SW_HIDETrue1
Fn
Process #2: devices.exe
(Host: 83, Network: 0)
+
InformationValue
ID / OS PID#2 / 0x84
OS Parent PID0x990 (c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe)
Initial Working DirectoryC:\Users\WI2yhmtI onvScY7Pe\AppData\Roaming
File Namec:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe
Command Line"C:\Users\WI2yhmtI onvScY7Pe\AppData\Roaming\Sun\Java\Devices.exe"
MonitorStart Time: 00:00:57, Reason: Child Process
UnmonitorEnd Time: 00:01:09, Reason: Terminated
Monitor Duration00:00:12
OS Thread IDs
#3
0xBCC
#4
0x8E4
Region
+
NameStart VAEnd VATypePermissionsMonitoredDumpYARA MatchActions
Devices.exe0x00bd00000x00bf3fffMemory Mapped FileReadable, Writable, ExecutableTrueTrueFalse
private_0x0000000000c400000x00c400000x00c5ffffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x0000000000c400000x00c400000x00c4ffffPagefile Backed MemoryReadable, WritableTrueFalseFalse
private_0x0000000000c500000x00c500000x00c53fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000000c600000x00c600000x00c61fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000000c600000x00c600000x00c60fffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x0000000000c700000x00c700000x00c83fffPagefile Backed MemoryReadableTrueFalseFalse
private_0x0000000000c900000x00c900000x00ccffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000000cd00000x00cd00000x00dcffffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x0000000000dd00000x00dd00000x00dd3fffPagefile Backed MemoryReadableTrueFalseFalse
private_0x0000000000de00000x00de00000x00de1fffPrivate MemoryReadable, WritableTrueFalseFalse
locale.nls0x00df00000x00eadfffMemory Mapped FileReadableFalseFalseFalse
private_0x0000000000eb00000x00eb00000x00eeffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000000ef00000x00ef00000x00ef0fffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x0000000000f000000x00f000000x00f00fffPagefile Backed MemoryReadable, WritableTrueFalseFalse
private_0x0000000000f600000x00f600000x00f6ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000010500000x010500000x0114ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000011f00000x011f00000x0127ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000012800000x012800000x0137ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000014c00000x014c00000x014cffffPrivate MemoryReadable, WritableTrueFalseFalse
SortDefault.nls0x014d00000x01806fffMemory Mapped FileReadableFalseFalseFalse
pagefile_0x00000000018100000x018100000x01997fffPagefile Backed MemoryReadableTrueFalseFalse
pagefile_0x00000000019a00000x019a00000x01b20fffPagefile Backed MemoryReadableTrueFalseFalse
pagefile_0x0000000001b300000x01b300000x02f2ffffPagefile Backed MemoryReadableTrueFalseFalse
wow64win.dll0x64da00000x64e12fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
wow64.dll0x64e200000x64e6efffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
wow64cpu.dll0x64e700000x64e77fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
ntmarta.dll0x743200000x74347fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
secur32.dll0x743500000x74359fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
rsaenh.dll0x743600000x7438efffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
bcrypt.dll0x743900000x743aafffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
cryptsp.dll0x743b00000x743c2fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
apphelp.dll0x743d00000x74460fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
bcryptprimitives.dll0x744700000x744c8fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
cryptbase.dll0x744d00000x744d9fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
sspicli.dll0x744e00000x744fdfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
msvcrt.dll0x745a00000x7465dfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
gdi32.dll0x746600000x747acfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
shell32.dll0x747b00000x75b6efffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
rpcrt4.dll0x75b700000x75c1bfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
user32.dll0x75dd00000x75f0ffffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
psapi.dll0x75f100000x75f15fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
windows.storage.dll0x75f200000x763fcfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
kernel32.dll0x764600000x7654ffffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
ole32.dll0x768000000x768e9fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
msctf.dll0x769c00000x76adffffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
shlwapi.dll0x76ae00000x76b23fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
advapi32.dll0x76d700000x76deafffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
SHCore.dll0x76df00000x76e7cfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
kernel.appcore.dll0x76e800000x76e8bfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
sechost.dll0x76e900000x76ed2fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
KernelBase.dll0x76fa00000x77115fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
combase.dll0x771200000x772d9fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
profapi.dll0x773400000x7734efffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
imm32.dll0x773500000x7737afffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
powrprof.dll0x773800000x773c3fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
ntdll.dll0x773d00000x77548fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
pagefile_0x000000007e3f00000x7e3f00000x7e4effffPagefile Backed MemoryReadableTrueFalseFalse
pagefile_0x000000007e4f00000x7e4f00000x7e512fffPagefile Backed MemoryReadableTrueFalseFalse
private_0x000000007e5130000x7e5130000x7e513fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007e5180000x7e5180000x7e518fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007e51a0000x7e51a0000x7e51cfffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007e51d0000x7e51d0000x7e51ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrueFalseFalse
private_0x000000007fff00000x7fff00000x7ffd2ef5ffffPrivate MemoryReadableTrueFalseFalse
ntdll.dll0x7ffd2ef600000x7ffd2f121fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
private_0x00007ffd2f1220000x7ffd2f1220000x7ffffffeffffPrivate MemoryReadableTrueFalseFalse
Threads
Thread 0xbcc
(Host: 83, Network: 0)
+
CategoryOperationInformationSuccessCountLogfile
MODGET_HANDLEmodule_name = c:\windows\syswow64\kernel32.dll, base_address = 0x76460000True1
Fn
MODGET_HANDLEmodule_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe, base_address = 0xbd0000True1
Fn
MODGET_HANDLEmodule_name = c:\windows\syswow64\ntdll.dll, base_address = 0x773d0000True1
Fn
MODLOADmodule_name = NTDLL, base_address = 0x773d0000True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\ntdll.dll, function = RtlAddVectoredExceptionHandler, address = 0x7742f090True1
Fn
MODGET_HANDLEmodule_name = advapi32.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = advapi32.dll, base_address = 0x76d70000True1
Fn
MODLOADmodule_name = NTDLL, base_address = 0x773d0000True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\ntdll.dll, function = RtlInitializeCriticalSection, address = 0x774295f0True1
Fn
MODGET_HANDLEmodule_name = shlwapi.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = shlwapi.dll, base_address = 0x76ae0000True1
Fn
REGOPEN_KEYreg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersionTrue1
Fn
REGREAD_VALUEreg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion, value_name = InstallDate, data_ident_out = 0True1
Fn
REGOPEN_KEYreg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersionTrue1
Fn
REGREAD_VALUEreg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion, value_name = DigitalProductIdFalse1
Fn
MODGET_HANDLEmodule_name = shell32.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = shell32.dll, base_address = 0x747b0000True1
Fn
MODGET_HANDLEmodule_name = ole32.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = ole32.dll, base_address = 0x76800000True1
Fn
MODLOADmodule_name = api-ms-win-core-com-l1-1-0, base_address = 0x77120000True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\combase.dll, function = CLSIDFromString, address = 0x771d1390True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_OPERATION, READ_CONTROL, desired_access = PROCESS_VM_OPERATION, READ_CONTROLTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
MODGET_HANDLEmodule_name = psapi.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = psapi.dll, base_address = 0x75f10000True1
Fn
MODGET_FILENAMEprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, file_name = C:\Users\WI2yhmtI onvScY7Pe\AppData\Roaming\Sun\Java\Devices.exe, module_name = psapi.dll, os_pid = 0x990True1
Fn
MODGET_HANDLEmodule_name = secur32.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = secur32.dll, base_address = 0x74350000True1
Fn
MODLOADmodule_name = SSPICLI, base_address = 0x744e0000True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\sspicli.dll, function = GetUserNameExW, address = 0x744ec5f0True1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
FILECREATE_DIRFalse1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEdesired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEdesired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALFalse1
Fn
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe, desired_access = FILE_READ_EA, file_attributes = FILE_ATTRIBUTE_NORMAL, create_disposition = FILE_OPEN, create_options = FILE_NON_DIRECTORY_FILE, ea_buffer = 0, ea_length = 0True1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 265True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 265True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 529True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
MUTEXCREATEmutex_name = 9C0000002CCF1F00ECD770C403E9DE7B, initial_owner = 1True1
Fn
MUTEXOPENmutex_name = D20000002A14C6E52964F51932B9F49F, desired_access = SYNCHRONIZEFalse2
Fn
PROCCREATEprocess_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, os_tid = 0x540, os_pid = 0x2ec, creation_flags = CREATE_SUSPENDED, show_window = SW_HIDETrue1
Fn
MUTEXCREATEmutex_name = 54000000F61A7DE2C294AD9653CFD4FD, initial_owner = 1True1
Fn
MEMALLOCaddress = 0x4eb0000, process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, os_pid = 0x2ec, size = 147456, allocation_type = MEM_COMMIT, MEM_RESERVE, protection = PAGE_EXECUTE_READWRITETrue1
Fn
MEMWRITEaddress = 0x4eb0000, process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, os_pid = 0x2ec, size = 147456True1
Fn
Data
MEMWRITEaddress = 0x4ece724, process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, os_pid = 0x2ec, size = 4True1
Fn
Data
MEMWRITEaddress = 0x4ece840, process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, os_pid = 0x2ec, size = 4True1
Fn
Data
MEMWRITEaddress = 0x4ecee38, process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, os_pid = 0x2ec, size = 4True1
Fn
Data
THREADCREATEprocess_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, os_pid = 0x2ec, proc_address = 0x4ebc978, flags = THREAD_RUNS_IMMEDIATELYTrue1
Fn
MUTEXOPENmutex_name = A1000000DA6AF38235D35BF570C2C4E9, desired_access = SYNCHRONIZEFalse2
Fn
PROCCREATEprocess_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, os_tid = 0xc58, os_pid = 0xc54, creation_flags = CREATE_SUSPENDED, show_window = SW_HIDETrue1
Fn
MUTEXCREATEmutex_name = AD0000002B4477546D3A308A977C30F1, initial_owner = 1True1
Fn
MEMALLOCaddress = 0x5b0000, process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, os_pid = 0xc54, size = 147456, allocation_type = MEM_COMMIT, MEM_RESERVE, protection = PAGE_EXECUTE_READWRITETrue1
Fn
MEMWRITEaddress = 0x5b0000, process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, os_pid = 0xc54, size = 147456True1
Fn
Data
MEMWRITEaddress = 0x5ce724, process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, os_pid = 0xc54, size = 4True1
Fn
Data
MEMWRITEaddress = 0x5ce840, process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, os_pid = 0xc54, size = 4True1
Fn
Data
MEMWRITEaddress = 0x5cee38, process_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, os_pid = 0xc54, size = 4True1
Fn
Data
THREADCREATEprocess_name = C:\Windows\SysWOW64\svchost.exe -k netsvcs, os_pid = 0xc54, proc_address = 0x5bc978, flags = THREAD_RUNS_IMMEDIATELYTrue1
Fn
Process #3: svchost.exe
(Host: 1960, Network: 1)
+
InformationValue
ID / OS PID#3 / 0x2ec
OS Parent PID0x84 (c:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe)
Initial Working DirectoryC:\Users\WI2yhmtI onvScY7Pe\AppData\Roaming
File Namec:\windows\syswow64\svchost.exe
Command LineC:\Windows\SysWOW64\svchost.exe -k netsvcs
MonitorStart Time: 00:00:58, Reason: Child Process
UnmonitorEnd Time: 00:02:38, Reason: Terminated by Timeout
Monitor Duration00:01:40
OS Thread IDs
#5
0x540
#6
0x7E4
#7
0x24C
#17
0xD4C
#18
0xD50
#21
0xD6C
#22
0xD70
#23
0xD74
#24
0xD78
#25
0xD7C
#26
0xD80
#27
0xD84
#28
0xD88
#34
0xDA0
#35
0xDA4
#36
0xDAC
Region
+
NameStart VAEnd VATypePermissionsMonitoredDumpYARA MatchActions
svchost.exe0x009000000x0090afffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
pagefile_0x0000000000db00000x00db00000x04daffffPagefile Backed Memory-TrueFalseFalse
private_0x0000000004db00000x04db00000x04dcffffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x0000000004db00000x04db00000x04dbffffPagefile Backed MemoryReadable, WritableTrueFalseFalse
svchost.exe.mui0x04dc00000x04dc0fffMemory Mapped FileReadableFalseFalseFalse
private_0x0000000004dd00000x04dd00000x04dd0fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000004dd00000x04dd00000x04dd0fffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x0000000004de00000x04de00000x04df3fffPagefile Backed MemoryReadableTrueFalseFalse
private_0x0000000004e000000x04e000000x04e3ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000004e400000x04e400000x04e7ffffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x0000000004e800000x04e800000x04e83fffPagefile Backed MemoryReadableTrueFalseFalse
pagefile_0x0000000004e900000x04e900000x04e90fffPagefile Backed MemoryReadableTrueFalseFalse
private_0x0000000004ea00000x04ea00000x04ea1fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000004eb00000x04eb00000x04ed3fffPrivate MemoryReadable, Writable, ExecutableTrueFalseFalse
private_0x0000000004ee00000x04ee00000x04f1ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000004ee00000x04ee00000x04efefffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000004ee00000x04ee00000x04f1ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000004f200000x04f200000x04f5ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000004f200000x04f200000x04f5ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000004f600000x04f600000x04f9ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000004fa00000x04fa00000x04fdffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000004fe00000x04fe00000x04fe0fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000004ff00000x04ff00000x04ff0fffPrivate MemoryReadable, Writable, ExecutableTrueFalseFalse
private_0x00000000050000000x050000000x05003fffPrivate MemoryReadable, WritableTrueFalseFalse
locale.nls0x050100000x050cdfffMemory Mapped FileReadableFalseFalseFalse
private_0x00000000050d00000x050d00000x050e2fffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x00000000050d00000x050d00000x050d0fffPagefile Backed MemoryReadable, WritableTrueFalseFalse
counters.dat0x050e00000x050e0fffMemory Mapped FileReadable, WritableTrueTrueFalse
private_0x00000000050f00000x050f00000x050f6fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000051000000x051000000x051fffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000052000000x052000000x052fffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000053000000x053000000x0533ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000053400000x053400000x05340fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000053400000x053400000x05352fffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x00000000053400000x053400000x0534ffffPagefile Backed MemoryReadableTrueFalseFalse
pagefile_0x00000000053500000x053500000x05350fffPagefile Backed MemoryReadable, WritableTrueFalseFalse
private_0x00000000053600000x053600000x05363fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000053700000x053700000x053affffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000053b00000x053b00000x053effffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x00000000053f00000x053f00000x053f1fffPagefile Backed MemoryReadableTrueFalseFalse
private_0x00000000054000000x054000000x054fffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000055000000x055000000x0553ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000055400000x055400000x0557ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000055800000x055800000x055bffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000055c00000x055c00000x055c4fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000055d00000x055d00000x055e2fffPrivate MemoryReadable, WritableTrueFalseFalse
mswsock.dll.mui0x055d00000x055d2fffMemory Mapped FileReadableFalseFalseFalse
pagefile_0x00000000055e00000x055e00000x055e1fffPagefile Backed MemoryReadableTrueFalseFalse
private_0x00000000055f00000x055f00000x055f0fffPrivate MemoryReadable, WritableTrueFalseFalse
crypt32.dll.mui0x055f00000x055f9fffMemory Mapped FileReadableFalseFalseFalse
private_0x00000000056000000x056000000x057cffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000056000000x056000000x056fffffPrivate MemoryReadable, WritableTrueFalseFalse
SortDefault.nls0x057000000x05a36fffMemory Mapped FileReadableFalseFalseFalse
pagefile_0x0000000005a400000x05a400000x05bc7fffPagefile Backed MemoryReadableTrueFalseFalse
pagefile_0x0000000005bd00000x05bd00000x05d50fffPagefile Backed MemoryReadableTrueFalseFalse
pagefile_0x0000000005d600000x05d600000x0715ffffPagefile Backed MemoryReadableTrueFalseFalse
private_0x00000000071600000x071600000x0725ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000072600000x072600000x0735ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000073600000x073600000x0745ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000074600000x074600000x0755ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000075600000x075600000x0759ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000075a00000x075a00000x0769ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000076a00000x076a00000x076dffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000076e00000x076e00000x077dffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000077e00000x077e00000x077f2fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000077e00000x077e00000x0781ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000078200000x078200000x0785ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000078600000x078600000x0789ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000078600000x078600000x07872fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000078600000x078600000x07872fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000078600000x078600000x07870fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000078a00000x078a00000x078dffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000078e00000x078e00000x078f2fffPrivate MemoryReadable, WritableTrueFalseFalse
winnlsres.dll0x078e00000x078e4fffMemory Mapped FileReadableFalseFalseFalse
winnlsres.dll.mui0x078f00000x078fffffMemory Mapped FileReadableFalseFalseFalse
private_0x00000000079000000x079000000x0793ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000079400000x079400000x0797ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000079a00000x079a00000x079a4fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000007a000000x07a000000x07baffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000007a000000x07a000000x07afffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000007b000000x07b000000x07bfffffPrivate MemoryReadable, WritableTrueFalseFalse
wow64win.dll0x64da00000x64e12fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
wow64.dll0x64e200000x64e6efffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
wow64cpu.dll0x64e700000x64e77fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
ncryptsslp.dll0x736600000x73679fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
cabinet.dll0x736800000x736a1fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
webio.dll0x736b00000x73717fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
dhcpcsvc.dll0x737200000x73733fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
dhcpcsvc6.dll0x737400000x73752fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
cryptnet.dll0x737600000x73785fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
gpapi.dll0x737900000x737aefffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
dpapi.dll0x737b00000x737b7fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
ntasn1.dll0x737c00000x737e7fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
ncrypt.dll0x737f00000x7380ffffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
mskeyprotect.dll0x738100000x7381ffffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
schannel.dll0x738200000x7387ffffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
comctl32.dll0x738800000x73a88fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
FWPUCLNT.DLL0x73a900000x73ad5fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
rasadhlp.dll0x73ae00000x73ae7fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
dnsapi.dll0x73af00000x73b73fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
mswsock.dll0x73b800000x73bcdfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
winhttp.dll0x73bd00000x73c76fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
winnsi.dll0x73c800000x73c87fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
IPHLPAPI.DLL0x73c900000x73cbffffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
urlmon.dll0x73cc00000x73e1ffffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
iertutil.dll0x73e200000x740e0fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
wininet.dll0x740f00000x74313fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
ntmarta.dll0x743200000x74347fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
secur32.dll0x743500000x74359fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
rsaenh.dll0x743600000x7438efffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
bcrypt.dll0x743900000x743aafffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
cryptsp.dll0x743b00000x743c2fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
OnDemandConnRouteHelper.dll0x743d00000x743e0fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
uxtheme.dll0x743f00000x74464fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
bcryptprimitives.dll0x744700000x744c8fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
cryptbase.dll0x744d00000x744d9fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
sspicli.dll0x744e00000x744fdfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
msvcrt.dll0x745a00000x7465dfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
gdi32.dll0x746600000x747acfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
shell32.dll0x747b00000x75b6efffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
rpcrt4.dll0x75b700000x75c1bfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
user32.dll0x75dd00000x75f0ffffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
psapi.dll0x75f100000x75f15fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
windows.storage.dll0x75f200000x763fcfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
Wldap32.dll0x764000000x76452fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
kernel32.dll0x764600000x7654ffffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
oleaut32.dll0x765500000x765e1fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
crypt32.dll0x765f00000x76764fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
msasn1.dll0x768f00000x768fdfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
wintrust.dll0x769000000x76941fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
nsi.dll0x769500000x76956fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
ws2_32.dll0x769600000x769bbfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
msctf.dll0x769c00000x76adffffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
shlwapi.dll0x76ae00000x76b23fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
advapi32.dll0x76d700000x76deafffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
SHCore.dll0x76df00000x76e7cfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
kernel.appcore.dll0x76e800000x76e8bfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
kernel.appcore.dll0x76e800000x76e8bfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
sechost.dll0x76e900000x76ed2fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
KernelBase.dll0x76fa00000x77115fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
combase.dll0x771200000x772d9fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
profapi.dll0x773400000x7734efffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
imm32.dll0x773500000x7737afffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
powrprof.dll0x773800000x773c3fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
ntdll.dll0x773d00000x77548fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
private_0x000000007e7c20000x7e7c20000x7e7c4fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007e7c50000x7e7c50000x7e7c7fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007e7c80000x7e7c80000x7e7cafffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007e7cb0000x7e7cb0000x7e7cdfffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007e7ce0000x7e7ce0000x7e7d0fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007e7d10000x7e7d10000x7e7d3fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007e7d40000x7e7d40000x7e7d6fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007e7d70000x7e7d70000x7e7d9fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007e7da0000x7e7da0000x7e7dcfffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007e7dd0000x7e7dd0000x7e7dffffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x000000007e7e00000x7e7e00000x7e8dffffPagefile Backed MemoryReadableTrueFalseFalse
pagefile_0x000000007e8e00000x7e8e00000x7e902fffPagefile Backed MemoryReadableTrueFalseFalse
private_0x000000007e9030000x7e9030000x7e905fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007e9060000x7e9060000x7e908fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007e9060000x7e9060000x7e908fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007e9090000x7e9090000x7e909fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007e90b0000x7e90b0000x7e90dfffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007e90e0000x7e90e0000x7e90efffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrueFalseFalse
private_0x000000007fff00000x7fff00000x7dfd2ef5ffffPrivate MemoryReadableTrueFalseFalse
pagefile_0x00007dfd2ef600000x7dfd2ef600000x7ffd2ef5ffffPagefile Backed Memory-TrueFalseFalse
ntdll.dll0x7ffd2ef600000x7ffd2f121fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
private_0x00007ffd2f1220000x7ffd2f1220000x7ffffffeffffPrivate MemoryReadableTrueFalseFalse
Injection Information
+
Injection TypeSource ProcessSource Os Thread IDInjection InfoSuccessCountLogfile
Modify Memoryc:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe0xbccaddress = 0x4eb0000, size = 147456True1
Fn
Data
Modify Memoryc:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe0xbccaddress = 0x4ece724, size = 4True1
Fn
Data
Modify Memoryc:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe0xbccaddress = 0x4ece840, size = 4True1
Fn
Data
Modify Memoryc:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe0xbccaddress = 0x4ecee38, size = 4True1
Fn
Data
Create Remote Threadc:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe0xbccaddress = 0x4ebc978, flags = THREAD_RUNS_IMMEDIATELYTrue1
Fn
Threads
Thread 0x7e4
(Host: 65, Network: 0)
+
CategoryOperationInformationSuccessCountLogfile
MODLOADmodule_name = KERNEL32.dll, base_address = 0x76460000True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = InterlockedIncrement, address = 0x76477520True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = HeapFree, address = 0x764725e0True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = GetProcessHeap, address = 0x76477910True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = HeapDestroy, address = 0x7647d940True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = HeapCreate, address = 0x76479950True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = InterlockedExchange, address = 0x76477650True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address = 0x7740da90True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = GetProcAddress, address = 0x76477940True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryA, address = 0x7647d8d0True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleA, address = 0x76479640True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = GetLastError, address = 0x76472db0True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = InterlockedDecrement, address = 0x76477560True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address = 0x764777b0True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = HeapReAlloc, address = 0x7740bae0True1
Fn
MODGET_HANDLEmodule_name = c:\windows\syswow64\ntdll.dll, base_address = 0x773d0000True1
Fn
MODLOADmodule_name = NTDLL, base_address = 0x773d0000True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\ntdll.dll, function = RtlAddVectoredExceptionHandler, address = 0x7742f090True1
Fn
MODGET_HANDLEmodule_name = advapi32.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = advapi32.dll, base_address = 0x76d70000True1
Fn
MODLOADmodule_name = NTDLL, base_address = 0x773d0000True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\ntdll.dll, function = RtlInitializeCriticalSection, address = 0x774295f0True1
Fn
MODGET_HANDLEmodule_name = shlwapi.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = shlwapi.dll, base_address = 0x76ae0000True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_OPERATION, READ_CONTROL, desired_access = PROCESS_VM_OPERATION, READ_CONTROLTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
MODGET_HANDLEmodule_name = psapi.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = psapi.dll, base_address = 0x75f10000True1
Fn
MODGET_FILENAMEprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, file_name = C:\Windows\SysWOW64\svchost.exe, module_name = psapi.dll, os_pid = 0x990True1
Fn
MUTEXCREATEmutex_name = D20000002A14C6E52964F51932B9F49F, initial_owner = 1True1
Fn
MODGET_HANDLEmodule_name = c:\windows\syswow64\user32.dll, base_address = 0x75dd0000True1
Fn
MODGET_HANDLEmodule_name = wininet.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = wininet.dll, base_address = 0x740f0000True1
Fn
MODGET_HANDLEmodule_name = secur32.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = secur32.dll, base_address = 0x74350000True1
Fn
MODLOADmodule_name = SSPICLI, base_address = 0x744e0000True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\sspicli.dll, function = GetUserNameExW, address = 0x744ec5f0True1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 529True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 1103True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
MUTEXOPENmutex_name = 4B000000D586D2D8AB6E07EC44CC9183, desired_access = SYNCHRONIZETrue1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = OnpiwaadFalse1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\desktop (create shortcut).igb, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 1103True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 1361True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
Thread 0xd6c
(Host: 122, Network: 1)
+
CategoryOperationInformationSuccessCountLogfile
MUTEXCREATEmutex_name = D9000000F219E1C779E2E7AC08DFD815, initial_owner = 0True1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = OnpiwaadFalse1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\desktop (create shortcut).igb, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 2193True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 2451True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
MUTEXCREATEmutex_name = D5000000C70E48D5408251026F4BDA97, initial_owner = 0True1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = VipougFalse1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = OnpiwaadFalse1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\desktop (create shortcut).igb, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 2967True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 3225True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGWRITE_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = VipougTrue1
Fn
Data
MUTEXRELEASEmutex_name = D5000000C70E48D5408251026F4BDA97True1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGFalse1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 300True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = VipougTrue2
Fn
Data
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = OnpiwaadFalse1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\desktop (create shortcut).igb, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 782True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 1040True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 1294True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 1584True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
MODGET_HANDLEmodule_name = crypt32.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = crypt32.dll, base_address = 0x765f0000True1
Fn
REGOPEN_KEYreg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersionTrue1
Fn
REGREAD_VALUEreg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion, value_name = InstallDate, data_ident_out = 0True1
Fn
REGOPEN_KEYreg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersionTrue1
Fn
REGREAD_VALUEreg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion, value_name = DigitalProductIdFalse1
Fn
MODGET_HANDLEmodule_name = urlmon.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = urlmon.dll, base_address = 0x73cc0000True1
Fn
INETOPEN_CONNECTIONTrue1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 4591True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 4808True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = OnpiwaadFalse1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\desktop (create shortcut).igb, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 4808True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 5066True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 5066True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 5303True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
Thread 0xd70
(Host: 231, Network: 0)
+
CategoryOperationInformationSuccessCountLogfile
MUTEXCREATEmutex_name = 7D0000008AA73D983C6DEAFF4C3848A7, initial_owner = 0True1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = OnpiwaadFalse1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\desktop (create shortcut).igb, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 2451True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 2709True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = VipougFalse1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = OnpiwaadFalse1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\desktop (create shortcut).igb, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 3485True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 3743True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 558True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 782True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = VipougTrue2
Fn
Data
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 1040True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 1294True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = OnpiwaadFalse1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\desktop (create shortcut).igb, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 1584True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 1842True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 1842True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 2080True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = VipougTrue2
Fn
Data
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = OnpiwaadFalse1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\desktop (create shortcut).igb, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 2080True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 2338True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = VipougTrue2
Fn
Data
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 2338True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 2593True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = OnpiwaadFalse1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\desktop (create shortcut).igb, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 2593True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 2851True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 2851True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 3089True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = VipougTrue2
Fn
Data
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 3089True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 3344True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = OnpiwaadFalse1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\desktop (create shortcut).igb, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 3344True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 3602True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 3602True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 3840True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = VipougTrue2
Fn
Data
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 3840True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 4095True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = OnpiwaadFalse1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\desktop (create shortcut).igb, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 4095True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 4353True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 4353True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 4591True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
Thread 0xd74
(Host: 36, Network: 0)
+
CategoryOperationInformationSuccessCountLogfile
MUTEXCREATEmutex_name = 3B000000F5DFE9C2D11C32931F7D5BB4, initial_owner = 0True1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = OnpiwaadFalse1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\desktop (create shortcut).igb, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 2709True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 2967True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE, create_disposition = OPEN_EXISTINGTrue1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
FILEMOVEdestination_file_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.tmp, source_file_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoeTrue1
Fn
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = OnpiwaadFalse1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\desktop (create shortcut).igb, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 300True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 558True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
SYSSLEEPduration = 60000 milliseconds (60.000 seconds)False1
Fn
Thread 0xd78
(Host: 1445, Network: 0)
+
CategoryOperationInformationSuccessCountLogfile
MUTEXCREATEmutex_name = C0000000844EE6C40648470D345E7B65, initial_owner = 0True1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0x414, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0x414, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0x414, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0x414, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0x414, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0x414, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0x414, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0x414, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0x414, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0x414, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0x414, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0x414, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xdc0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xdc0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xdc0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xdc0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xdc0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xdc0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xdc0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xdc0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xdc0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\program files\windows defender\mpcmdrun.exe, os_pid = 0xde0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xdc0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xdc0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xdc0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xdc0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\lsass.exe, os_pid = 0x1e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x23c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x25c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\dwm.exe, os_pid = 0x2e4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x320, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x334, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x354, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x368, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x390, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x274, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\spoolsv.exe, os_pid = 0x230, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x41c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x550, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sihost.exe, os_pid = 0x700, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\taskhostw.exe, os_pid = 0x728, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\explorer.exe, os_pid = 0x7cc, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\runtimebroker.exe, os_pid = 0x4b0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe, os_pid = 0x910, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe, os_pid = 0xa10, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\svchost.exe, os_pid = 0x590, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiadap.exe, os_pid = 0xb34, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\sppsvc.exe, os_pid = 0x6ac, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xba8, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\wbem\wmiprvse.exe, os_pid = 0xfc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\audiodg.exe, os_pid = 0x3f8, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_QUERY_INFORMATIONTrue2
Fn
PROCOPEN_TOKENprocess_name = c:\windows\syswow64\svchost.exe, os_pid = 0xc54, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
PROCOPENprocess_name = c:\windows\system32\backgroundtaskhost.exe, os_pid = 0xdc0, desired_access = PROCESS_QUERY_INFORMATIONTrue1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONFalse1
Fn
SYSGET_INFOtype = SYSTEM_PROCESS_INFORMATIONTrue1
Fn
PROCOPENprocess_name = System Idle Process, os_pid = 0x0, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = System, os_pid = 0x4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\smss.exe, os_pid = 0x108, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x150, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\wininit.exe, os_pid = 0x18c, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\csrss.exe, os_pid = 0x194, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\winlogon.exe, os_pid = 0x1c4, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
PROCOPENprocess_name = c:\windows\system32\services.exe, os_pid = 0x1dc, desired_access = PROCESS_QUERY_INFORMATIONFalse1
Fn
For performance reasons, the remaining 408 entries are omitted.
Click to download all 1408 entries as text file (1.07 MB).
Thread 0xd7c
(Host: 61, Network: 0)
+
CategoryOperationInformationSuccessCountLogfile
MUTEXCREATEmutex_name = 4A000000AF17366BF4960AE62A76878C, initial_owner = 0True1
Fn
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\Currentversion\RunTrue1
Fn
REGWRITE_VALUEreg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\Currentversion\Run, value_name = Devices.exe, data = "C:\Users\WI2yhmtI onvScY7Pe\AppData\Roaming\Sun\Java\Devices.exe"True1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 3225True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 3485True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe, size = 124416True1
Fn
Data
MODLOADmodule_name = NTDLL, base_address = 0x773d0000True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\ntdll.dll, function = RtlEnterCriticalSection, address = 0x77415e80True1
Fn
MODLOADmodule_name = NTDLL, base_address = 0x773d0000True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\ntdll.dll, function = RtlLeaveCriticalSection, address = 0x77415e00True1
Fn
SYSSLEEPduration = -1 (infinite)True39
Fn
SYSSLEEPduration = -1 (infinite)False1
Fn
Process #4: svchost.exe
(Host: 82, Network: 0)
+
InformationValue
ID / OS PID#4 / 0xc54
OS Parent PID0x84 (c:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe)
Initial Working DirectoryC:\Users\WI2yhmtI onvScY7Pe\AppData\Roaming
File Namec:\windows\syswow64\svchost.exe
Command LineC:\Windows\SysWOW64\svchost.exe -k netsvcs
MonitorStart Time: 00:01:04, Reason: Child Process
UnmonitorEnd Time: 00:02:38, Reason: Terminated by Timeout
Monitor Duration00:01:34
OS Thread IDs
#8
0xC58
#9
0xC5C
#10
0xC64
#19
0xD54
#20
0xD58
#29
0xD8C
#30
0xD90
#31
0xD94
#32
0xD98
#33
0xD9C
Region
+
NameStart VAEnd VATypePermissionsMonitoredDumpYARA MatchActions
private_0x00000000004b00000x004b00000x004cffffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x00000000004b00000x004b00000x004bffffPagefile Backed MemoryReadable, WritableTrueFalseFalse
svchost.exe.mui0x004c00000x004c0fffMemory Mapped FileReadableFalseFalseFalse
private_0x00000000004d00000x004d00000x004d0fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000004d00000x004d00000x004d0fffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x00000000004e00000x004e00000x004f3fffPagefile Backed MemoryReadableTrueFalseFalse
private_0x00000000005000000x005000000x0053ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000005400000x005400000x0057ffffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x00000000005800000x005800000x00583fffPagefile Backed MemoryReadableTrueFalseFalse
pagefile_0x00000000005900000x005900000x00590fffPagefile Backed MemoryReadableTrueFalseFalse
private_0x00000000005a00000x005a00000x005a1fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000005b00000x005b00000x005d3fffPrivate MemoryReadable, Writable, ExecutableTrueFalseFalse
private_0x00000000005e00000x005e00000x0061ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000006200000x006200000x0065ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000006600000x006600000x0069ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000006a00000x006a00000x006a0fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000006b00000x006b00000x006b6fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000006c00000x006c00000x006fffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000007000000x007000000x007fffffPrivate MemoryReadable, WritableTrueFalseFalse
locale.nls0x008000000x008bdfffMemory Mapped FileReadableFalseFalseFalse
private_0x00000000008c00000x008c00000x008c0fffPrivate MemoryReadable, Writable, ExecutableTrueFalseFalse
svchost.exe0x009000000x0090afffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
pagefile_0x00000000009100000x009100000x0490ffffPagefile Backed Memory-TrueFalseFalse
private_0x0000000004a100000x04a100000x04a13fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000004ae00000x04ae00000x04ae3fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000004b000000x04b000000x04bfffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000004c000000x04c000000x04cfffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000004e100000x04e100000x04e14fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000004f000000x04f000000x0501ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x0000000004f000000x04f000000x04ffffffPrivate MemoryReadable, WritableTrueFalseFalse
SortDefault.nls0x050000000x05336fffMemory Mapped FileReadableFalseFalseFalse
pagefile_0x00000000053400000x053400000x054c7fffPagefile Backed MemoryReadableTrueFalseFalse
pagefile_0x00000000054d00000x054d00000x05650fffPagefile Backed MemoryReadableTrueFalseFalse
pagefile_0x00000000056600000x056600000x06a5ffffPagefile Backed MemoryReadableTrueFalseFalse
wow64win.dll0x64da00000x64e12fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
wow64.dll0x64e200000x64e6efffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
wow64cpu.dll0x64e700000x64e77fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
wininet.dll0x740f00000x74313fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
ntmarta.dll0x743200000x74347fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
secur32.dll0x743500000x74359fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
rsaenh.dll0x743600000x7438efffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
bcrypt.dll0x743900000x743aafffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
cryptsp.dll0x743b00000x743c2fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
bcryptprimitives.dll0x744700000x744c8fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
cryptbase.dll0x744d00000x744d9fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
sspicli.dll0x744e00000x744fdfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
msvcrt.dll0x745a00000x7465dfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
gdi32.dll0x746600000x747acfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
rpcrt4.dll0x75b700000x75c1bfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
user32.dll0x75dd00000x75f0ffffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
psapi.dll0x75f100000x75f15fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
kernel32.dll0x764600000x7654ffffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
msctf.dll0x769c00000x76adffffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
shlwapi.dll0x76ae00000x76b23fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
advapi32.dll0x76d700000x76deafffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
sechost.dll0x76e900000x76ed2fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
KernelBase.dll0x76fa00000x77115fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
combase.dll0x771200000x772d9fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
imm32.dll0x773500000x7737afffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
ntdll.dll0x773d00000x77548fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
pagefile_0x000000007f3700000x7f3700000x7f46ffffPagefile Backed MemoryReadableTrueFalseFalse
pagefile_0x000000007f4700000x7f4700000x7f492fffPagefile Backed MemoryReadableTrueFalseFalse
private_0x000000007f4940000x7f4940000x7f496fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007f4970000x7f4970000x7f499fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007f49a0000x7f49a0000x7f49afffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007f49c0000x7f49c0000x7f49efffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007f49f0000x7f49f0000x7f49ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrueFalseFalse
private_0x000000007fff00000x7fff00000x7dfd2ef5ffffPrivate MemoryReadableTrueFalseFalse
pagefile_0x00007dfd2ef600000x7dfd2ef600000x7ffd2ef5ffffPagefile Backed Memory-TrueFalseFalse
ntdll.dll0x7ffd2ef600000x7ffd2f121fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
private_0x00007ffd2f1220000x7ffd2f1220000x7ffffffeffffPrivate MemoryReadableTrueFalseFalse
Injection Information
+
Injection TypeSource ProcessSource Os Thread IDInjection InfoSuccessCountLogfile
Modify Memoryc:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe0xbccaddress = 0x5b0000, size = 147456True1
Fn
Data
Modify Memoryc:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe0xbccaddress = 0x5ce724, size = 4True1
Fn
Data
Modify Memoryc:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe0xbccaddress = 0x5ce840, size = 4True1
Fn
Data
Modify Memoryc:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe0xbccaddress = 0x5cee38, size = 4True1
Fn
Data
Create Remote Threadc:\users\wi2yhmti onvscy7pe\appdata\roaming\sun\java\devices.exe0xbccaddress = 0x5bc978, flags = THREAD_RUNS_IMMEDIATELYTrue1
Fn
Threads
Thread 0xc5c
(Host: 72, Network: 0)
+
CategoryOperationInformationSuccessCountLogfile
MODLOADmodule_name = KERNEL32.dll, base_address = 0x76460000True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = InterlockedIncrement, address = 0x76477520True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = HeapFree, address = 0x764725e0True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = GetProcessHeap, address = 0x76477910True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = HeapDestroy, address = 0x7647d940True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = HeapCreate, address = 0x76479950True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = InterlockedExchange, address = 0x76477650True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address = 0x7740da90True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = GetProcAddress, address = 0x76477940True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = LoadLibraryA, address = 0x7647d8d0True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleA, address = 0x76479640True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = GetLastError, address = 0x76472db0True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = InterlockedDecrement, address = 0x76477560True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address = 0x764777b0True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = HeapReAlloc, address = 0x7740bae0True1
Fn
MODGET_HANDLEmodule_name = c:\windows\syswow64\ntdll.dll, base_address = 0x773d0000True1
Fn
MODLOADmodule_name = NTDLL, base_address = 0x773d0000True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\ntdll.dll, function = RtlAddVectoredExceptionHandler, address = 0x7742f090True1
Fn
MODGET_HANDLEmodule_name = advapi32.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = advapi32.dll, base_address = 0x76d70000True1
Fn
MODLOADmodule_name = NTDLL, base_address = 0x773d0000True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\ntdll.dll, function = RtlInitializeCriticalSection, address = 0x774295f0True1
Fn
MODGET_HANDLEmodule_name = shlwapi.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = shlwapi.dll, base_address = 0x76ae0000True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_OPERATION, READ_CONTROL, desired_access = PROCESS_VM_OPERATION, READ_CONTROLTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_OPERATION, desired_access = PROCESS_VM_OPERATIONTrue1
Fn
MODGET_HANDLEmodule_name = psapi.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = psapi.dll, base_address = 0x75f10000True1
Fn
MODGET_FILENAMEprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, file_name = C:\Windows\SysWOW64\svchost.exe, module_name = psapi.dll, os_pid = 0x990True1
Fn
MUTEXCREATEmutex_name = A1000000DA6AF38235D35BF570C2C4E9, initial_owner = 1True1
Fn
MODGET_HANDLEmodule_name = c:\windows\syswow64\user32.dll, base_address = 0x75dd0000True1
Fn
MODGET_HANDLEmodule_name = wininet.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = wininet.dll, base_address = 0x740f0000True1
Fn
MODGET_HANDLEmodule_name = secur32.dll, base_address = 0x0False1
Fn
MODLOADmodule_name = secur32.dll, base_address = 0x74350000True1
Fn
MODLOADmodule_name = SSPICLI, base_address = 0x744e0000True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\sspicli.dll, function = GetUserNameExW, address = 0x744ec5f0True1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 1361True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 1935True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
MUTEXOPENmutex_name = 4B000000D586D2D8AB6E07EC44CC9183, desired_access = SYNCHRONIZETrue1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = OnpiwaadFalse1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\desktop (create shortcut).igb, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
MUTEXCREATEmutex_name = 8A000000B7496798F6145935AA3E2760, initial_owner = 0True1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
PROCOPEN_TOKENprocess_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, desired_access = PROCESS_VM_WRITETrue1
Fn
USERLOOKUP_PRIVILEGEserver_name = Localhost, privilege = SeSecurityPrivilegeTrue1
Fn
USERSET_PRIVILEGEserver_name = Localhost, process_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, os_pid = 0x990, desired_access = PROCESS_VM_WRITE, disable_all_privileges = 0, privilege = SeSecurityPrivilegeTrue1
Fn
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, create_disposition = OPEN_EXISTINGTrue1
Fn
FILEREADfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 1935True1
Fn
Data
FILECREATEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, desired_access = GENERIC_WRITE, share_mode = FILE_SHARE_READ, create_disposition = CREATE_ALWAYS, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEWRITEfile_name = c:\users\wi2yhmti onvscy7pe\appdata\roaming\adobe\flash player\1e45a456cb803f4096a6a7598c65e692_8c74eee4-8873-4eb3-9315-336075ff5033.hoe, size = 2193True1
Fn
Data
MUTEXRELEASEmutex_name = 8A000000B7496798F6145935AA3E2760True1
Fn
MUTEXCREATEmutex_name = D5000000C70E48D5408251026F4BDA97, initial_owner = 0True1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = VipougTrue2
Fn
Data
REGCREATE_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGWRITE_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = VipougTrue1
Fn
Data
MUTEXRELEASEmutex_name = D5000000C70E48D5408251026F4BDA97True1
Fn
Thread 0xd8c
(Host: 1, Network: 0)
+
CategoryOperationInformationSuccessCountLogfile
MUTEXCREATEmutex_name = C0000000844EE6C40648470D345E7B65, initial_owner = 0True1
Fn
Thread 0xd90
(Host: 1, Network: 0)
+
CategoryOperationInformationSuccessCountLogfile
MUTEXCREATEmutex_name = 4A000000AF17366BF4960AE62A76878C, initial_owner = 0True1
Fn
Thread 0xd94
(Host: 4, Network: 0)
+
CategoryOperationInformationSuccessCountLogfile
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = VipougTrue2
Fn
Data
SYSSLEEPduration = -1 (infinite)False1
Fn
Thread 0xd98
(Host: 4, Network: 0)
+
CategoryOperationInformationSuccessCountLogfile
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\FaboTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fabo, value_name = VipougTrue2
Fn
Data
SYSSLEEPduration = -1 (infinite)False1
Fn
Process #5: cmd.exe
(Host: 88, Network: 0)
+
InformationValue
ID / OS PID#5 / 0xcac
OS Parent PID0x990 (c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe)
Initial Working DirectoryC:\Users\WI2yhmtI onvScY7Pe\Desktop
File Namec:\windows\syswow64\cmd.exe
Command Line"C:\Windows\system32\cmd.exe" /c "C:\Users\WI2YHM~1\AppData\Local\Temp\upd823d0e12.bat"
MonitorStart Time: 00:01:09, Reason: Child Process
UnmonitorEnd Time: 00:01:21, Reason: Terminated
Monitor Duration00:00:12
OS Thread IDs
#11
0xCB0
#16
0xD00
Region
+
NameStart VAEnd VATypePermissionsMonitoredDumpYARA MatchActions
private_0x00000000000e00000x000e00000x000fffffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x00000000000e00000x000e00000x000effffPagefile Backed MemoryReadable, WritableTrueFalseFalse
private_0x00000000000f00000x000f00000x000f3fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000001000000x001000000x00101fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000001000000x001000000x00103fffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x00000000001100000x001100000x00123fffPagefile Backed MemoryReadableTrueFalseFalse
private_0x00000000001300000x001300000x0016ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000001700000x001700000x0026ffffPrivate MemoryReadable, WritableTrueFalseFalse
pagefile_0x00000000002700000x002700000x00273fffPagefile Backed MemoryReadableTrueFalseFalse
pagefile_0x00000000002800000x002800000x00280fffPagefile Backed MemoryReadableTrueFalseFalse
private_0x00000000002900000x002900000x00291fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000002a00000x002a00000x002dffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000003000000x003000000x0030ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000003200000x003200000x0041ffffPrivate MemoryReadable, WritableTrueFalseFalse
locale.nls0x004200000x004ddfffMemory Mapped FileReadableFalseFalseFalse
private_0x00000000004e00000x004e00000x005dffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x00000000007000000x007000000x0070ffffPrivate MemoryReadable, WritableTrueFalseFalse
cmd.exe0x009c00000x00a0ffffMemory Mapped FileReadable, Writable, ExecutableTrueFalseFalse
pagefile_0x0000000000a100000x00a100000x04a0ffffPagefile Backed Memory-TrueFalseFalse
wow64win.dll0x64da00000x64e12fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
wow64.dll0x64e200000x64e6efffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
wow64cpu.dll0x64e700000x64e77fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
cmdext.dll0x744600000x74467fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
bcryptprimitives.dll0x744700000x744c8fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
cryptbase.dll0x744d00000x744d9fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
sspicli.dll0x744e00000x744fdfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
msvcrt.dll0x745a00000x7465dfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
rpcrt4.dll0x75b700000x75c1bfffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
kernel32.dll0x764600000x7654ffffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
advapi32.dll0x76d700000x76deafffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
sechost.dll0x76e900000x76ed2fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
KernelBase.dll0x76fa00000x77115fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
ntdll.dll0x773d00000x77548fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
pagefile_0x000000007e9f00000x7e9f00000x7eaeffffPagefile Backed MemoryReadableTrueFalseFalse
pagefile_0x000000007eaf00000x7eaf00000x7eb12fffPagefile Backed MemoryReadableTrueFalseFalse
private_0x000000007eb160000x7eb160000x7eb16fffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007eb180000x7eb180000x7eb1afffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007eb1b0000x7eb1b0000x7eb1bfffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007eb1d0000x7eb1d0000x7eb1ffffPrivate MemoryReadable, WritableTrueFalseFalse
private_0x000000007ffe00000x7ffe00000x7ffeffffPrivate MemoryReadableTrueFalseFalse
private_0x000000007fff00000x7fff00000x7dfd2ef5ffffPrivate MemoryReadableTrueFalseFalse
pagefile_0x00007dfd2ef600000x7dfd2ef600000x7ffd2ef5ffffPagefile Backed Memory-TrueFalseFalse
ntdll.dll0x7ffd2ef600000x7ffd2f121fffMemory Mapped FileReadable, Writable, ExecutableFalseFalseFalse
private_0x00007ffd2f1220000x7ffd2f1220000x7ffffffeffffPrivate MemoryReadableTrueFalseFalse
Threads
Thread 0xcb0
(Host: 88, Network: 0)
+
CategoryOperationInformationSuccessCountLogfile
MODGET_HANDLEmodule_name = c:\windows\syswow64\cmd.exe, base_address = 0x9c0000True1
Fn
MODGET_HANDLEmodule_name = c:\windows\syswow64\kernel32.dll, base_address = 0x76460000True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = SetThreadUILanguage, address = 0x764a2780True1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\SystemFalse1
Fn
FILEOPENfile_name = STD_OUTPUT_HANDLETrue3
Fn
FILEOPENfile_name = STD_INPUT_HANDLETrue2
Fn
REGOPEN_KEYreg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command ProcessorTrue1
Fn
REGREAD_VALUEreg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data_ident_out = 80False1
Fn
REGREAD_VALUEreg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data_ident_out = 1True1
Fn
REGREAD_VALUEreg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data_ident_out = 1False1
Fn
REGREAD_VALUEreg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data_ident_out = 0True1
Fn
REGREAD_VALUEreg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data_ident_out = 64True1
Fn
REGREAD_VALUEreg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data_ident_out = 64True1
Fn
REGREAD_VALUEreg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data_ident_out = 64False1
Fn
REGOPEN_KEYreg_name = HKEY_CURRENT_USER\Software\Microsoft\Command ProcessorTrue1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data_ident_out = 64False1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data_ident_out = 1True1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data_ident_out = 1False1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data_ident_out = 0True1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data_ident_out = 9True1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data_ident_out = 9True1
Fn
REGREAD_VALUEreg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data_ident_out = 9False1
Fn
MODGET_FILENAMEfile_name = C:\Windows\SysWOW64\cmd.exeTrue1
Fn
PROCSET_CURDIRprocess_name = c:\windows\syswow64\cmd.exe, os_pid = 0xcac, new_path_name = c:\users\wi2yhmti onvscy7pe\desktopTrue1
Fn
MODGET_HANDLEmodule_name = c:\windows\syswow64\kernel32.dll, base_address = 0x76460000True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = CopyFileExW, address = 0x7647fa80True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = IsDebuggerPresent, address = 0x7647a790True1
Fn
MODGET_PROC_ADDRESSmodule_name = c:\windows\syswow64\kernel32.dll, function = SetConsoleInputExeNameW, address = 0x770b35c0True1
Fn
FILECREATEfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.bat, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEOPENfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.batTrue3
Fn
FILEREADfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.bat, size = 8191True1
Fn
Data
FILEOPENfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.batTrue2
Fn
FILEOPENfile_name = STD_OUTPUT_HANDLETrue2
Fn
FILEOPENfile_name = STD_INPUT_HANDLETrue1
Fn
FILECREATEfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.bat, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEOPENfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.batTrue3
Fn
FILEREADfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.bat, size = 8191True1
Fn
Data
FILEOPENfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.batTrue2
Fn
FILECREATEfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.bat, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEOPENfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.batTrue3
Fn
FILEREADfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.bat, size = 8191True1
Fn
Data
FILEOPENfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.batTrue2
Fn
FILEOPENfile_name = c:\users\wi2yhmti onvscy7pe\desktop\tax tool.exe, desired_access = DELETE, share_mode = FILE_SHARE_DELETE, open_options = FILE_NON_DIRECTORY_FILE, FILE_DELETE_ON_CLOSE, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
FILEOPENfile_name = STD_OUTPUT_HANDLETrue2
Fn
FILEOPENfile_name = STD_INPUT_HANDLETrue1
Fn
FILECREATEfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.bat, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEOPENfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.batTrue3
Fn
FILEREADfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.bat, size = 8191True1
Fn
Data
FILEOPENfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.batTrue2
Fn
FILEOPENfile_name = STD_OUTPUT_HANDLETrue2
Fn
FILEOPENfile_name = STD_INPUT_HANDLETrue1
Fn
FILECREATEfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.bat, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMALTrue1
Fn
FILEOPENfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.batTrue3
Fn
FILEREADfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.bat, size = 8191True1
Fn
Data
FILEOPENfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.batTrue2
Fn
FILEOPENfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.bat, desired_access = DELETE, share_mode = FILE_SHARE_DELETE, open_options = FILE_NON_DIRECTORY_FILE, FILE_DELETE_ON_CLOSE, FILE_OPEN_FOR_BACKUP_INTENTTrue1
Fn
FILEOPENfile_name = STD_OUTPUT_HANDLETrue2
Fn
FILEOPENfile_name = STD_INPUT_HANDLETrue1
Fn
FILECREATEfile_name = c:\users\wi2yhm~1\appdata\local\temp\upd823d0e12.bat, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, create_disposition = OPEN_EXISTING, file_attributes = FILE_ATTRIBUTE_NORMALFalse1
Fn
FILEOPENfile_name = STD_ERROR_HANDLETrue3
Fn
FILEWRITEfile_name = STD_ERROR_HANDLE, size = 33True1
Fn
Data
FILEOPENfile_name = STD_OUTPUT_HANDLETrue2
Fn
FILEOPENfile_name = STD_INPUT_HANDLETrue1
Fn
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefox with deactivated setting "security.fileuri.strict_origin_policy".


Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image