Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- "Time of Day","Process Name","PID","Operation","Path","Result","Detail"
- "1:15:34.0637176 PM","rundll32.exe","9780","CreateFile","C:\Windows\Prefetch\RUNDLL32.EXE-12CD7E38.pf","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: None, AllocationSize: n/a"
- "1:15:34.0638634 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\UseFilter","NAME NOT FOUND","Length: 544"
- "1:15:34.0638733 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\DisableHeapLookaside","NAME NOT FOUND","Length: 1,024"
- "1:15:34.0638800 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\FrontEndHeapDebugOptions","NAME NOT FOUND","Length: 1,024"
- "1:15:34.0638857 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\ShutdownFlags","NAME NOT FOUND","Length: 1,024"
- "1:15:34.0638942 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\UnloadEventTraceDepth","NAME NOT FOUND","Length: 1,024"
- "1:15:34.0639026 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\TracingFlags","NAME NOT FOUND","Length: 1,024"
- "1:15:34.0639083 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\MinimumStackCommitInBytes","NAME NOT FOUND","Length: 1,024"
- "1:15:34.0639171 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\BreakOnInitializeProcessFailure","NAME NOT FOUND","Length: 1,024"
- "1:15:34.0639259 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\KeepActivationContextsAlive","NAME NOT FOUND","Length: 1,024"
- "1:15:34.0639319 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\TrackActivationContextReleases","NAME NOT FOUND","Length: 1,024"
- "1:15:34.0639373 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\MaxDeadActivationContexts","NAME NOT FOUND","Length: 1,024"
- "1:15:34.0639512 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\GlobalFlag","NAME NOT FOUND","Length: 1,024"
- "1:15:34.0639606 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\CWDIllegalInDLLSearch","NAME NOT FOUND","Length: 1,024"
- "1:15:34.0640191 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\DebugProcessHeapOnly","NAME NOT FOUND","Length: 1,024"
- "1:15:34.0736195 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\UseFilter","NAME NOT FOUND","Length: 544"
- "1:15:34.0736297 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\SearchPathMode","NAME NOT FOUND","Length: 1,024"
- "1:15:34.0737055 PM","rundll32.exe","9780","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","REPARSE","Desired Access: Query Value, Set Value"
- "1:15:34.0737251 PM","rundll32.exe","9780","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","NAME NOT FOUND","Desired Access: Query Value, Set Value"
- "1:15:34.0737387 PM","rundll32.exe","9780","RegOpenKey","HKLM\System\CurrentControlSet\Control\Srp\GP\DLL","REPARSE","Desired Access: Read"
- "1:15:34.0737499 PM","rundll32.exe","9780","RegOpenKey","HKLM\System\CurrentControlSet\Control\Srp\GP\DLL","NAME NOT FOUND","Desired Access: Read"
- "1:15:34.0737749 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled","NAME NOT FOUND","Length: 80"
- "1:15:34.0737924 PM","rundll32.exe","9780","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:34.0749193 PM","rundll32.exe","9780","CreateFileMapping","C:\Windows\System32\imm32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.0753844 PM","rundll32.exe","9780","CreateFileMapping","C:\Windows\System32\imm32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.0758445 PM","rundll32.exe","9780","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions","REPARSE","Desired Access: Read"
- "1:15:34.0759489 PM","rundll32.exe","9780","RegOpenKey","HKLM\System\CurrentControlSet\Control\Error Message Instrument\","REPARSE","Desired Access: Read"
- "1:15:34.0759643 PM","rundll32.exe","9780","RegOpenKey","HKLM\System\CurrentControlSet\Control\Error Message Instrument","NAME NOT FOUND","Desired Access: Read"
- "1:15:34.0759996 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles","NAME NOT FOUND","Length: 20"
- "1:15:34.0760591 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Compatibility32\rundll32","NAME NOT FOUND","Length: 172"
- "1:15:34.0760811 PM","rundll32.exe","9780","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\IME Compatibility","NAME NOT FOUND","Desired Access: Read"
- "1:15:34.0761732 PM","rundll32.exe","9780","RegOpenKey","HKCU\Control Panel\Desktop\MuiCached\MachineLanguageConfiguration","NAME NOT FOUND","Desired Access: Read"
- "1:15:34.0762022 PM","rundll32.exe","9780","RegOpenKey","HKLM\Software\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read"
- "1:15:34.0762345 PM","rundll32.exe","9780","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read"
- "1:15:34.0762644 PM","rundll32.exe","9780","RegEnumValue","HKCU\Control Panel\Desktop\LanguageConfiguration","NO MORE ENTRIES","Index: 0, Length: 512"
- "1:15:34.0762985 PM","rundll32.exe","9780","RegOpenKey","HKLM\Software\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read"
- "1:15:34.0763299 PM","rundll32.exe","9780","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read"
- "1:15:34.0763576 PM","rundll32.exe","9780","RegQueryValue","HKCU\Control Panel\Desktop\PreferredUILanguages","NAME NOT FOUND","Length: 12"
- "1:15:34.0763896 PM","rundll32.exe","9780","RegOpenKey","HKLM\Software\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read"
- "1:15:34.0764343 PM","rundll32.exe","9780","RegQueryValue","HKCU\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages","BUFFER OVERFLOW","Length: 12"
- "1:15:34.0766423 PM","rundll32.exe","9780","CreateFileMapping","C:\Windows\System32\en-US\rundll32.exe.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.0772581 PM","rundll32.exe","9780","CreateFile","C:\Windows\System32\shell32.dll.manifest","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:34.0774262 PM","rundll32.exe","9780","CreateFileMapping","C:\Windows\System32\shell32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.0775077 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest","NAME NOT FOUND","Length: 20"
- "1:15:34.0775771 PM","rundll32.exe","9780","CreateFile","C:\Windows\System32\shell32.dll.123.Manifest","NAME NOT FOUND","Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a"
- "1:15:34.0777752 PM","rundll32.exe","9780","CreateFileMapping","C:\Windows\System32\shell32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.0778775 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest","NAME NOT FOUND","Length: 20"
- "1:15:34.0784604 PM","rundll32.exe","9780","CreateFileMapping","C:\Windows\System32\combase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.0790110 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\PageAllocatorUseSystemHeap","NAME NOT FOUND","Length: 144"
- "1:15:34.0790605 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\PageAllocatorSystemHeapIsPrivate","NAME NOT FOUND","Length: 144"
- "1:15:34.0791043 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\AggressiveMTATesting","NAME NOT FOUND","Length: 144"
- "1:15:34.0791519 PM","rundll32.exe","9780","RegOpenKey","HKLM\Software\Microsoft\OLE\Tracing","NAME NOT FOUND","Desired Access: Read"
- "1:15:34.0798906 PM","rundll32.exe","9780","CreateFileMapping","C:\Windows\System32\uxtheme.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.0801611 PM","rundll32.exe","9780","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:34.0802226 PM","rundll32.exe","9780","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:34.0802622 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
- "1:15:34.0802918 PM","rundll32.exe","9780","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:34.0803117 PM","rundll32.exe","9780","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:34.0803425 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
- "1:15:34.0803763 PM","rundll32.exe","9780","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Appcompat\","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:34.0830046 PM","rundll32.exe","9780","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\DirectManipulation","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:34.0831588 PM","rundll32.exe","9780","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","REPARSE","Desired Access: Read"
- "1:15:34.0832041 PM","rundll32.exe","9780","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\en-US","NAME NOT FOUND","Length: 532"
- "1:15:34.0832304 PM","rundll32.exe","9780","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","REPARSE","Desired Access: Read"
- "1:15:34.0832627 PM","rundll32.exe","9780","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale\en-US","NAME NOT FOUND","Length: 532"
- "1:15:34.0841350 PM","rundll32.exe","9780","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value"
- "1:15:34.0841782 PM","rundll32.exe","9780","RegQueryValue","HKLM\System\CurrentControlSet\Control\SESSION MANAGER\SafeDllSearchMode","NAME NOT FOUND","Length: 16"
- "1:15:34.0845154 PM","rundll32.exe","9780","CreateFileMapping","C:\Windows\System32\dwmapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.0851408 PM","rundll32.exe","9780","CreateFileMapping","C:\Windows\System32\SHCore.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.0891900 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles","NAME NOT FOUND","Length: 20"
- "1:15:34.6501867 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.6503802 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.6601756 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.6605417 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\common","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.6776958 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\common\css","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.6783312 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\css","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.6787749 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\css\und-latn","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.6791408 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\images","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.6901922 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\microsoft.system.package.metadata","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.6906338 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\nytshared","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.6912408 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\wsjshared","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.6949824 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.6955822 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\microsoft.system.package.metadata","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.7284151 PM","wwahost.exe","2812","FileSystemControl","C:\Users","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.7285887 PM","wwahost.exe","2812","FileSystemControl","C:\Users\Chloe","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.7289080 PM","wwahost.exe","2812","FileSystemControl","C:\Users\Chloe\AppData\Local","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.7290883 PM","wwahost.exe","2812","FileSystemControl","C:\Users\Chloe\AppData\Local\Packages","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.7292651 PM","wwahost.exe","2812","FileSystemControl","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.7294478 PM","wwahost.exe","2812","FileSystemControl","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\AC","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.7297988 PM","wwahost.exe","2812","FileSystemControl","C:\Windows","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.7299709 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\apppatch","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.7301375 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\apppatch\apppatch64","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.7303087 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\assembly","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.7304783 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\assembly\NativeImages_v4.0.30319_64","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.7437970 PM","wwahost.exe","2812","CreateFile","C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\36BDCA19B5E894E99F1723ACD37EF442","NAME NOT FOUND","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Complete If Oplocked, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:34.7453929 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Diagd2d95910#\664c4b72d162ef6bf0961ab8f6466e57","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.7663712 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.caf7096d#\6893cdef3f45a5a82453d1a2a613eb7e","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.7893092 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runt0d283adf#\c0773b528798357263b45b13e47df3a0","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.8018409 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runt1e58aa76#\ed7dab94f316db1c7076b5dcece5e0ba","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.8078186 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtbff93e24#\3e4a52cfe965934afd16ce06288bbcc7","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.8153817 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Thre7bb2aad0#\212e032faa8c80bc75ee5ed64f2bf8c8","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.8252827 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.App640a3541#\52610b15de6cf7f4ddd8b93f543abe24","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.8332708 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Gloaae92e31#\678926c3ae1779d1515a93d5afbc45f4","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.8416507 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\Microsoft.NET","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.8419985 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\Microsoft.NET\assembly\GAC_64","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.8425989 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.8430372 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\Microsoft.NET\assembly\GAC_MSIL","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.8453902 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\Microsoft.NET\Framework64","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.8455671 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\Microsoft.NET\Framework64\v4.0.30319","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.8460748 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Config","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.8465831 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\ServiceProfiles\LocalService","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.8469106 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\ServiceProfiles\LocalService\AppData\Local","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.8470661 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\System32","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.8472388 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\System32\en-US","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.8474072 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\System32\WinMetadata","END OF FILE","Control: FSCTL_FILE_PREFETCH"
- "1:15:34.8693687 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\ntdll.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8695441 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WWAHost.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8697110 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\kernel32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8698716 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\KernelBase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8700364 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\locale.nls","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8702305 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-1327121770-2262649544-634666869-1001.pckgdep","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8703926 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\apphelp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8705592 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\apppatch\apppatch64\sysmain.sdb","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8707415 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\combase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8709042 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinTypes.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8710672 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\SHCore.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8712281 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\BCP47Langs.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8713902 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\iertutil.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8715765 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\mshtml.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8717591 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\urlmon.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8719212 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\twinapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8720815 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\profapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8722406 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dwmapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8724042 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\ole32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8725811 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\oleaut32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8727543 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rometadata.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8729267 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\uxtheme.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8730970 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dui70.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8733569 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\user32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8735383 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\gdi32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8736898 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\msvcrt.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8738428 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rpcrt4.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8739956 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\sechost.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8741516 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\shlwapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8743056 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\wininet.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8744586 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\imm32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8746295 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\msctf.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8748106 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\cryptbase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8749694 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\bcryptprimitives.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8751538 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\advapi32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8753304 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rpcss.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8755124 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\MrmCoreR.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8756887 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\d2d1.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8758460 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Globalization\Sorting\SortDefault.nls","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8760461 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\resources.pri","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8762505 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\resources.pri","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8764298 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\DWrite.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8766091 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\AppEx.Common.NewsBdiTransformer.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8767857 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8769454 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\d3d11.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8771023 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\aticfx64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8772527 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\atiuxp64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8775741 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\version.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8778392 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\atidxx64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8780426 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Microsoft.Media.AdaptiveStreaming.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8782542 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\MicrosoftAdvertising.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8784435 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\News.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8786349 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\NYT.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8788350 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8790176 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\cryptsp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8791827 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rsaenh.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8793672 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\actxprxy.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8795320 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.UI.Immersive.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8796917 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.UI.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8798746 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\ninput.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8800572 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\comctl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8802975 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\secur32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8804759 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\sspicli.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8806380 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\msimtf.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8808164 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\powrprof.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8809740 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dcomp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8811349 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WwaApi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8813127 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\tzres.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8814726 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\tzres.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8816529 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\shell32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8818361 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\Autogen\JSByteCodeCache_64","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8820287 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\default.html","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8822367 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\microsoft.system.package.metadata\Autogen\JSByteCodeCache_64","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8824304 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\css\ui-light.css","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8826251 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\common\css\und-latn\immersive.css","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8828192 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\common\css\und-latn\common.css","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8830607 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\css\und-latn\default.css","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8833140 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\css\und-latn\partners.css","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8835005 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\css\und-latn\apNewsTheme.css","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8837013 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\nytshared\und-latn\nytTheme.css","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8838942 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\wsjshared\und-latn\wsjTheme.css","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8841260 PM","wwahost.exe","2812","CreateFileMapping","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\AC\INetCache\MSIMGSIZ.DAT","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8843225 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WindowsCodecs.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8845054 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\images\splash.scale-100.png","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8846742 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\jscript9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8848668 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Foundation.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8850651 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\clrhost.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8852489 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\mscoree.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8854418 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8856299 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8858119 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\msvcr110_clr0400.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8859942 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.ApplicationModel.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8861777 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8862544 PM","wwahost.exe","2812","CreateFile","C:\WINDOWS\ASSEMBLY\NATIVEIMAGES_V4.0.30319_64\MSCORLIB\36BDCA19B5E894E99F1723ACD37EF442\MSCORLIB.NI.DLL.AUX","PATH NOT FOUND","Desired Access: Read Data/List Directory, Execute/Traverse, Read Attributes, Disposition: Open, Options: Non-Directory File, Complete If Oplocked, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:34.8864328 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8866393 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\5a23c5e185cb978f73c67718f6e061a4\mscorlib.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8868219 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\5a23c5e185cb978f73c67718f6e061a4\mscorlib.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8870226 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime\92dbe33346751ef372e3590eb71b1cac\System.Runtime.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8872149 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime\92dbe33346751ef372e3590eb71b1cac\System.Runtime.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8874078 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Networking.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8876040 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\WWAHost_AppExNews.profile","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8878470 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtbff93e24#\3e4a52cfe965934afd16ce06288bbcc7\System.Runtime.InteropServices.WindowsRuntime.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8880474 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtbff93e24#\3e4a52cfe965934afd16ce06288bbcc7\System.Runtime.InteropServices.WindowsRuntime.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8882355 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8884266 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\bcrypt.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8886041 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Collections\29ced27766a0483b74ea5e43df52a217\System.Collections.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8888377 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Collections\29ced27766a0483b74ea5e43df52a217\System.Collections.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8890898 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.App640a3541#\52610b15de6cf7f4ddd8b93f543abe24\Windows.ApplicationModel.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8894710 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.App640a3541#\52610b15de6cf7f4ddd8b93f543abe24\Windows.ApplicationModel.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8898556 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Foundation\87788b39516ef9bf7e5c60a2b5fb3aeb\Windows.Foundation.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8900491 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Foundation\87788b39516ef9bf7e5c60a2b5fb3aeb\Windows.Foundation.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8902347 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Storage.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8904183 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.Storage.ApplicationData.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8905776 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.UI.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8907551 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Media.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8909450 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Globalization.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8911249 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\propsys.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8912897 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\shell32.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8914681 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.ApplicationModel.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8916468 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Graphics.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8918270 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.Graphics.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8920676 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Gloaae92e31#\678926c3ae1779d1515a93d5afbc45f4\Windows.Globalization.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8922659 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Gloaae92e31#\678926c3ae1779d1515a93d5afbc45f4\Windows.Globalization.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8924615 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Linq\edff7029ad67ee17c87b4f3f69df5c93\System.Linq.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8926553 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Linq\edff7029ad67ee17c87b4f3f69df5c93\System.Linq.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8928534 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\3145945493fbcef888aa44b0081134cc\System.Core.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8930456 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System\67f7ddcb264bac2f465b439bb19616b1\System.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8932283 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System\67f7ddcb264bac2f465b439bb19616b1\System.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8934109 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\3145945493fbcef888aa44b0081134cc\System.Core.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8936053 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.System\4022b99b813a11eb3afa84dd8fd0eee6\Windows.System.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8938371 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Diagd2d95910#\664c4b72d162ef6bf0961ab8f6466e57\System.Diagnostics.Tracing.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8940369 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Diagd2d95910#\664c4b72d162ef6bf0961ab8f6466e57\System.Diagnostics.Tracing.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8942335 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.System\4022b99b813a11eb3afa84dd8fd0eee6\Windows.System.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8944303 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.Globalization.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8945987 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Threading\b715c79b7d168a31bc4086b6a3e1201f\System.Threading.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8947801 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Threading\b715c79b7d168a31bc4086b6a3e1201f\System.Threading.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8950029 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Thre7bb2aad0#\212e032faa8c80bc75ee5ed64f2bf8c8\System.Threading.Tasks.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8951894 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Thre7bb2aad0#\212e032faa8c80bc75ee5ed64f2bf8c8\System.Threading.Tasks.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8953784 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.Requests\e19ae87ac64e07ecb0e1d216e7c042fa\System.Net.Requests.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8955843 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.Requests\e19ae87ac64e07ecb0e1d216e7c042fa\System.Net.Requests.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8958807 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.caf7096d#\6893cdef3f45a5a82453d1a2a613eb7e\System.Net.Primitives.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8960917 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.caf7096d#\6893cdef3f45a5a82453d1a2a613eb7e\System.Net.Primitives.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8962846 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\8517b132cbe0b329b40bc6a9ef106828\System.Configuration.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8964636 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\8517b132cbe0b329b40bc6a9ef106828\System.Configuration.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8966921 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml\4334f45efbe62a6415f2cb7393c59f74\System.Xml.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8968850 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml\4334f45efbe62a6415f2cb7393c59f74\System.Xml.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8971277 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8973067 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rasapi32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8974679 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rasman.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8976273 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\ws2_32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8978066 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\nsi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8979647 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\mswsock.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8981238 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\winhttp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8982808 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\IPHLPAPI.DLL","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8984359 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\winnsi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8985890 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dhcpcsvc6.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8987668 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dhcpcsvc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8989736 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Collections.Concurrent\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Collections.Concurrent.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8991643 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.Http\69640072694356ffed3bbe2d2352f935\System.Net.Http.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8993524 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.Http\69640072694356ffed3bbe2d2352f935\System.Net.Http.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8995890 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runt0d283adf#\c0773b528798357263b45b13e47df3a0\System.Runtime.WindowsRuntime.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.8997843 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runt0d283adf#\c0773b528798357263b45b13e47df3a0\System.Runtime.WindowsRuntime.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9000098 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runt1e58aa76#\ed7dab94f316db1c7076b5dcece5e0ba\System.Runtime.Extensions.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9218307 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\Windows.Storage.ApplicationData.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9220504 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runt1e58aa76#\ed7dab94f316db1c7076b5dcece5e0ba\System.Runtime.Extensions.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9222511 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.UI\3d103d35427b58930da5043a06ff14e0\Windows.UI.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9224437 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9226710 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.UI\3d103d35427b58930da5043a06ff14e0\Windows.UI.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9228739 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\diasymreader.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9621120 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\ServiceProfiles\LocalService\AppData\Local\~FontCache-System.dat","FILE LOCKED WITH WRITERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9623960 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IO\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9625953 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\winbrand.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9627863 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Text.Encoding\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Text.Encoding.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9629735 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\oleacc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9631619 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Branding\Basebrd\basebrd.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9633644 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\oleaccrc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9635416 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Branding\Basebrd\en-US\basebrd.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9637930 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Globalization\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Globalization.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9640019 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\sxs.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9641598 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\wer.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9643786 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\Windows.Graphics.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9645676 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Security.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9647490 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Devices.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:34.9649217 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\atipblag.dat","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3312453 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\ntdll.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3313570 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WWAHost.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3314521 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\kernel32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3315445 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\KernelBase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3316375 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\apphelp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3317289 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\combase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3318210 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinTypes.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3319125 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\SHCore.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3320027 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\BCP47Langs.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3320933 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\iertutil.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3321859 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\mshtml.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3322859 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\urlmon.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3323773 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\twinapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3324685 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\profapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3325584 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dwmapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3326496 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\ole32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3327411 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\oleaut32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3328307 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rometadata.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3329768 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\uxtheme.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3330686 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dui70.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3331597 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\user32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3332509 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\gdi32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3333421 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\msvcrt.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3334335 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rpcrt4.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3335238 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\sechost.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3336149 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\shlwapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3337055 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\wininet.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3337958 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\imm32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3338860 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\msctf.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3339760 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\cryptbase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3340662 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\bcryptprimitives.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3341565 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\advapi32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3342467 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\MrmCoreR.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3343373 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\d2d1.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3344297 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\DWrite.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3345199 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\AppEx.Common.NewsBdiTransformer.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3637867 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3638323 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\d3d11.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3638721 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\aticfx64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3639105 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\atiuxp64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3639485 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\version.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3639877 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\atidxx64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3640273 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Microsoft.Media.AdaptiveStreaming.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3645504 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\MicrosoftAdvertising.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3884480 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\News.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.3887810 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\NYT.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4114536 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4299480 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\cryptsp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4299932 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rsaenh.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4300334 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\actxprxy.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4300732 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.UI.Immersive.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4301134 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.UI.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4302015 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\ninput.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4302571 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\comctl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4302954 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\secur32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4303334 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\sspicli.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4303926 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\msimtf.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4304312 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\powrprof.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4304696 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dcomp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4305070 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WwaApi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4305592 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\tzres.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4305997 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\shell32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4306392 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WindowsCodecs.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4306785 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\jscript9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4307201 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Foundation.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4307581 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\clrhost.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4308514 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\mscoree.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4308907 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4309320 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4309930 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\msvcr110_clr0400.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4310522 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.ApplicationModel.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4310920 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4311337 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\5a23c5e185cb978f73c67718f6e061a4\mscorlib.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4311747 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime\92dbe33346751ef372e3590eb71b1cac\System.Runtime.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4314892 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Networking.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4318174 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtbff93e24#\3e4a52cfe965934afd16ce06288bbcc7\System.Runtime.InteropServices.WindowsRuntime.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4321168 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4321630 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\bcrypt.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4322022 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Collections\29ced27766a0483b74ea5e43df52a217\System.Collections.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4324685 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.App640a3541#\52610b15de6cf7f4ddd8b93f543abe24\Windows.ApplicationModel.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4578663 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Foundation\87788b39516ef9bf7e5c60a2b5fb3aeb\Windows.Foundation.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4582545 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Storage.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4583043 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.Storage.ApplicationData.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4583448 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.UI.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4583846 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Media.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4584245 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Globalization.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4586859 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\propsys.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4587321 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.ApplicationModel.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4587722 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Graphics.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4588124 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.Graphics.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4588788 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Gloaae92e31#\678926c3ae1779d1515a93d5afbc45f4\Windows.Globalization.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4592558 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Linq\edff7029ad67ee17c87b4f3f69df5c93\System.Linq.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4595118 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System\67f7ddcb264bac2f465b439bb19616b1\System.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4595576 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\3145945493fbcef888aa44b0081134cc\System.Core.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4810485 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Diagd2d95910#\664c4b72d162ef6bf0961ab8f6466e57\System.Diagnostics.Tracing.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4813785 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.System\4022b99b813a11eb3afa84dd8fd0eee6\Windows.System.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4818113 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.Globalization.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4818566 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Threading\b715c79b7d168a31bc4086b6a3e1201f\System.Threading.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4821539 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Thre7bb2aad0#\212e032faa8c80bc75ee5ed64f2bf8c8\System.Threading.Tasks.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4824117 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.Requests\e19ae87ac64e07ecb0e1d216e7c042fa\System.Net.Requests.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4826858 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.caf7096d#\6893cdef3f45a5a82453d1a2a613eb7e\System.Net.Primitives.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4829566 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\8517b132cbe0b329b40bc6a9ef106828\System.Configuration.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4908236 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml\4334f45efbe62a6415f2cb7393c59f74\System.Xml.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4908707 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rasapi32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4909103 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rasman.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4909492 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\ws2_32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4909876 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\nsi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4910265 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\mswsock.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4910654 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\winhttp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4911053 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\IPHLPAPI.DLL","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4911807 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\winnsi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4912200 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dhcpcsvc6.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4912773 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dhcpcsvc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4913353 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Collections.Concurrent\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Collections.Concurrent.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4919203 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.Http\69640072694356ffed3bbe2d2352f935\System.Net.Http.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.4924492 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runt0d283adf#\c0773b528798357263b45b13e47df3a0\System.Runtime.WindowsRuntime.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.5031561 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runt1e58aa76#\ed7dab94f316db1c7076b5dcece5e0ba\System.Runtime.Extensions.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.5034338 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.UI\3d103d35427b58930da5043a06ff14e0\Windows.UI.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.5230227 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\diasymreader.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.5233031 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IO\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.5235452 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\winbrand.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.5235908 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Text.Encoding\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Text.Encoding.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.5236810 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\oleacc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.5237221 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Globalization\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Globalization.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.5239748 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\sxs.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.5240206 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\wer.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.5240602 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Security.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:35.5243699 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Devices.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:36.6722883 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","REPARSE","Desired Access: Query Value, Set Value"
- "1:15:36.6723508 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","NAME NOT FOUND","Desired Access: Query Value, Set Value"
- "1:15:36.6723882 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Srp\GP\DLL","REPARSE","Desired Access: Read"
- "1:15:36.6724172 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Srp\GP\DLL","NAME NOT FOUND","Desired Access: Read"
- "1:15:36.6724806 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled","NAME NOT FOUND","Length: 80"
- "1:15:36.6725276 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:36.6732844 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\apphelp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:36.6738649 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\DbgLog","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:36.6739210 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\DbgLog","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:36.6740454 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\ShowDebugInfo","NAME NOT FOUND","Length: 256"
- "1:15:36.6743711 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\WWAHost.exe","BUFFER OVERFLOW","Information: Owner"
- "1:15:36.6747219 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\ntdll.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:36.6750651 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\kernel32.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:36.6753838 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\KernelBase.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:36.6758686 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\apppatch\apppatch64\sysmain.sdb","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:36.6762550 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","REPARSE","Desired Access: Read"
- "1:15:36.6763564 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\PackageRootFolder","BUFFER OVERFLOW","Length: 144"
- "1:15:36.6767205 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-1327121770-2262649544-634666869-1001.pckgdep","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:36.6769849 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","REPARSE","Desired Access: Read"
- "1:15:36.6770848 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\PackageRootFolder","BUFFER OVERFLOW","Length: 144"
- "1:15:36.6774317 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-1327121770-2262649544-634666869-1001.pckgdep","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:36.6777293 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","REPARSE","Desired Access: Read"
- "1:15:36.6795241 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\combase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:36.6806154 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinTypes.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:36.6816909 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\SHCore.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:36.6823719 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Bcp47Langs.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:36.7149066 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Bcp47Langs.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:36.7150467 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Bcp47Langs.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:36.7154659 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\BCP47Langs.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:36.7161047 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\MSHTML.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:36.7162342 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\MSHTML.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:36.7163489 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\MSHTML.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.0990285 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\mshtml.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.0994789 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\TWINAPI.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.0995727 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\TWINAPI.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.0996567 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\TWINAPI.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.0999449 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\twinapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.1002737 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\profapi.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1003730 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\profapi.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1004584 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\profapi.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1007865 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\profapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.1010842 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\dwmapi.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1011717 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\dwmapi.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1012535 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\dwmapi.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1015529 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dwmapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.1020631 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\RoMetadata.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1021497 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\RoMetadata.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1022321 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\RoMetadata.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1595887 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rometadata.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.1599395 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\UxTheme.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1600358 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\UxTheme.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1601276 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\UxTheme.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1604258 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\uxtheme.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.1606495 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DUI70.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1607331 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\DUI70.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1608249 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\DUI70.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1611092 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dui70.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.1618071 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\sechost.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.1630224 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\msvcrt.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1631863 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\rpcrt4.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1633433 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\combase.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1635017 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\WinTypes.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1636524 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\SHCore.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1637976 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\sechost.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1639503 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\BCP47Langs.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1641100 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\iertutil.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1642558 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\user32.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1644094 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\gdi32.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1645583 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\mshtml.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1647086 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\ole32.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1648577 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\shlwapi.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1650053 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\wininet.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1651556 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\urlmon.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1652978 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\twinapi.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1654457 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\profapi.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1655942 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\dwmapi.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1657361 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\oleaut32.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1658831 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\rometadata.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1660280 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\uxtheme.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1661714 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\dui70.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1663199 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions","REPARSE","Desired Access: Read"
- "1:15:37.1664838 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\PageAllocatorUseSystemHeap","NAME NOT FOUND","Length: 144"
- "1:15:37.1665285 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\PageAllocatorSystemHeapIsPrivate","NAME NOT FOUND","Length: 144"
- "1:15:37.1665686 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\AggressiveMTATesting","NAME NOT FOUND","Length: 144"
- "1:15:37.1666281 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\OLE\Tracing","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1672303 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\imm32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.1676608 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\imm32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.1680728 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\msctf.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1682298 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\imm32.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1684667 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Error Message Instrument\","REPARSE","Desired Access: Read"
- "1:15:37.1684885 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Error Message Instrument","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1685292 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles","NAME NOT FOUND","Length: 20"
- "1:15:37.1686050 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Compatibility32\wwahost","NAME NOT FOUND","Length: 172"
- "1:15:37.1686324 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\IME Compatibility","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1687438 PM","wwahost.exe","2812","RegOpenKey","HKCU\Control Panel\Desktop\MuiCached\MachineLanguageConfiguration","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1687716 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1688039 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1688341 PM","wwahost.exe","2812","RegEnumValue","HKCU\Control Panel\Desktop\LanguageConfiguration","NO MORE ENTRIES","Index: 0, Length: 512"
- "1:15:37.1688670 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1688981 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1689268 PM","wwahost.exe","2812","RegQueryValue","HKCU\Control Panel\Desktop\PreferredUILanguages","NAME NOT FOUND","Length: 12"
- "1:15:37.1689573 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1690046 PM","wwahost.exe","2812","RegQueryValue","HKCU\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages","BUFFER OVERFLOW","Length: 12"
- "1:15:37.1692030 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\WWAHost.exe.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.1697128 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\CRYPTBASE.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1698311 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\CRYPTBASE.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1699211 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\CRYPTBASE.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1702118 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\cryptbase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.1705656 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\bcryptPrimitives.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1706588 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\bcryptPrimitives.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1707461 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\bcryptPrimitives.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1710301 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\bcryptprimitives.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.1714168 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\bcryptprimitives.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1716184 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\cryptbase.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1717102 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","REPARSE","Desired Access: Query Value"
- "1:15:37.1717676 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa","REPARSE","Desired Access: Query Value"
- "1:15:37.1717987 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","NAME NOT FOUND","Length: 20"
- "1:15:37.1718388 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration","REPARSE","Desired Access: Query Value"
- "1:15:37.1718545 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.1719825 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\OLE\Tracing","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1724217 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\advapi32.dll","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.1726511 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only","NAME NOT FOUND","Length: 144"
- "1:15:37.1726840 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.1727344 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.1728174 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_STRUCTURE_NODE_CHILD_COUNT","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.1728431 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_STRUCTURE_NODE_CHILD_COUNT","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.1729327 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay","NAME NOT FOUND","Length: 16"
- "1:15:37.1729662 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","REPARSE","Desired Access: Read"
- "1:15:37.1729976 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\en-US","NAME NOT FOUND","Length: 532"
- "1:15:37.1730170 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","REPARSE","Desired Access: Read"
- "1:15:37.1730438 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale\en-US","NAME NOT FOUND","Length: 532"
- "1:15:37.1797412 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXE","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1798951 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Application Compatibility\wwahost.exe","NAME NOT FOUND","Length: 144"
- "1:15:37.1799516 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\DOMStorage","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1799999 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\DOMStorage","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1800282 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\DOMStorage","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1800593 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Internet Explorer\DOMStorage","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1800959 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\DOMStorage","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1801233 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Internet Explorer\DOMStorage","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1801553 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\microsoft\Internet Explorer\Persistence","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.1801798 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\microsoft\Internet Explorer\Persistence","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.1803334 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\OLEAUT","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.1804300 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1804795 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1805133 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
- "1:15:37.1805396 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1805580 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1805912 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
- "1:15:37.1806220 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Appcompat\","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.1807769 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\2a3c6602-411e-4dc6-b138-ea19d64f5bba","NAME NOT FOUND","Length: 524"
- "1:15:37.1808040 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\d8b068fb-6f2d-4eab-8a45-93744db9ee59","NAME NOT FOUND","Length: 524"
- "1:15:37.1808227 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\bf602ba6-72f7-42fc-ad01-a8ed5b87241e","NAME NOT FOUND","Length: 524"
- "1:15:37.1812505 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rpcss.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.1814216 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Ole\AppCompat\InputMessages","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1814835 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wwahost.exe","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.1815656 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1816085 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1816326 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
- "1:15:37.1816501 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1816631 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1816864 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
- "1:15:37.1817259 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\52B21FA5","NAME NOT FOUND","Length: 24"
- "1:15:37.1817422 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1817564 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1817682 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1818026 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\ThrottleStore\ThrottleExpiryTime","NAME NOT FOUND","Length: 24"
- "1:15:37.1818125 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1818361 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
- "1:15:37.1818509 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1818633 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1818859 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
- "1:15:37.1819125 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows\winsqm8\13238528","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1819315 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8\13238528","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1819457 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1819577 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1819692 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1819921 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\ThrottleStore\ThrottleExpiryTime","NAME NOT FOUND","Length: 24"
- "1:15:37.1820009 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1820241 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
- "1:15:37.1820444 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1820573 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1820821 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
- "1:15:37.1821041 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows\winsqm8\13238784","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1821168 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8\13238784","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1821401 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1821527 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1821639 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1821868 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\ThrottleStore\ThrottleExpiryTime","NAME NOT FOUND","Length: 24"
- "1:15:37.1821986 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1822240 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
- "1:15:37.1822391 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1822511 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1822738 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
- "1:15:37.1823022 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows\winsqm8\101457980","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1823160 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8\101457980","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1824796 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","REPARSE","Desired Access: Read"
- "1:15:37.1825581 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\PackageRootFolder","BUFFER OVERFLOW","Length: 144"
- "1:15:37.1825753 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\PackageRootFolder","BUFFER OVERFLOW","Length: 144"
- "1:15:37.1826596 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1827091 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1827281 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Applications\Microsoft.BingNews_8wekyb3d8bbwe!AppexNews\DisplayName","BUFFER OVERFLOW","Length: 144"
- "1:15:37.1827441 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Applications\Microsoft.BingNews_8wekyb3d8bbwe!AppexNews\DisplayName","BUFFER OVERFLOW","Length: 144"
- "1:15:37.1827803 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1828521 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Applications\Microsoft.BingNews_8wekyb3d8bbwe!AppexNews\ApplicationContentUris","NAME NOT FOUND","Length: 144"
- "1:15:37.1828745 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.1829355 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.1829388 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","REPARSE","Desired Access: Read"
- "1:15:37.1829415 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1829907 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DevelopmentMode","NAME NOT FOUND","Length: 144"
- "1:15:37.1830324 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1830677 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.1831154 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\UseSWRender","NAME NOT FOUND","Length: 144"
- "1:15:37.1831552 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.1831791 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\UseSWRender","NAME NOT FOUND","Length: 144"
- "1:15:37.1832204 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1833384 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.1833650 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\InprocServer32\InprocServer32","NAME NOT FOUND","Length: 144"
- "1:15:37.1834009 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\UseSWRender","NAME NOT FOUND","Length: 144"
- "1:15:37.1834230 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\UseSWRender","NAME NOT FOUND","Length: 144"
- "1:15:37.1834266 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.1834818 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.1835763 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\d2d1.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1835872 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.1836874 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.1836883 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\d2d1.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1837140 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.1837523 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.1837767 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.1837930 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\d2d1.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.1838262 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\MaxSxSHashCount","NAME NOT FOUND","Length: 144"
- "1:15:37.1839388 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1840472 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1840759 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.1842283 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\d2d1.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.2398396 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\MrmCoreR.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.2398538 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\MrmCoreR.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.2402960 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize","NAME NOT FOUND","Length: 144"
- "1:15:37.2403437 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize","NAME NOT FOUND","Length: 144"
- "1:15:37.2403881 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize","NAME NOT FOUND","Length: 144"
- "1:15:37.2404385 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize","NAME NOT FOUND","Length: 144"
- "1:15:37.2404659 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode","NAME NOT FOUND","Length: 144"
- "1:15:37.2404759 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode","NAME NOT FOUND","Length: 144"
- "1:15:37.2404847 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode","NAME NOT FOUND","Length: 144"
- "1:15:37.2406957 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Globalization\Sorting\SortDefault.nls","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.2407343 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Rpc\MaxRpcSize","NAME NOT FOUND","Length: 144"
- "1:15:37.2407847 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName","REPARSE","Desired Access: Read"
- "1:15:37.2408354 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids","REPARSE","Desired Access: Read"
- "1:15:37.2408544 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DWrite.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.2408828 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids\en-US","NAME NOT FOUND","Length: 90"
- "1:15:37.2408997 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids\en","NAME NOT FOUND","Length: 90"
- "1:15:37.2410153 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\DWrite.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.2410760 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","REPARSE","Desired Access: Read"
- "1:15:37.2411228 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows NT\Rpc","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.2411530 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\PackageRootFolder","BUFFER OVERFLOW","Length: 144"
- "1:15:37.2411596 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.2411832 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\DWrite.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.2412272 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.2412659 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
- "1:15:37.2412949 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.2413151 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.2413477 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
- "1:15:37.2414473 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Rpc\IdleTimerWindow","NAME NOT FOUND","Length: 144"
- "1:15:37.2416269 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\DWrite.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.2416272 PM","wwahost.exe","2812","RegCreateKey","HKCU\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe%5Cresources.pri","REPARSE","Desired Access: Read/Write"
- "1:15:37.2416544 PM","wwahost.exe","2812","RegCreateKey","HKCU\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe%5Cresources.pri","ACCESS DENIED","Desired Access: Read/Write"
- "1:15:37.2420374 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\FontCache\Parameters","REPARSE","Desired Access: Read"
- "1:15:37.2422363 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\dxgi.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.2423378 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\dxgi.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.2424259 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\dxgi.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.2427193 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.2429638 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.2512242 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\WWAHost.exe","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.2514265 PM","wwahost.exe","2812","RegCreateKey","HKCU\Software\Classes\Local Settings\MrtCache","ACCESS DENIED","Desired Access: Maximum Allowed"
- "1:15:37.2515351 PM","wwahost.exe","2812","CreateFile","C:\ProgramData\PRICache","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
- "1:15:37.2851309 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.2851635 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
- "1:15:37.2851894 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.2851949 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\Server","NAME NOT FOUND","Length: 138"
- "1:15:37.2852036 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.2852076 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.2852371 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
- "1:15:37.2855550 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Query Value"
- "1:15:37.2856582 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Direct3D","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.2856902 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Direct3D","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.2856972 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\AC\PRICache","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
- "1:15:37.2858324 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\DXGIDebug.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.2858559 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","REPARSE","Desired Access: Read"
- "1:15:37.2859012 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\PackageRootFolder","BUFFER OVERFLOW","Length: 144"
- "1:15:37.2859293 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\DXGIDebug.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.2860214 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\DXGIDebug.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.2861086 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\DXGIDebug.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.2862013 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\DXGIDebug.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.2862547 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\resources.pri","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.2862849 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\DXGIDebug.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.2864814 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\DXGI","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.2865104 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\DXGI","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.2867307 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\apppatch\apppatch64\sysmain.sdb","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.2870875 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\d3d11.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.2871778 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\d3d11.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.2872629 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\d3d11.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.2875346 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\d3d11.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.2878358 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.2878920 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.2879312 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
- "1:15:37.2879542 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.2879798 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.2880085 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
- "1:15:37.2881809 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\aticfx64.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.2882787 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\aticfx64.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.2883641 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\aticfx64.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.2885829 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Query Value"
- "1:15:37.2886349 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\aticfx64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.2886699 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\Microsoft.BingNews_8wekyb3d8bbwe","REPARSE","Desired Access: Read/Write"
- "1:15:37.2888419 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\ManifestLanguagesList","BUFFER OVERFLOW","Length: 144"
- "1:15:37.3000017 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\Server","NAME NOT FOUND","Length: 138"
- "1:15:37.3000104 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.3059848 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\KernelBase.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.3063118 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\atiuxp64.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.3063483 PM","wwahost.exe","2812","CreateFile","C:\ProgramData\PRICache","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
- "1:15:37.3064120 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\atiuxp64.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.3065086 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\atiuxp64.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.3065958 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Query Value"
- "1:15:37.3067093 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\AC\PRICache","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
- "1:15:37.3068225 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\atiuxp64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.3070767 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\resources.pri","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.3071690 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\VERSION.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.3072699 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\VERSION.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.3073559 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\VERSION.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.3076792 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\version.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.3085325 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000","REPARSE","Desired Access: Query Value"
- "1:15:37.3086062 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000\Blacklist","NAME NOT FOUND","Length: 144"
- "1:15:37.3087677 PM","wwahost.exe","2812","QueryAllInformationFile","C:\Windows\System32\atipblag.dat","BUFFER OVERFLOW","CreationTime: 2/15/2013 10:25:14 PM, LastAccessTime: 2/15/2013 10:25:14 PM, LastWriteTime: 9/13/2011 9:06:16 AM, ChangeTime: 3/9/2013 1:47:51 AM, FileAttributes: A, AllocationSize: 4,096, EndOfFile: 3,917, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x100000007478c, EaSize: 0, Access: Read Data/List Directory, Read Attributes, Synchronize, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Long"
- "1:15:37.3089711 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\atidxx64.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.3090729 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\atidxx64.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.3091622 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\atidxx64.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.3094420 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\resources.pri","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.3094577 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\atidxx64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.3317573 PM","wwahost.exe","2812","RegEnumValue","HKLM\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000\UMD","NO MORE ENTRIES","Index: 76, Length: 770"
- "1:15:37.3334963 PM","wwahost.exe","2812","RegEnumValue","HKLM\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000\UMD\DXVA","NO MORE ENTRIES","Index: 84, Length: 770"
- "1:15:37.3340780 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\GraphicsDrivers","REPARSE","Desired Access: Read"
- "1:15:37.3343771 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Direct3D","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.3344158 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Direct3D","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.3345130 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\GraphicsDrivers\Scheduler","REPARSE","Desired Access: Read, Maximum Allowed"
- "1:15:37.3345344 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\GraphicsDrivers\Scheduler","NAME NOT FOUND","Desired Access: Read, Maximum Allowed"
- "1:15:37.3425793 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\resources.pri","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.3471530 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\ManifestLanguagesList","BUFFER OVERFLOW","Length: 144"
- "1:15:37.3472418 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\OverrideLanguagesList","NAME NOT FOUND","Length: 144"
- "1:15:37.3478684 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.3479276 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.3479575 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
- "1:15:37.3479750 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.3479892 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.3480127 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
- "1:15:37.3480951 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only","NAME NOT FOUND","Length: 144"
- "1:15:37.3481247 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.3481513 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.3481830 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.3482162 PM","wwahost.exe","2812","RegOpenKey","HKLM\ZoneMap\Ranges\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.3482391 PM","wwahost.exe","2812","RegOpenKey","HKCU\ZoneMap\Ranges\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.3482606 PM","wwahost.exe","2812","RegOpenKey","HKLM\ZoneMap\Ranges\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.3485078 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.3485826 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.3486587 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.3486895 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.3487185 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.3489859 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.3923797 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\AppEx.Common.NewsBdiTransformer.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.4355447 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\GPU\AdapterInfo","BUFFER OVERFLOW","Length: 144"
- "1:15:37.4357687 PM","wwahost.exe","2812","RegCreateKey","HKCU\Software\Microsoft\Internet Explorer\GPU","ACCESS DENIED","Desired Access: Write"
- "1:15:37.4358052 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\WWAHost.exe","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.4359628 PM","wwahost.exe","2812","RegCreateKey","HKCU\Software\Microsoft\Internet Explorer\GPU","ACCESS DENIED","Desired Access: Write"
- "1:15:37.4359830 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\WWAHost.exe","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.4911318 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Microsoft.Media.AdaptiveStreaming.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.5249709 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\MicrosoftAdvertising.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.5552788 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\News.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.5818367 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\NYT.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.6309891 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.6315424 PM","wwahost.exe","2812","QueryDirectory","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","NO MORE FILES",""
- "1:15:37.6317325 PM","wwahost.exe","2812","QueryDirectory","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\*.winmd","NO SUCH FILE","Filter: *.winmd"
- "1:15:37.6318820 PM","wwahost.exe","2812","QueryDirectory","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\*.winmd","NO SUCH FILE","Filter: *.winmd"
- "1:15:37.6319761 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wwahost.exe","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6321011 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wwahost.exe","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.6321271 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wwahost.exe","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.6334737 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\AppID\wwahost.exe","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6335005 PM","wwahost.exe","2812","RegOpenKey","HKCR\AppID\wwahost.exe","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6335660 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\AppID\wwahost.exe","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6335826 PM","wwahost.exe","2812","RegOpenKey","HKCR\AppID\wwahost.exe","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6336258 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel","NAME NOT FOUND","Length: 144"
- "1:15:37.6336738 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\DefaultAccessPermission","NAME NOT FOUND","Length: 144"
- "1:15:37.6343626 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\CRYPTSP.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.6344671 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\CRYPTSP.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.6345567 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\CRYPTSP.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.6348797 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\cryptsp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.6354928 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rsaenh.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.6357255 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","REPARSE","Desired Access: Query Value"
- "1:15:37.6357823 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa","REPARSE","Desired Access: Query Value"
- "1:15:37.6358125 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","NAME NOT FOUND","Length: 20"
- "1:15:37.6358427 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration","REPARSE","Desired Access: Query Value"
- "1:15:37.6358581 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.6359236 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCacheMaxItems","NAME NOT FOUND","Length: 144"
- "1:15:37.6359323 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCachePurgeIntervalSeconds","NAME NOT FOUND","Length: 144"
- "1:15:37.6359402 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Cryptography\PrivateKeyLifetimeSeconds","NAME NOT FOUND","Length: 144"
- "1:15:37.6360663 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Cryptography\Offload","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6362118 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6362752 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6363450 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.6369097 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6369487 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6369828 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6370103 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6370332 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package","REPARSE","Desired Access: Read"
- "1:15:37.6371020 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package","REPARSE","Desired Access: Read"
- "1:15:37.6371298 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DebugInformation\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6371585 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa\CommandLine","NAME NOT FOUND","Length: 530"
- "1:15:37.6371669 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa\ActivatableClasses","BUFFER OVERFLOW","Length: 136"
- "1:15:37.6371980 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa\Identity","NAME NOT FOUND","Length: 138"
- "1:15:37.6372050 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa\ServiceName","NAME NOT FOUND","Length: 138"
- "1:15:37.6372119 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa\Permissions","BUFFER OVERFLOW","Length: 136"
- "1:15:37.6372348 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.6372726 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6373055 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6373206 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6373348 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6373520 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package","REPARSE","Desired Access: Read"
- "1:15:37.6374169 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{35262B8B-9081-54A2-9E54-E5D67149AF20}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6374317 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{35262B8B-9081-54A2-9E54-E5D67149AF20}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6374836 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{35262B8B-9081-54A2-9E54-E5D67149AF20}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6374984 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{35262B8B-9081-54A2-9E54-E5D67149AF20}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6375539 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Wow6432Node\CLSID\{35262B8B-9081-54A2-9E54-E5D67149AF20}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6375720 PM","wwahost.exe","2812","RegOpenKey","HKCR\Wow6432Node\CLSID\{35262B8B-9081-54A2-9E54-E5D67149AF20}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6375889 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\CLSID","REPARSE","Desired Access: Read"
- "1:15:37.6376493 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6376638 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6377229 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\DllPath","NAME NOT FOUND","Length: 530"
- "1:15:37.6377395 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6377543 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6378008 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DebugInformation\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6378144 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.6378446 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.6378884 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\AppexNews.AppX840xcewdazfg7z839sn6pf6ws2g4dfec.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6379074 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppX840xcewdazfg7z839sn6pf6ws2g4dfec.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6379222 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppX840xcewdazfg7z839sn6pf6ws2g4dfec.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6379361 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppX840xcewdazfg7z839sn6pf6ws2g4dfec.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6489965 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{15E195FA-CCBA-52B5-83D6-34A16E8180C0}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6490228 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{15E195FA-CCBA-52B5-83D6-34A16E8180C0}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6490780 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{15E195FA-CCBA-52B5-83D6-34A16E8180C0}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6490961 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{15E195FA-CCBA-52B5-83D6-34A16E8180C0}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6491523 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Wow6432Node\CLSID\{15E195FA-CCBA-52B5-83D6-34A16E8180C0}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6491701 PM","wwahost.exe","2812","RegOpenKey","HKCR\Wow6432Node\CLSID\{15E195FA-CCBA-52B5-83D6-34A16E8180C0}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6575823 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\AppexNews.AppX840xcewdazfg7z839sn6pf6ws2g4dfec.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6576067 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppX840xcewdazfg7z839sn6pf6ws2g4dfec.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6576768 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppX840xcewdazfg7z839sn6pf6ws2g4dfec.wwa\DllPath","NAME NOT FOUND","Length: 530"
- "1:15:37.6576955 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6577148 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6577652 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DebugInformation\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6577800 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.6578129 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppX840xcewdazfg7z839sn6pf6ws2g4dfec.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.6578582 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\AppexNews.AppXmr5vsssa5hr66w886547dqn2casn6rsg.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6578769 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXmr5vsssa5hr66w886547dqn2casn6rsg.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6578926 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXmr5vsssa5hr66w886547dqn2casn6rsg.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6579077 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXmr5vsssa5hr66w886547dqn2casn6rsg.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6579623 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{118D5336-7258-57A7-946D-C218AC241D40}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6579792 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{118D5336-7258-57A7-946D-C218AC241D40}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6580308 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{118D5336-7258-57A7-946D-C218AC241D40}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6580484 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{118D5336-7258-57A7-946D-C218AC241D40}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6581111 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Wow6432Node\CLSID\{118D5336-7258-57A7-946D-C218AC241D40}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6581293 PM","wwahost.exe","2812","RegOpenKey","HKCR\Wow6432Node\CLSID\{118D5336-7258-57A7-946D-C218AC241D40}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6581812 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\AppexNews.AppXmr5vsssa5hr66w886547dqn2casn6rsg.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6581966 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXmr5vsssa5hr66w886547dqn2casn6rsg.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6582557 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXmr5vsssa5hr66w886547dqn2casn6rsg.wwa\DllPath","NAME NOT FOUND","Length: 530"
- "1:15:37.6582726 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6582883 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6583339 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DebugInformation\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6583478 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.6583774 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXmr5vsssa5hr66w886547dqn2casn6rsg.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.6584199 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\AppexNews.AppXctnv7jgfexcxjqxhnfr8weh1x4cw0e6g.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6584387 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXctnv7jgfexcxjqxhnfr8weh1x4cw0e6g.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6584531 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXctnv7jgfexcxjqxhnfr8weh1x4cw0e6g.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6584673 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXctnv7jgfexcxjqxhnfr8weh1x4cw0e6g.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6585244 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{D9A93F9B-739F-5240-AF23-A40768CD5D31}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6585404 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{D9A93F9B-739F-5240-AF23-A40768CD5D31}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6585896 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D9A93F9B-739F-5240-AF23-A40768CD5D31}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6586062 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{D9A93F9B-739F-5240-AF23-A40768CD5D31}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6586596 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Wow6432Node\CLSID\{D9A93F9B-739F-5240-AF23-A40768CD5D31}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6586762 PM","wwahost.exe","2812","RegOpenKey","HKCR\Wow6432Node\CLSID\{D9A93F9B-739F-5240-AF23-A40768CD5D31}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6746213 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\AppexNews.AppXctnv7jgfexcxjqxhnfr8weh1x4cw0e6g.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6746506 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXctnv7jgfexcxjqxhnfr8weh1x4cw0e6g.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6747182 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXctnv7jgfexcxjqxhnfr8weh1x4cw0e6g.wwa\DllPath","NAME NOT FOUND","Length: 530"
- "1:15:37.6747354 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6747533 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6748019 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DebugInformation\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6748160 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.6748480 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXctnv7jgfexcxjqxhnfr8weh1x4cw0e6g.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.6791963 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6792235 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6792395 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6792624 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.6792811 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\ThrottleStore\ThrottleExpiryTime","NAME NOT FOUND","Length: 24"
- "1:15:37.6792938 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6793270 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DebugInformation\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6793310 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
- "1:15:37.6793439 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.6793563 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6793714 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6793962 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
- "1:15:37.6794212 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows\winsqm8\101457980","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6794306 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.6794345 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8\101457980","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6794840 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DebugInformation\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6794979 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.6795407 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{2E5500B6-66AD-467F-ABB5-022A64283D88}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6795957 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6796238 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6796446 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6796618 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6797161 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.6797729 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DebugInformation\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6797880 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.6803084 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\Server","NAME NOT FOUND","Length: 138"
- "1:15:37.6803186 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.6803817 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\CustomAttributes\AppObject.Aliased","BUFFER TOO SMALL","Length: 0"
- "1:15:37.6804246 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\CustomAttributes\AppObject.RuntimeType","NAME NOT FOUND","Length: 0"
- "1:15:37.6804336 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\CustomAttributes\AppObject.EntryPoint","BUFFER TOO SMALL","Length: 0"
- "1:15:37.6805493 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.6806030 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DebugInformation\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6806175 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.6807065 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{AF86E2E0-B12D-4C6A-9C5A-D7AA65101E90}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6879059 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{2E5500B6-66AD-467F-ABB5-022A64283D88}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6879472 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{AF86E2E0-B12D-4C6A-9C5A-D7AA65101E90}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6879898 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{2E5500B6-66AD-467F-ABB5-022A64283D88}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.6880462 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{AF86E2E0-B12D-4C6A-9C5A-D7AA65101E90}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.6880474 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6880680 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6881220 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6882011 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.6882479 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.6883206 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.6883813 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.6884495 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6885292 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.6885528 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32\InprocServer32","NAME NOT FOUND","Length: 144"
- "1:15:37.6885959 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.6886463 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.6887152 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.6887961 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.6888296 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.6888712 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.6889138 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.6889956 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6890792 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6891221 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6892546 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{92696C00-7578-48E1-AC1A-2CA909E2C8CF}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6895347 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\actxprxy.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.6906235 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6906552 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6907156 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6907868 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.6908119 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.6908617 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.6908750 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\(Default)","NAME NOT FOUND","Length: 144"
- "1:15:37.6909100 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6909794 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.6909933 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\InProcServer32\InprocServer32","NAME NOT FOUND","Length: 144"
- "1:15:37.6910274 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.6910781 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.6911288 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.6911910 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.6912179 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.6912559 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.6912801 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.6913543 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6914153 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6914416 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6953247 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{92696C00-7578-48E1-AC1A-2CA909E2C8CF}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.6954077 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{92696C00-7578-48E1-AC1A-2CA909E2C8CF}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.7015798 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.7016387 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.7018068 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.7066450 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.7066839 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.7067504 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.7067673 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\(Default)","NAME NOT FOUND","Length: 144"
- "1:15:37.7068110 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.7068415 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.7068892 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.7069828 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\InProcHandler32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.7070978 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.7071757 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\InProcHandler32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.7072871 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.7073182 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.7074087 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.7074860 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.7075207 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.7078733 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.UI.Immersive.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.7084163 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{CD292360-2763-4085-8A9F-74B224A29175}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.7084900 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{CD292360-2763-4085-8A9F-74B224A29175}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.7085697 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{CD292360-2763-4085-8A9F-74B224A29175}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.7088628 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{CF651713-CD08-4FD8-B697-A281B6544E2E}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.7089666 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{CF651713-CD08-4FD8-B697-A281B6544E2E}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.7090451 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{CF651713-CD08-4FD8-B697-A281B6544E2E}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.7093128 PM","wwahost.exe","2812","RegOpenKey","HKCR\Extensions\ContractId\Windows.Launch\PackageId\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.7095495 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Extensions\ContractId\Windows.Launch\PackageId\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\Icon","BUFFER OVERFLOW","Length: 144"
- "1:15:37.7095598 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Extensions\ContractId\Windows.Launch\PackageId\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\Icon","BUFFER OVERFLOW","Length: 144"
- "1:15:37.7095821 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Extensions\ContractId\Windows.Launch\PackageId\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\DisplayName","BUFFER OVERFLOW","Length: 144"
- "1:15:37.7095915 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Extensions\ContractId\Windows.Launch\PackageId\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\DisplayName","BUFFER OVERFLOW","Length: 144"
- "1:15:37.7096126 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Extensions\ContractId\Windows.Launch\PackageId\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\Description","BUFFER OVERFLOW","Length: 144"
- "1:15:37.7096222 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Extensions\ContractId\Windows.Launch\PackageId\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\Description","BUFFER OVERFLOW","Length: 144"
- "1:15:37.7096585 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Extensions\ContractId\Windows.Launch\PackageId\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\CustomProperties","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.7096805 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.7096995 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.7097527 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.7098106 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DebugInformation\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.7098263 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.7101267 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","REPARSE","Desired Access: Read"
- "1:15:37.7101762 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\PackageRootFolder","BUFFER OVERFLOW","Length: 144"
- "1:15:37.7104807 PM","wwahost.exe","2812","RegCreateKey","HKCU\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe%5Cresources.pri","REPARSE","Desired Access: Read/Write"
- "1:15:37.7105043 PM","wwahost.exe","2812","RegCreateKey","HKCU\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe%5Cresources.pri","ACCESS DENIED","Desired Access: Read/Write"
- "1:15:37.7105299 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\WWAHost.exe","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.7106878 PM","wwahost.exe","2812","RegCreateKey","HKCU\Software\Classes\Local Settings\MrtCache","ACCESS DENIED","Desired Access: Maximum Allowed"
- "1:15:37.7107838 PM","wwahost.exe","2812","CreateFile","C:\ProgramData\PRICache","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
- "1:15:37.7110289 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Query Value"
- "1:15:37.7111385 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\AC\PRICache","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
- "1:15:37.7112517 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","REPARSE","Desired Access: Read"
- "1:15:37.7112985 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\PackageRootFolder","BUFFER OVERFLOW","Length: 144"
- "1:15:37.7116468 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\resources.pri","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.7138978 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Query Value"
- "1:15:37.7139880 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\Microsoft.BingNews_8wekyb3d8bbwe","REPARSE","Desired Access: Read/Write"
- "1:15:37.7141145 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\ManifestLanguagesList","BUFFER OVERFLOW","Length: 144"
- "1:15:37.7141269 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\ManifestLanguagesList","BUFFER OVERFLOW","Length: 144"
- "1:15:37.7141921 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\OverrideLanguagesList","NAME NOT FOUND","Length: 144"
- "1:15:37.7148840 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\windows.ui.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.7149766 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\windows.ui.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.7150639 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\windows.ui.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.7852700 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.UI.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.7856317 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\NInput.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.7857307 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\NInput.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.7858209 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\NInput.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.8300799 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\ninput.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.8305100 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\2c3e6d9f-8298-450f-8e5d-49b724f1216f","NAME NOT FOUND","Length: 524"
- "1:15:37.8305526 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\954cc269-9c80-41b9-a2cd-ce4c8ccf59a2","NAME NOT FOUND","Length: 524"
- "1:15:37.8306021 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\a3d95055-34cc-4e4a-b99f-ec88f5370495","NAME NOT FOUND","Length: 524"
- "1:15:37.8306268 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\23e0d3d9-6334-4edd-9c80-54d3d7cfa8da","NAME NOT FOUND","Length: 524"
- "1:15:37.8337698 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\DirectManipulation","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.8359767 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{C7EE80FC-8335-492C-81FB-11D2E10B2FF9}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.8360509 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{C7EE80FC-8335-492C-81FB-11D2E10B2FF9}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.8361324 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{C7EE80FC-8335-492C-81FB-11D2E10B2FF9}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.8862136 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Resources.Core.ResourceManager\Server","NAME NOT FOUND","Length: 138"
- "1:15:37.8862236 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Resources.Core.ResourceManager","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.8970625 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.ApplicationView\Server","NAME NOT FOUND","Length: 138"
- "1:15:37.8970727 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.ApplicationView","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.8972560 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Scaling","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.8973088 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Scaling","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.8976997 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Query Value"
- "1:15:37.8977999 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\Microsoft.BingNews_8wekyb3d8bbwe","REPARSE","Desired Access: Read/Write"
- "1:15:37.8979418 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\ManifestLanguagesList","BUFFER OVERFLOW","Length: 144"
- "1:15:37.8979542 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\ManifestLanguagesList","BUFFER OVERFLOW","Length: 144"
- "1:15:37.8980085 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\OverrideLanguagesList","NAME NOT FOUND","Length: 144"
- "1:15:37.8981821 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Query Value"
- "1:15:37.8982530 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\Microsoft.BingNews_8wekyb3d8bbwe","REPARSE","Desired Access: Read"
- "1:15:37.8985277 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.AccessibilitySettings\Server","NAME NOT FOUND","Length: 138"
- "1:15:37.8985383 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.AccessibilitySettings","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.9027703 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.Core.CoreWindow\Server","NAME NOT FOUND","Length: 138"
- "1:15:37.9027809 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.Core.CoreWindow","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:37.9028890 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Query Value"
- "1:15:37.9029747 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\Microsoft.BingNews_8wekyb3d8bbwe","REPARSE","Desired Access: Read/Write"
- "1:15:37.9031078 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\ManifestLanguagesList","BUFFER OVERFLOW","Length: 144"
- "1:15:37.9031187 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\ManifestLanguagesList","BUFFER OVERFLOW","Length: 144"
- "1:15:37.9031561 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\OverrideLanguagesList","NAME NOT FOUND","Length: 144"
- "1:15:37.9032162 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","REPARSE","Desired Access: Read"
- "1:15:37.9166776 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9167591 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9168409 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9169221 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.9169523 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.9170115 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.9170730 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.9171328 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9172131 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.9172288 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InProcServer32\InprocServer32","NAME NOT FOUND","Length: 144"
- "1:15:37.9172696 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.9173278 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.9173867 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.9174588 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.9174875 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.9175319 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.9175605 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.9176662 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9177402 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9177909 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9217470 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots","NAME NOT FOUND","Desired Access: Enumerate Sub Keys"
- "1:15:37.9219091 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\wwahost.exe.Local","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.9726070 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9200.16384_none_7762d5fd3178b04e\comctl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.9734308 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9200.16384_none_7762d5fd3178b04e\comctl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.9740357 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragScrollInset","NAME NOT FOUND","Length: 16"
- "1:15:37.9741227 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragScrollDelay","NAME NOT FOUND","Length: 16"
- "1:15:37.9742005 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay","NAME NOT FOUND","Length: 16"
- "1:15:37.9742760 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragScrollInterval","NAME NOT FOUND","Length: 16"
- "1:15:37.9743463 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IEharden","NAME NOT FOUND","Length: 144"
- "1:15:37.9743877 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.9752408 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\FlipAhead\NotificationDelay","NAME NOT FOUND","Length: 144"
- "1:15:37.9753144 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Internet Explorer\Security\Floppy Access","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9753588 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Security\Adv AddrBar Spoof Detection","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9753956 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Internet Explorer\Security\Adv AddrBar Spoof Detection","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9755396 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.9755797 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.9756380 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck","NAME NOT FOUND","Length: 144"
- "1:15:37.9757325 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck","NAME NOT FOUND","Length: 144"
- "1:15:37.9758910 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Secur32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.9760039 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Secur32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.9761107 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Secur32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.9764597 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\secur32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.9768385 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\SSPICLI.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.9769417 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\SSPICLI.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.9770441 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\SSPICLI.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:37.9773861 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\sspicli.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:37.9784550 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9784942 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9785304 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9785669 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9786038 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9787804 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9788181 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9788616 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9790590 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9791021 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9791423 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9792413 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","ACCESS DENIED","Desired Access: Read/Write"
- "1:15:37.9792766 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\WWAHost.exe","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.9794692 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9795087 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9795685 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9797566 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9797949 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9798305 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9800385 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9800784 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9801143 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9802281 PM","wwahost.exe","2812","RegEnumKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones","NO MORE ENTRIES","Index: 5, Length: 288"
- "1:15:37.9802812 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9803247 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9803627 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9803989 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9804370 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9806081 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9806504 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9806866 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9808701 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9809076 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9809432 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9810404 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","ACCESS DENIED","Desired Access: Read/Write"
- "1:15:37.9810697 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\WWAHost.exe","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.9812309 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9812689 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9813042 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9815062 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9815469 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9815831 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9817670 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9818041 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9818424 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9819523 PM","wwahost.exe","2812","RegEnumKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones","NO MORE ENTRIES","Index: 5, Length: 288"
- "1:15:37.9819985 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9820353 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9820718 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9821165 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9821784 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9823852 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9824314 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9824694 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9826553 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9826934 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9827353 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9828319 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","ACCESS DENIED","Desired Access: Read/Write"
- "1:15:37.9828612 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\WWAHost.exe","BUFFER OVERFLOW","Information: Owner"
- "1:15:37.9830197 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9830604 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9830988 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9833098 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9833514 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9833882 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9835959 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9836352 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9836711 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9837740 PM","wwahost.exe","2812","RegEnumKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones","NO MORE ENTRIES","Index: 5, Length: 288"
- "1:15:37.9838323 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9838607 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9839449 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9840415 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.9840801 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.9841676 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.9842491 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.9843500 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9844792 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.9845003 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InProcServer32\InprocServer32","NAME NOT FOUND","Length: 144"
- "1:15:37.9845549 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.9846346 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.9847222 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.9848194 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.9848583 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.9849244 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.9849636 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.9850805 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9851795 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9852226 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9854092 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Zoom","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9854493 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Zoom","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9856265 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Zoom\ZoomDisabled","NAME NOT FOUND","Length: 144"
- "1:15:37.9856576 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Internet Explorer\Zoom","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9857989 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9858614 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9858994 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
- "1:15:37.9859293 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9859507 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9859891 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
- "1:15:37.9861590 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\MinimumSystemTimerResolution","NAME NOT FOUND","Length: 144"
- "1:15:37.9862236 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\MinimumSystemTimerResolution","NAME NOT FOUND","Length: 144"
- "1:15:37.9862432 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\RenderingLoopMaxTime","NAME NOT FOUND","Length: 144"
- "1:15:37.9863431 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9864050 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\PageSetup\Print_Background","NAME NOT FOUND","Length: 144"
- "1:15:37.9864524 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\MenuExt","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9865074 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Nls\CodePage","REPARSE","Desired Access: Read"
- "1:15:37.9868430 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSize","NAME NOT FOUND","Length: 144"
- "1:15:37.9868844 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSizePrivate","NAME NOT FOUND","Length: 144"
- "1:15:37.9869598 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\International\Scripts","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9872059 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\AcceptLanguage","NAME NOT FOUND","Length: 144"
- "1:15:37.9872717 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TravelLog","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9873091 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\TravelLog","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9873523 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TravelLog","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9873861 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\TravelLog","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9874238 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TravelLog","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9874609 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\TravelLog","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9877459 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\MaximumAllowedAllocationSize","NAME NOT FOUND","Length: 144"
- "1:15:37.9879324 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9879629 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9880716 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9881697 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.9882053 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.9882895 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.9883879 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.9884987 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9886294 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.9886494 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InProcServer32\InprocServer32","NAME NOT FOUND","Length: 144"
- "1:15:37.9886970 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.9887680 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.9888389 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.9889171 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:37.9890004 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.9890451 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.9891061 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.9891393 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:37.9892350 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9893122 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:37.9893524 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0138890 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\msimtf.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:38.0149271 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0149570 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0150343 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0151267 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0151614 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0152320 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.0152498 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\(Default)","NAME NOT FOUND","Length: 144"
- "1:15:38.0152975 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0154131 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.0154502 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InProcServer32\InprocServer32","NAME NOT FOUND","Length: 144"
- "1:15:38.0155173 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.0155867 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.0156555 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.0157243 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.0158073 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0158409 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0159024 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0159368 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0160331 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0161131 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0161506 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0162324 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0162553 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0163232 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0164105 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0164446 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0165152 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.0165330 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\(Default)","NAME NOT FOUND","Length: 144"
- "1:15:38.0165822 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0166746 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.0166933 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InProcServer32\InprocServer32","NAME NOT FOUND","Length: 144"
- "1:15:38.0167428 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.0168128 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.0168832 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.0169526 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.0170356 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0170694 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0171229 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0171564 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0172475 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0173266 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0173674 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0203069 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\powrprof.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:38.0207760 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\dcomp.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.0208777 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\dcomp.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.0209604 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\DXGI","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0209725 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\dcomp.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.0209897 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\DXGI","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0212852 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dcomp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:38.0215689 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\UseSWRender","NAME NOT FOUND","Length: 144"
- "1:15:38.0215874 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\UseSWRender","NAME NOT FOUND","Length: 144"
- "1:15:38.0217724 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\CONTROL\VIDEO\{E41E0436-9CB3-4E45-8C09-ED35631B9477}\0000","REPARSE","Desired Access: Read"
- "1:15:38.0218276 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000\PruningMode","NAME NOT FOUND","Length: 52"
- "1:15:38.0218916 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Enum\PCI\VEN_1002&DEV_675D&SUBSYS_2B221028&REV_00\4&1136de53&0&0008\HardwareID","BUFFER OVERFLOW","Length: 271"
- "1:15:38.0221222 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\CONTROL\VIDEO\{E41E0436-9CB3-4E45-8C09-ED35631B9477}\0001","REPARSE","Desired Access: Read"
- "1:15:38.0221760 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000\PruningMode","NAME NOT FOUND","Length: 52"
- "1:15:38.0222255 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Enum\PCI\VEN_1002&DEV_675D&SUBSYS_2B221028&REV_00\4&1136de53&0&0008\HardwareID","BUFFER OVERFLOW","Length: 271"
- "1:15:38.0904415 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Manipulation","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0917941 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\mshtml.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:38.0925645 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0925983 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0926753 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0927969 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0928358 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0929038 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.0929207 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\(Default)","NAME NOT FOUND","Length: 144"
- "1:15:38.0929647 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0930601 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.0930776 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\InProcServer32\InprocServer32","NAME NOT FOUND","Length: 144"
- "1:15:38.0931229 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.0931866 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.0932678 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.0933575 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0933888 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0934362 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0934716 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0935654 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0936382 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0936841 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0939711 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wwahost.exe","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0940071 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0940300 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0940892 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0941679 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0941975 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0942561 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.0943168 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.0943774 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0944064 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.0944686 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0944991 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0945441 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.0945727 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.1073145 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\DXGI","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.1073541 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\DXGI","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.1090457 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\MaximumAllowedAllocationSize","NAME NOT FOUND","Length: 144"
- "1:15:38.1091369 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{1A887A1C-8182-4463-B485-38A701B839BA}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.1092220 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{1A887A1C-8182-4463-B485-38A701B839BA}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.1093098 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{1A887A1C-8182-4463-B485-38A701B839BA}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.1101191 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{1C613948-2128-4731-A329-EF818F969E04}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.1101997 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{1C613948-2128-4731-A329-EF818F969E04}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.1102845 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{1C613948-2128-4731-A329-EF818F969E04}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.1108632 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Query Value"
- "1:15:38.1109634 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\Microsoft.BingNews_8wekyb3d8bbwe","REPARSE","Desired Access: Read/Write"
- "1:15:38.1111189 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\ManifestLanguagesList","BUFFER OVERFLOW","Length: 144"
- "1:15:38.1111349 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\ManifestLanguagesList","BUFFER OVERFLOW","Length: 144"
- "1:15:38.1111880 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\OverrideLanguagesList","NAME NOT FOUND","Length: 144"
- "1:15:38.1112520 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.1113054 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\PageSetup\Print_Background","NAME NOT FOUND","Length: 144"
- "1:15:38.1113543 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\MenuExt","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.1114071 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSize","NAME NOT FOUND","Length: 144"
- "1:15:38.1114256 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSizePrivate","NAME NOT FOUND","Length: 144"
- "1:15:38.1115152 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\AcceptLanguage","NAME NOT FOUND","Length: 144"
- "1:15:38.1117612 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.WebUI.WebUIApplication\Server","NAME NOT FOUND","Length: 138"
- "1:15:38.1117709 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.WebUI.WebUIApplication","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:38.1416414 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WwaApi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:38.1420266 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\565e0113-343e-43a3-a927-a17037182ff2","NAME NOT FOUND","Length: 524"
- "1:15:38.1530810 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.1531226 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.1532086 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.1533004 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.1533333 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.1534006 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.1534978 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.1535651 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.1536536 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.1536708 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\InProcServer32\InprocServer32","NAME NOT FOUND","Length: 144"
- "1:15:38.1537143 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.1537855 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.1538501 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.1539340 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.1539657 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.1540137 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.1540442 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.1541369 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.1542093 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.1542485 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.1546307 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize","NAME NOT FOUND","Length: 144"
- "1:15:38.1547016 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize","NAME NOT FOUND","Length: 144"
- "1:15:38.1547457 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize","NAME NOT FOUND","Length: 144"
- "1:15:38.1547910 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize","NAME NOT FOUND","Length: 144"
- "1:15:38.1548933 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.1549298 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.1550850 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\FrameTabWindow","NAME NOT FOUND","Length: 144"
- "1:15:38.1551097 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FrameTabWindow","NAME NOT FOUND","Length: 144"
- "1:15:38.1551294 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\FrameMerging","NAME NOT FOUND","Length: 144"
- "1:15:38.1551463 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FrameMerging","NAME NOT FOUND","Length: 144"
- "1:15:38.1551614 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\SessionMerging","NAME NOT FOUND","Length: 144"
- "1:15:38.1551734 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\SessionMerging","NAME NOT FOUND","Length: 144"
- "1:15:38.1551855 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\AdminTabProcs","NAME NOT FOUND","Length: 144"
- "1:15:38.1551967 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\AdminTabProcs","NAME NOT FOUND","Length: 144"
- "1:15:38.1552190 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\TabProcGrowth","NAME NOT FOUND","Length: 144"
- "1:15:38.1558487 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\tzres.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.1559598 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\tzres.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.1560585 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\tzres.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.1563987 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\tzres.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:38.1566619 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\tzres.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:38.1568986 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\tzres.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.1569921 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\tzres.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.1570836 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\tzres.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.1573858 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\tzres.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:38.1576297 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\tzres.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:38.1579062 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSize","NAME NOT FOUND","Length: 144"
- "1:15:38.1579282 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSizePrivate","NAME NOT FOUND","Length: 144"
- "1:15:38.1580097 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IEDevTools\Options","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.1580707 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\IEDevTools\Options","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.1585609 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\text/xml\UserChoice","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.1586720 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\MIME\Database\Content Type\text/xml","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.1587795 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\MIME\Database\Content Type\text/xml","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.1973972 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\Autogen\JSByteCodeCache_64","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:38.2018041 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\IsTextPlainHonored","NAME NOT FOUND","Length: 144"
- "1:15:38.2019740 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\default.html","END OF FILE","Offset: 3,296, Length: 4,896"
- "1:15:38.2020142 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\default.html","END OF FILE","Offset: 3,296, Length: 4,896"
- "1:15:38.2030502 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck","NAME NOT FOUND","Length: 144"
- "1:15:38.2031247 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck","NAME NOT FOUND","Length: 144"
- "1:15:38.2033834 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\PROTOCOLS\Name-Space Handler\","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.2034918 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\PROTOCOLS\Name-Space Handler","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.2035271 PM","wwahost.exe","2812","RegEnumKey","HKCR\PROTOCOLS\Name-Space Handler","NO MORE ENTRIES","Index: 1, Length: 288"
- "1:15:38.2067860 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\PredictedViewExpansion","NAME NOT FOUND","Length: 144"
- "1:15:38.2068204 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\ContentLayerCacheExpansion","NAME NOT FOUND","Length: 144"
- "1:15:38.2068448 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\PredictedViewChangeThreshold","NAME NOT FOUND","Length: 144"
- "1:15:38.2068690 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\PredictedViewChangeThresholdPaint","NAME NOT FOUND","Length: 144"
- "1:15:38.2074051 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\microsoft.system.package.metadata\Autogen\JSByteCodeCache_64","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:38.2109818 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\common\dynamicpano\js\dynamicPanoAuth.js","PATH NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.2116827 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.2118092 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.2118826 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.2653636 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\css\ui-light.css","END OF FILE","Offset: 114,370, Length: 318"
- "1:15:38.2660902 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.2661599 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.2801900 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\common\css\und-latn\immersive.css","END OF FILE","Offset: 114,496, Length: 192"
- "1:15:38.2808979 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.2809691 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.2934423 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\common\css\und-latn\common.css","END OF FILE","Offset: 119,307, Length: 3,573"
- "1:15:38.2940481 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.2941269 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.3094556 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\css\und-latn\default.css","END OF FILE","Offset: 239,471, Length: 6,289"
- "1:15:38.3100675 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.3101369 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.3249027 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\css\und-latn\partners.css","END OF FILE","Offset: 2,018, Length: 6,174"
- "1:15:38.3255816 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.3256507 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.3601701 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\css\und-latn\apNewsTheme.css","END OF FILE","Offset: 42,599, Length: 6,553"
- "1:15:38.3608412 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.3609157 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.3945981 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\nytshared\und-latn\nytTheme.css","END OF FILE","Offset: 127,530, Length: 3,542"
- "1:15:38.3952875 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.3953630 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.4117226 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\wsjshared\und-latn\wsjTheme.css","END OF FILE","Offset: 90,927, Length: 7,377"
- "1:15:38.4127033 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\.png\Content Type","NAME NOT FOUND","Length: 144"
- "1:15:38.4127987 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\.png\Content Type","NAME NOT FOUND","Length: 144"
- "1:15:38.4135712 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Description","NAME NOT FOUND","Length: 144"
- "1:15:38.4135947 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\ParsingName","NAME NOT FOUND","Length: 144"
- "1:15:38.4136044 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\InfoTip","NAME NOT FOUND","Length: 144"
- "1:15:38.4136137 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\LocalizedName","NAME NOT FOUND","Length: 144"
- "1:15:38.4136234 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Icon","NAME NOT FOUND","Length: 144"
- "1:15:38.4136328 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Security","NAME NOT FOUND","Length: 144"
- "1:15:38.4136421 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\StreamResource","NAME NOT FOUND","Length: 144"
- "1:15:38.4136515 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\StreamResourceType","NAME NOT FOUND","Length: 144"
- "1:15:38.4136741 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Roamable","NAME NOT FOUND","Length: 144"
- "1:15:38.4136835 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PreCreate","NAME NOT FOUND","Length: 144"
- "1:15:38.4136928 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Stream","NAME NOT FOUND","Length: 144"
- "1:15:38.4137022 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PublishExpandedPath","NAME NOT FOUND","Length: 144"
- "1:15:38.4137115 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Attributes","NAME NOT FOUND","Length: 144"
- "1:15:38.4137209 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\FolderTypeID","NAME NOT FOUND","Length: 144"
- "1:15:38.4137303 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\InitFolderHandler","NAME NOT FOUND","Length: 144"
- "1:15:38.4137565 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PropertyBag","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.4138975 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\ParentFolder","NAME NOT FOUND","Length: 144"
- "1:15:38.4139071 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\Description","NAME NOT FOUND","Length: 144"
- "1:15:38.4139298 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\ParsingName","NAME NOT FOUND","Length: 144"
- "1:15:38.4139391 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\InfoTip","NAME NOT FOUND","Length: 144"
- "1:15:38.4139485 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\LocalizedName","NAME NOT FOUND","Length: 144"
- "1:15:38.4139579 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\Icon","NAME NOT FOUND","Length: 144"
- "1:15:38.4139672 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\Security","NAME NOT FOUND","Length: 144"
- "1:15:38.4139766 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\StreamResource","NAME NOT FOUND","Length: 144"
- "1:15:38.4139859 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\StreamResourceType","NAME NOT FOUND","Length: 144"
- "1:15:38.4140080 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\Roamable","NAME NOT FOUND","Length: 144"
- "1:15:38.4140173 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\PreCreate","NAME NOT FOUND","Length: 144"
- "1:15:38.4140267 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\Stream","NAME NOT FOUND","Length: 144"
- "1:15:38.4140490 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\Attributes","NAME NOT FOUND","Length: 144"
- "1:15:38.4140584 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\FolderTypeID","NAME NOT FOUND","Length: 144"
- "1:15:38.4140677 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\InitFolderHandler","NAME NOT FOUND","Length: 144"
- "1:15:38.4140919 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\PropertyBag","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.4141504 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Read"
- "1:15:38.4143240 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.4146558 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\KnownFolderSettings","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.4146871 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\KnownFolderSettings","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.4205885 PM","wwahost.exe","2812","CreateFileMapping","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\AC\INetCache\MSIMGSIZ.DAT","FILE LOCKED WITH WRITERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:38.4209136 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.4209501 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.4210301 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\AppHost","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.4210491 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.4211071 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\AppHost\EnableWebContentEvaluation","NAME NOT FOUND","Length: 144"
- "1:15:38.4211575 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.4212031 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.4212610 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\AppHost","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.4212979 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.4213202 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\(Default)","NAME NOT FOUND","Length: 144"
- "1:15:38.4213413 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\AppHost\EnableWebContentEvaluation","NAME NOT FOUND","Length: 144"
- "1:15:38.4214114 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.4214980 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.4215137 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InProcServer32\InprocServer32","NAME NOT FOUND","Length: 144"
- "1:15:38.4215490 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.4216009 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.4216526 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.4217072 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.4217733 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.4217990 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.4218394 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.4218720 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.4219786 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.4220250 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck","NAME NOT FOUND","Length: 144"
- "1:15:38.4220447 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.4220736 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.4220981 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck","NAME NOT FOUND","Length: 144"
- "1:15:38.4223559 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\AppHost","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.4224084 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\AppHost\EnableWebContentEvaluation","NAME NOT FOUND","Length: 144"
- "1:15:38.4224470 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WindowsCodecs.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:38.4225183 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\AppHost","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.4225759 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\AppHost\EnableWebContentEvaluation","NAME NOT FOUND","Length: 144"
- "1:15:38.4227172 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnIntranet","NAME NOT FOUND","Length: 144"
- "1:15:38.4227700 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnIntranet","NAME NOT FOUND","Length: 144"
- "1:15:38.4228198 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnIntranet","NAME NOT FOUND","Length: 144"
- "1:15:38.4228666 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.4229424 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.4229629 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.4229747 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.4229816 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.4230656 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.4230906 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.4231582 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.4232470 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.4232877 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.4233505 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.4234133 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.4234755 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.4235715 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.4235893 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\InprocServer32\InprocServer32","NAME NOT FOUND","Length: 144"
- "1:15:38.4236424 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.4237052 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.4237677 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.4238428 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.4238736 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.4239216 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.4239518 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.4240381 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.4241218 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.4241553 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.4361983 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\images\splash.scale-100.png","END OF FILE","Offset: 2,452, Length: 1,796"
- "1:15:38.5138619 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\jscript9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:38.5144028 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\JScript9","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.5145589 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{16D51579-A30B-4C8B-A276-0FF4DC41E755}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.5311385 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{16D51579-A30B-4C8B-A276-0FF4DC41E755}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.5318482 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Locale","REPARSE","Desired Access: Read"
- "1:15:38.5319049 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts","REPARSE","Desired Access: Read"
- "1:15:38.5319420 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Language Groups","REPARSE","Desired Access: Read"
- "1:15:38.5325938 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.5326257 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.5327021 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.5327897 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.5328223 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.5328878 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.5329536 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.5330182 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.5331181 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.5331371 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\InprocServer32\InprocServer32","NAME NOT FOUND","Length: 144"
- "1:15:38.5331824 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.5332479 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.5333140 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:38.5334009 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.5334341 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.5334854 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.5335180 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:38.5336140 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.5336925 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.5337272 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.6047671 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Foundation.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:38.6053642 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Foundation.Uri.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.6069457 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\Server","NAME NOT FOUND","Length: 138"
- "1:15:38.6069605 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:38.6185126 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.Networking.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.6191305 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:38.6197279 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.Networking.NetworkManager.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.6201994 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Platform.Networking.NetworkManager","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.6202438 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Networking.NetworkManager","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.6202706 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Networking.NetworkManager","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.6202933 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\ActivatableClassId\Platform.Networking.NetworkManager","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.6203947 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{205A397A-0A27-5ACC-A7B7-2149C760480E}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.6204252 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{205A397A-0A27-5ACC-A7B7-2149C760480E}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.6205290 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{205A397A-0A27-5ACC-A7B7-2149C760480E}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.6205637 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{205A397A-0A27-5ACC-A7B7-2149C760480E}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.6206709 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Wow6432Node\CLSID\{205A397A-0A27-5ACC-A7B7-2149C760480E}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.6206960 PM","wwahost.exe","2812","RegOpenKey","HKCR\Wow6432Node\CLSID\{205A397A-0A27-5ACC-A7B7-2149C760480E}","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.6290258 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Platform.Networking.NetworkManager","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.6290557 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Networking.NetworkManager","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.6291758 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Networking.NetworkManager\Server","NAME NOT FOUND","Length: 138"
- "1:15:38.6291888 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Networking.NetworkManager","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:38.6505209 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\clrhost.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:38.6508882 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\mscoree.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.6509957 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\mscoree.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.6510935 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\mscoree.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.7250705 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\mscoree.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:38.7722252 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\mscoree.dll.local","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.8340240 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:38.8345459 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\.NETFramework\CLRLoadLogDir","NAME NOT FOUND","Length: 144"
- "1:15:38.8345954 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.8346675 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.8347095 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
- "1:15:38.8347424 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.8347656 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.8348061 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
- "1:15:38.8351191 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.8351430 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.8351635 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.8352248 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\ThrottleStore\ThrottleExpiryTime","NAME NOT FOUND","Length: 24"
- "1:15:38.8352426 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.8352848 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
- "1:15:38.8353189 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.8353404 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.8354086 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
- "1:15:38.8354659 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows\winsqm8\101457945","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.8354883 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8\101457945","NAME NOT FOUND","Desired Access: Read"
- "1:15:38.8356567 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\mscoree.dll.local","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.8360159 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v2.0.50727\clr.dll","NAME NOT FOUND","Desired Access: Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Random Access, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.8731359 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll","ACCESS DENIED","Desired Access: Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Random Access, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.8734199 PM","wwahost.exe","2812","QueryDirectory","C:\Windows\Microsoft.NET\Framework64","NO MORE FILES",""
- "1:15:38.9449748 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:38.9454753 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\MSVCR110_CLR0400.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.9455870 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\MSVCR110_CLR0400.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:38.9456914 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\MSVCR110_CLR0400.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.0321724 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\msvcr110_clr0400.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:39.0335386 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\.NETFramework","ACCESS DENIED","Desired Access: Read"
- "1:15:39.0336542 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\.NETFramework\DisableConfigCache","NAME NOT FOUND","Length: 144"
- "1:15:39.0337143 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\.NETFramework","ACCESS DENIED","Desired Access: Read"
- "1:15:39.0342283 PM","wwahost.exe","2812","RegEnumValue","HKLM\SOFTWARE\Microsoft\.NETFramework","NO MORE ENTRIES","Index: 2, Length: 220"
- "1:15:39.0453386 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\api-ms-win-core-winrt-l1-1-0.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.0454599 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\api-ms-win-core-winrt-l1-1-0.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.0455819 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\api-ms-win-core-winrt-string-l1-1-0.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.0456821 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\api-ms-win-core-winrt-string-l1-1-0.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.0695857 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.DesignMode\Server","NAME NOT FOUND","Length: 138"
- "1:15:39.0696017 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.DesignMode","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:39.0700992 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.ApplicationModel.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:39.0705490 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\wwahost.exe.config","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.0706782 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoree.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.0708535 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoree.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.0709486 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\wwahost.exe.config","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Disallow Exclusive, Attributes: N, ShareMode: Read, AllocationSize: n/a"
- "1:15:39.1143663 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wwahost.exe","NAME NOT FOUND","Desired Access: Read"
- "1:15:39.1145326 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\fusion.localgac","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.1146337 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Fusion\CacheLocation","NAME NOT FOUND","Length: 144"
- "1:15:39.1147318 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB","NAME NOT FOUND","Length: 144"
- "1:15:39.1147665 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Fusion","NAME NOT FOUND","Desired Access: Read"
- "1:15:39.1148073 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Fusion\EnableLog","NAME NOT FOUND","Length: 144"
- "1:15:39.1148218 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Fusion\LoggingLevel","NAME NOT FOUND","Length: 144"
- "1:15:39.1148357 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Fusion\ForceLog","NAME NOT FOUND","Length: 144"
- "1:15:39.1148489 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Fusion\LogFailures","NAME NOT FOUND","Length: 144"
- "1:15:39.1148625 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Fusion\LogResourceBinds","NAME NOT FOUND","Length: 144"
- "1:15:39.1148764 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts","NAME NOT FOUND","Length: 144"
- "1:15:39.1148900 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries","NAME NOT FOUND","Length: 144"
- "1:15:39.1149063 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Fusion\DisableMSIPeek","NAME NOT FOUND","Length: 144"
- "1:15:39.1149975 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable","NAME NOT FOUND","Length: 144"
- "1:15:39.1219076 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries","NAME NOT FOUND","Length: 144"
- "1:15:39.1226227 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\NoNGen.txt","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.1231250 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ole32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.1232443 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ole32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.1237891 PM","wwahost.exe","2812","CreateFile","C:\windows\Microsoft.Net\assembly\GAC_MSIL\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll","PATH NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.1892824 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\5a23c5e185cb978f73c67718f6e061a4\mscorlib.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:39.1896742 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\StrongName","NAME NOT FOUND","Desired Access: Read"
- "1:15:39.1915360 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Platform.Networking.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.1916701 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Platform.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.1917917 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Platform.Networking.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.1919058 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Platform.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.1920220 PM","wwahost.exe","2812","CreateFile","C:\Windows\assembly\NativeImages_v4.0.30319_64\Platform","NAME NOT FOUND","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.2195407 PM","wwahost.exe","2812","CreateFile","C:\windows\assembly\GAC\PublisherPolicy.tme","PATH NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.2965614 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Security.Authentication.OnlineId.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.2966815 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Security.Authentication.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.2972623 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Networking.NetworkOperators.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.3003757 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Foundation.Collections.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.3160220 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Storage.Streams.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.4016797 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.UI.Xaml.Interop.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.4049033 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.System.Profile.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.4062484 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.ApplicationModel.Background.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.4075225 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Globalization.Fonts.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.4334918 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.UI.ApplicationSettings.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.4351701 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Data.Html.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.4547080 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Devices.Sms.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.4565801 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Graphics.Display.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.5300008 PM","wwahost.exe","2812","CreateFileMapping","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\Platform\6e7823fcc964cf9789d4f388f3042791\Platform.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:39.5320969 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Cryptography\Offload","NAME NOT FOUND","Desired Access: Read"
- "1:15:39.5340155 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA","NAME NOT FOUND","Desired Access: Read"
- "1:15:39.5483378 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Networking.Connectivity.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.6378069 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Networking\170d797fe060a5a3f9697960928c48d7\Windows.Networking.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:39.6390454 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Networking.Connectivity.NetworkStatusChangedEventHandler.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.7469520 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Networking.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:39.7999848 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:39.8004204 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\.NETFramework","ACCESS DENIED","Desired Access: Read"
- "1:15:39.8005402 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\.NETFramework\CseOn","NAME NOT FOUND","Length: 144"
- "1:15:39.8005915 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\.NETFramework","ACCESS DENIED","Desired Access: Read"
- "1:15:39.8006612 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\.NETFramework\TailCallOpt","NAME NOT FOUND","Length: 144"
- "1:15:39.8007105 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\.NETFramework","ACCESS DENIED","Desired Access: Read"
- "1:15:39.8007699 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\.NETFramework\PInvokeInline","NAME NOT FOUND","Length: 144"
- "1:15:39.8008149 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\.NETFramework","ACCESS DENIED","Desired Access: Read"
- "1:15:39.8008713 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\.NETFramework\NewGCCalc","NAME NOT FOUND","Length: 144"
- "1:15:39.8009296 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\.NETFramework","ACCESS DENIED","Desired Access: Read"
- "1:15:39.8009870 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\.NETFramework\TURNOFFDEBUGINFO","NAME NOT FOUND","Length: 144"
- "1:15:39.8010325 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\.NETFramework","ACCESS DENIED","Desired Access: Read"
- "1:15:39.8010881 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\.NETFramework\DisableHotCold","NAME NOT FOUND","Length: 144"
- "1:15:39.8011352 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\.NETFramework\internal\jit\Perf","NAME NOT FOUND","Desired Access: Read"
- "1:15:39.8700222 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\api-ms-win-core-winrt-roparameterizediid-l1-1-0.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.8701270 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\api-ms-win-core-winrt-roparameterizediid-l1-1-0.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.8702722 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\bcrypt.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.8703660 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\bcrypt.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.8704548 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\bcrypt.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.8708134 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\bcrypt.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:39.8711651 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
- "1:15:39.8712336 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
- "1:15:39.8713018 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
- "1:15:39.8713492 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
- "1:15:39.8714506 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
- "1:15:39.8714986 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
- "1:15:39.8715511 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
- "1:15:39.8715958 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
- "1:15:39.8716683 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
- "1:15:39.8717141 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
- "1:15:39.8717645 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
- "1:15:39.8718092 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
- "1:15:39.8797207 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.Resources.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.8800485 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Platform.Resources.StringResourceLoader","NAME NOT FOUND","Desired Access: Read"
- "1:15:39.8801088 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Resources.StringResourceLoader","NAME NOT FOUND","Desired Access: Read"
- "1:15:39.8801472 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Resources.StringResourceLoader","NAME NOT FOUND","Desired Access: Read"
- "1:15:39.8801783 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\ActivatableClassId\Platform.Resources.StringResourceLoader","NAME NOT FOUND","Desired Access: Read"
- "1:15:39.8802969 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{D86095BD-EFD0-5B58-9176-430CFD0FAF4D}","NAME NOT FOUND","Desired Access: Read"
- "1:15:39.8803256 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{D86095BD-EFD0-5B58-9176-430CFD0FAF4D}","NAME NOT FOUND","Desired Access: Read"
- "1:15:39.8804210 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D86095BD-EFD0-5B58-9176-430CFD0FAF4D}","NAME NOT FOUND","Desired Access: Read"
- "1:15:39.8804490 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{D86095BD-EFD0-5B58-9176-430CFD0FAF4D}","NAME NOT FOUND","Desired Access: Read"
- "1:15:39.8805474 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Wow6432Node\CLSID\{D86095BD-EFD0-5B58-9176-430CFD0FAF4D}","NAME NOT FOUND","Desired Access: Read"
- "1:15:39.8805822 PM","wwahost.exe","2812","RegOpenKey","HKCR\Wow6432Node\CLSID\{D86095BD-EFD0-5B58-9176-430CFD0FAF4D}","NAME NOT FOUND","Desired Access: Read"
- "1:15:39.8966836 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Platform.Resources.StringResourceLoader","NAME NOT FOUND","Desired Access: Read"
- "1:15:39.8967141 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Resources.StringResourceLoader","NAME NOT FOUND","Desired Access: Read"
- "1:15:39.8968557 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Resources.StringResourceLoader\Server","NAME NOT FOUND","Length: 138"
- "1:15:39.8968907 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Resources.StringResourceLoader","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:39.8971799 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Platform.Resources.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.8973209 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Platform.Resources.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.9467999 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\api-ms-win-core-winrt-string-l1-1-0.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:39.9469103 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\api-ms-win-core-winrt-string-l1-1-0.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.0750282 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.App640a3541#\52610b15de6cf7f4ddd8b93f543abe24\Windows.ApplicationModel.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:40.0782029 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.ApplicationModel.Resources.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.1029807 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Resources.ResourceLoader\Server","NAME NOT FOUND","Length: 138"
- "1:15:40.1029958 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Resources.ResourceLoader","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:40.1053724 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Platform.Process","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.1054364 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Process","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.1054678 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Process","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.1054916 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\ActivatableClassId\Platform.Process","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.1055876 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{A8034CBD-D885-5F9F-A046-9C9BB9BD43E7}","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.1056123 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{A8034CBD-D885-5F9F-A046-9C9BB9BD43E7}","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.1056954 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{A8034CBD-D885-5F9F-A046-9C9BB9BD43E7}","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.1057222 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{A8034CBD-D885-5F9F-A046-9C9BB9BD43E7}","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.1058061 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Wow6432Node\CLSID\{A8034CBD-D885-5F9F-A046-9C9BB9BD43E7}","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.1058309 PM","wwahost.exe","2812","RegOpenKey","HKCR\Wow6432Node\CLSID\{A8034CBD-D885-5F9F-A046-9C9BB9BD43E7}","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.1818358 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Platform.Process","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.1818808 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Process","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.1820395 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Process\Server","NAME NOT FOUND","Length: 138"
- "1:15:40.1820540 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Process","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:40.2877948 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Storage.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:40.2884547 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Storage.ApplicationData.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.3125962 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.ApplicationData\Server","NAME NOT FOUND","Length: 138"
- "1:15:40.3126261 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.ApplicationData","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:40.3135180 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.Storage.ApplicationData.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:40.3149075 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{E1CDD77A-65D3-4DB0-B339-21F6A48CC2FF}","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.3150838 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{E1CDD77A-65D3-4DB0-B339-21F6A48CC2FF}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.3152383 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{E1CDD77A-65D3-4DB0-B339-21F6A48CC2FF}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:40.3157738 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingNews_8wekyb3d8bbwe\PSR","REPARSE","Desired Access: Query Value"
- "1:15:40.3160045 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Notifications\41C64E6DA3BC70E5","BUFFER TOO SMALL","Length: 0"
- "1:15:40.3163145 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
- "1:15:40.3164660 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
- "1:15:40.3166248 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
- "1:15:40.3167479 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
- "1:15:40.3182105 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.Instrumentation.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.3998348 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.UI.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:40.4004801 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.UI.ViewManagement.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.4006208 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.UI.ViewManagement.ApplicationView.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.5148278 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Media.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:40.5154059 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Media.MediaControl.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.5790188 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Globalization.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:40.5796395 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Globalization.DateTimeFormatting.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.5805127 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\common\dynamicpano\js\dynamicPanoAuth.js","PATH NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.6247883 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.KnownFolders\Server","NAME NOT FOUND","Length: 138"
- "1:15:40.6248046 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.KnownFolders","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:40.6254176 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\PROPSYS.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.6255381 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\PROPSYS.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.6256459 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\PROPSYS.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.6260519 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\propsys.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:40.6266483 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\Directory","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.6267036 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\Shell\Associations","ACCESS DENIED","Desired Access: Query Value"
- "1:15:40.6269764 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Directory\URL Protocol","NAME NOT FOUND","Length: 144"
- "1:15:40.6269961 PM","wwahost.exe","2812","RegQueryValue","HKCR\Directory\URL Protocol","NAME NOT FOUND","Length: 144"
- "1:15:40.6272146 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Directory\CurVer","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:40.6272406 PM","wwahost.exe","2812","RegOpenKey","HKCR\Directory\CurVer","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:40.6274793 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Directory\IsShortcut","NAME NOT FOUND","Length: 144"
- "1:15:40.6274963 PM","wwahost.exe","2812","RegQueryValue","HKCR\Directory\IsShortcut","NAME NOT FOUND","Length: 144"
- "1:15:40.6276019 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Directory\FriendlyTypeName","NAME NOT FOUND","Length: 144"
- "1:15:40.6278256 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\shell32.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:40.6289216 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
- "1:15:40.6290086 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
- "1:15:40.6291009 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
- "1:15:40.6291716 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
- "1:15:40.6296002 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Explorer","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:40.6296376 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Explorer","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:40.6297173 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\LocalState","ACCESS DENIED","Desired Access: Read Data/List Directory, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.6298414 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\LocalState\state.json","ACCESS DENIED","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.6306963 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\jscript9.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:40.6309734 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
- "1:15:40.6310669 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
- "1:15:40.6311602 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
- "1:15:40.6312399 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
- "1:15:40.6329813 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\RoamingState","ACCESS DENIED","Desired Access: Read Data/List Directory, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.6331606 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\RoamingState\state.json","ACCESS DENIED","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.6335721 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.CrashReporting.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.6339732 PM","wwahost.exe","2812","QueryDirectory","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.CrashReporting*.winmd","NO SUCH FILE","Filter: Platform.CrashReporting*.winmd"
- "1:15:40.6341535 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Platform.CrashReporting.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.6342854 PM","wwahost.exe","2812","QueryDirectory","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Platform.CrashReporting*.winmd","NO SUCH FILE","Filter: Platform.CrashReporting*.winmd"
- "1:15:40.6344550 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Platform.CrashReporting.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.6345830 PM","wwahost.exe","2812","QueryDirectory","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Platform.CrashReporting*.winmd","NO SUCH FILE","Filter: Platform.CrashReporting*.winmd"
- "1:15:40.6347925 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.UI.WebUI.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.6352148 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.ApplicationModel.ISuspendingEventArgs.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.7149682 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.ApplicationModel.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:40.7936847 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Graphics.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:40.7944100 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Graphics.Display.DisplayProperties.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.7950575 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Display.DisplayProperties\Server","NAME NOT FOUND","Length: 138"
- "1:15:40.7950732 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Display.DisplayProperties","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:40.8265982 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.Graphics.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:40.8270069 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\fa5cf675-72eb-49e2-b447-de5552faff1c","NAME NOT FOUND","Length: 524"
- "1:15:40.8274627 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.Globalization.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.8278790 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Platform.Globalization.Marketization","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.8279189 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Globalization.Marketization","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.8279472 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Globalization.Marketization","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.8279717 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\ActivatableClassId\Platform.Globalization.Marketization","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.8280710 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{A33E8EAB-F3C4-5E16-89C0-628E2168A4E9}","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.8281256 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{A33E8EAB-F3C4-5E16-89C0-628E2168A4E9}","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.8282488 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{A33E8EAB-F3C4-5E16-89C0-628E2168A4E9}","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.8282763 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{A33E8EAB-F3C4-5E16-89C0-628E2168A4E9}","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.8283747 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Wow6432Node\CLSID\{A33E8EAB-F3C4-5E16-89C0-628E2168A4E9}","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.8284015 PM","wwahost.exe","2812","RegOpenKey","HKCR\Wow6432Node\CLSID\{A33E8EAB-F3C4-5E16-89C0-628E2168A4E9}","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.8490677 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Platform.Globalization.Marketization","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.8491127 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Globalization.Marketization","NAME NOT FOUND","Desired Access: Read"
- "1:15:40.8492805 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Globalization.Marketization\Server","NAME NOT FOUND","Length: 138"
- "1:15:40.8492959 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Globalization.Marketization","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:40.8496382 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Platform.Globalization.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.8497895 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Platform.Globalization.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:40.8781911 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Gloaae92e31#\678926c3ae1779d1515a93d5afbc45f4\Windows.Globalization.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:40.9737227 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Foundation\87788b39516ef9bf7e5c60a2b5fb3aeb\Windows.Foundation.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:41.0458934 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime\92dbe33346751ef372e3590eb71b1cac\System.Runtime.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:41.1597677 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System\67f7ddcb264bac2f465b439bb19616b1\System.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:41.2668261 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\3145945493fbcef888aa44b0081134cc\System.Core.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:41.4147463 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.System\4022b99b813a11eb3afa84dd8fd0eee6\Windows.System.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:41.4367063 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.System.UserProfile.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.4369934 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.UserProfile.GlobalizationPreferences\Server","NAME NOT FOUND","Length: 138"
- "1:15:41.4370018 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.UserProfile.GlobalizationPreferences","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:41.4373393 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.Globalization.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:41.4925545 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.ApplicationModel.Resources.Core.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.4937499 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\api-ms-win-ro-typeresolution-l1-1-0.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.4938540 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\api-ms-win-ro-typeresolution-l1-1-0.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.4940089 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
- "1:15:41.4940861 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
- "1:15:41.4941595 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
- "1:15:41.4942102 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
- "1:15:41.4948197 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
- "1:15:41.4949132 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
- "1:15:41.4949745 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
- "1:15:41.4950204 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
- "1:15:41.4953639 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
- "1:15:41.4954207 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
- "1:15:41.4954798 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
- "1:15:41.4955296 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
- "1:15:41.4959900 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Platform.ServicesAccessor","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.4960310 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.ServicesAccessor","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.4960609 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.ServicesAccessor","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.4960872 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\ActivatableClassId\Platform.ServicesAccessor","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.4961886 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{CAD01161-1440-542A-BE93-1C79B0C08AD3}","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.4962152 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{CAD01161-1440-542A-BE93-1C79B0C08AD3}","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.4963036 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{CAD01161-1440-542A-BE93-1C79B0C08AD3}","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.4963302 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{CAD01161-1440-542A-BE93-1C79B0C08AD3}","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.4964240 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Wow6432Node\CLSID\{CAD01161-1440-542A-BE93-1C79B0C08AD3}","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.4964503 PM","wwahost.exe","2812","RegOpenKey","HKCR\Wow6432Node\CLSID\{CAD01161-1440-542A-BE93-1C79B0C08AD3}","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.5039102 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Platform.ServicesAccessor","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.5040122 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.ServicesAccessor","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.5043536 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.ServicesAccessor\Server","NAME NOT FOUND","Length: 138"
- "1:15:41.5043913 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.ServicesAccessor","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:41.5106609 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.Configuration.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.5109885 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Platform.Configuration.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.5112789 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Platform.Configuration.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.5121950 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Platform.Instrumentation.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.5125086 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Platform.Instrumentation.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.5129554 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.Configuration.Manifest.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.5132630 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Platform.Configuration.Manifest.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.5135612 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Platform.Configuration.Manifest.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.5139917 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.Diagnostics.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.5142857 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Platform.Diagnostics.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.5145863 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Platform.Diagnostics.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.6834275 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\8517b132cbe0b329b40bc6a9ef106828\System.Configuration.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:41.7879454 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml\4334f45efbe62a6415f2cb7393c59f74\System.Xml.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:41.8119227 PM","wwahost.exe","2812","ReadFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config","END OF FILE","Offset: 35,983, Length: 4,096"
- "1:15:41.8122511 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\wwahost.exe.config","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8123975 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\wwahost.exe.config","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8138715 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\rasapi32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8139648 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\rasapi32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8140762 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\rasapi32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8141698 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\rasapi32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8142700 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\rasapi32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8145866 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rasapi32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:41.8149766 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\rasman.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8150717 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\rasman.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8151970 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\rasman.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8155474 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rasman.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:41.8167292 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\ws2_32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8168844 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\ws2_32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8171108 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.8171850 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.8172140 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
- "1:15:41.8172360 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.8172523 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.8172801 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
- "1:15:41.8177498 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","REPARSE","Desired Access: Read"
- "1:15:41.8178932 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog\0D0D3D6C-18CC075D","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.8179198 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog\0D0D3D6C","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.8180665 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\00000006","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.8181634 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000001\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
- "1:15:41.8182545 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000002\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
- "1:15:41.8183252 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000003\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
- "1:15:41.8184045 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000004\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
- "1:15:41.8184704 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000005\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
- "1:15:41.8185301 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000006\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
- "1:15:41.8185872 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000007\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
- "1:15:41.8186481 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000008\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
- "1:15:41.8187067 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000009\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
- "1:15:41.8187638 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000010\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
- "1:15:41.8188214 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000011\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
- "1:15:41.8189422 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\0000001A","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.8191396 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\AddressFamily","NAME NOT FOUND","Length: 144"
- "1:15:41.8193660 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\AddressFamily","NAME NOT FOUND","Length: 144"
- "1:15:41.8195712 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\AddressFamily","NAME NOT FOUND","Length: 144"
- "1:15:41.8197834 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\AddressFamily","NAME NOT FOUND","Length: 144"
- "1:15:41.8199911 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\AddressFamily","NAME NOT FOUND","Length: 144"
- "1:15:41.8202085 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\AddressFamily","NAME NOT FOUND","Length: 144"
- "1:15:41.8204216 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000007\AddressFamily","NAME NOT FOUND","Length: 144"
- "1:15:41.8205459 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Winsock2\Parameters","REPARSE","Desired Access: Query Value"
- "1:15:41.8205791 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Ws2_32NumHandleBuckets","NAME NOT FOUND","Length: 144"
- "1:15:41.8205879 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Ws2_32SpinCount","NAME NOT FOUND","Length: 144"
- "1:15:41.8209625 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\mswsock.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:41.8212626 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.8213395 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.8213694 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
- "1:15:41.8213905 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.8214062 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.8214343 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
- "1:15:41.8218771 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Parameters","REPARSE","Desired Access: Read"
- "1:15:41.8219620 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock","REPARSE","Desired Access: Read"
- "1:15:41.8220407 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Setup Migration\Providers","REPARSE","Desired Access: Read"
- "1:15:41.8221808 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock","REPARSE","Desired Access: Read"
- "1:15:41.8223713 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Parameters","REPARSE","Desired Access: Read"
- "1:15:41.8224537 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock","REPARSE","Desired Access: Read"
- "1:15:41.8225285 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock","REPARSE","Desired Access: Read"
- "1:15:41.8226107 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Setup Migration\Providers","REPARSE","Desired Access: Read"
- "1:15:41.8227290 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock","REPARSE","Desired Access: Read"
- "1:15:41.8241731 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\.NETFramework\LegacyWPADSupport","NAME NOT FOUND","Length: 144"
- "1:15:41.8247460 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\winhttp.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8248432 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\winhttp.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8249579 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\winhttp.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8250530 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\winhttp.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8251424 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\winhttp.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8254605 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\winhttp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:41.8258979 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ShareCredsWithWinHttp","NAME NOT FOUND","Length: 144"
- "1:15:41.8259915 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp\DisableBranchCache","NAME NOT FOUND","Length: 144"
- "1:15:41.8262100 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\IPHLPAPI.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8263084 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\IPHLPAPI.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8263984 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\IPHLPAPI.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8267042 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\IPHLPAPI.DLL","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:41.8270175 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\WINNSI.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8271195 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\WINNSI.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8272095 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\WINNSI.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8275144 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\winnsi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:41.8291160 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\dhcpcsvc6.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8292159 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\dhcpcsvc6.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8293077 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\dhcpcsvc6.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8296041 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dhcpcsvc6.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:41.8301837 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\dhcpcsvc.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8302770 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\dhcpcsvc.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8303748 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\dhcpcsvc.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8306697 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dhcpcsvc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:41.8311986 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read"
- "1:15:41.8313474 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read"
- "1:15:41.8314666 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read"
- "1:15:41.8315819 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read"
- "1:15:41.8316480 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{97e1de57-d6fa-11e1-be62-806e6f6e6963}\EnableDhcp","NAME NOT FOUND","Length: 144"
- "1:15:41.8316870 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read"
- "1:15:41.8318035 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read"
- "1:15:41.8318566 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62fd552d-2a3f-4558-9937-3b0b4057f927}","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:41.8318928 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read"
- "1:15:41.8319441 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0b4f74ec-4340-4d00-b2ff-e77f0ec5eed1}","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:41.8319873 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read"
- "1:15:41.8320410 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{d20e8fa7-1438-440c-8296-653e483eb333}","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:41.8320761 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read"
- "1:15:41.8321283 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{d93979cc-e9be-4a24-a75a-4d792ec23e05}","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:41.8321678 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C728CD83-069D-4EAF-BAC9-5B79C65D1C90}","REPARSE","Desired Access: Read"
- "1:15:41.8322831 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0B1A6944-7F9A-43B4-9D0E-299C2B003D29}","REPARSE","Desired Access: Read"
- "1:15:41.8323577 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0B1A6944-7F9A-43B4-9D0E-299C2B003D29}\DhcpDomain","NAME NOT FOUND","Length: 144"
- "1:15:41.8323885 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{0B1A6944-7F9A-43B4-9D0E-299C2B003D29}","REPARSE","Desired Access: Read"
- "1:15:41.8324208 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\TCPIP6\Parameters\Interfaces\{0B1A6944-7F9A-43B4-9D0E-299C2B003D29}\Dhcpv6Domain","NAME NOT FOUND","Length: 144"
- "1:15:41.8324567 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3915EDAE-3B2F-4D83-98A4-FF3EB1FA73E5}","REPARSE","Desired Access: Read"
- "1:15:41.8325264 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3915EDAE-3B2F-4D83-98A4-FF3EB1FA73E5}\DhcpDomain","NAME NOT FOUND","Length: 144"
- "1:15:41.8325590 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3915EDAE-3B2F-4D83-98A4-FF3EB1FA73E5}","REPARSE","Desired Access: Read"
- "1:15:41.8325901 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\TCPIP6\Parameters\Interfaces\{3915EDAE-3B2F-4D83-98A4-FF3EB1FA73E5}\Dhcpv6Domain","NAME NOT FOUND","Length: 144"
- "1:15:41.8326257 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{40F8964E-7AF3-4B88-86E2-DCDBCADAB0A1}","REPARSE","Desired Access: Read"
- "1:15:41.8326925 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{40F8964E-7AF3-4B88-86E2-DCDBCADAB0A1}\DhcpDomain","NAME NOT FOUND","Length: 144"
- "1:15:41.8327217 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{40F8964E-7AF3-4B88-86E2-DCDBCADAB0A1}","REPARSE","Desired Access: Read"
- "1:15:41.8327510 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\TCPIP6\Parameters\Interfaces\{40F8964E-7AF3-4B88-86E2-DCDBCADAB0A1}\Dhcpv6Domain","NAME NOT FOUND","Length: 144"
- "1:15:41.8327857 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{97E1DE57-D6FA-11E1-BE62-806E6F6E6963}","REPARSE","Desired Access: Read"
- "1:15:41.8328150 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{97e1de57-d6fa-11e1-be62-806e6f6e6963}\RegistrationEnabled","NAME NOT FOUND","Length: 144"
- "1:15:41.8328238 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{97e1de57-d6fa-11e1-be62-806e6f6e6963}\RegisterAdapterName","NAME NOT FOUND","Length: 144"
- "1:15:41.8328316 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{97e1de57-d6fa-11e1-be62-806e6f6e6963}\Domain","NAME NOT FOUND","Length: 144"
- "1:15:41.8328398 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{97e1de57-d6fa-11e1-be62-806e6f6e6963}\DhcpDomain","NAME NOT FOUND","Length: 144"
- "1:15:41.8328832 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{97E1DE57-D6FA-11E1-BE62-806E6F6E6963}","REPARSE","Desired Access: Read"
- "1:15:41.8329016 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{97E1DE57-D6FA-11E1-BE62-806E6F6E6963}","NAME NOT FOUND","Desired Access: Read"
- "1:15:41.8329364 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{815D19A4-3D8E-45FE-A47E-7CE7F0B8E381}","REPARSE","Desired Access: Read"
- "1:15:41.8330016 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{815D19A4-3D8E-45FE-A47E-7CE7F0B8E381}\DhcpDomain","NAME NOT FOUND","Length: 144"
- "1:15:41.8330308 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{815D19A4-3D8E-45FE-A47E-7CE7F0B8E381}","REPARSE","Desired Access: Read"
- "1:15:41.8330604 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\TCPIP6\Parameters\Interfaces\{815D19A4-3D8E-45FE-A47E-7CE7F0B8E381}\Dhcpv6Domain","NAME NOT FOUND","Length: 144"
- "1:15:41.8330957 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{969429AB-1E8B-4A16-9F46-E66A3EBF489B}","REPARSE","Desired Access: Read"
- "1:15:41.8331603 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{969429AB-1E8B-4A16-9F46-E66A3EBF489B}\DhcpDomain","NAME NOT FOUND","Length: 144"
- "1:15:41.8331899 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{969429AB-1E8B-4A16-9F46-E66A3EBF489B}","REPARSE","Desired Access: Read"
- "1:15:41.8332189 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\TCPIP6\Parameters\Interfaces\{969429AB-1E8B-4A16-9F46-E66A3EBF489B}\Dhcpv6Domain","NAME NOT FOUND","Length: 144"
- "1:15:41.8332741 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Linkage","REPARSE","Desired Access: Read"
- "1:15:41.8333164 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Linkage\Bind","BUFFER OVERFLOW","Length: 144"
- "1:15:41.8333273 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Linkage\Bind","BUFFER OVERFLOW","Length: 144"
- "1:15:41.8333508 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Linkage\Bind","BUFFER OVERFLOW","Length: 144"
- "1:15:41.8333587 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Linkage\Bind","BUFFER OVERFLOW","Length: 144"
- "1:15:41.8334559 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ProxySettingsPerUser","NAME NOT FOUND","Length: 144"
- "1:15:41.8334912 PM","wwahost.exe","2812","RegOpenKey","HKCU","ACCESS DENIED","Desired Access: Query Value, Set Value"
- "1:15:41.8335174 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\WWAHost.exe","BUFFER OVERFLOW","Information: Owner"
- "1:15:41.8335887 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings","BUFFER OVERFLOW","Length: 144"
- "1:15:41.8335983 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings","BUFFER OVERFLOW","Length: 144"
- "1:15:41.8656748 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.Http\69640072694356ffed3bbe2d2352f935\System.Net.Http.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:41.8755985 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Package\Server","NAME NOT FOUND","Length: 138"
- "1:15:41.8756084 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Package","BUFFER TOO SMALL","Query: Full, Length: 0"
- "1:15:41.8855076 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\oleaut32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.8856139 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\oleaut32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:41.9825295 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Storage\702ec9a3c9175b1eb68df2438ef50b27\Windows.Storage.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:42.0619106 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtbff93e24#\3e4a52cfe965934afd16ce06288bbcc7\System.Runtime.InteropServices.WindowsRuntime.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:42.2251119 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runt0d283adf#\c0773b528798357263b45b13e47df3a0\System.Runtime.WindowsRuntime.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:42.2262653 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{E521C894-2C26-5946-9E61-2B5E188D01ED}","NAME NOT FOUND","Desired Access: Read"
- "1:15:42.2544828 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{E521C894-2C26-5946-9E61-2B5E188D01ED}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
- "1:15:42.2864811 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{E521C894-2C26-5946-9E61-2B5E188D01ED}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:42.2871201 PM","wwahost.exe","2812","RegLoadKey","\REGISTRY\A\{52cb3144-3ce2-7974-b278-80a3452eaae2}","ACCESS DENIED","Hive Path: C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\Settings\settings.dat"
- "1:15:42.2874003 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\Settings\settings.dat","ACCESS DENIED","Desired Access: Read Data/List Directory, Write Data/Add File, Read Control, Disposition: OpenIf, Options: Sequential Access, Synchronous IO Non-Alert, No Compression, Attributes: N, ShareMode: None, AllocationSize: 0"
- "1:15:42.2875439 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\Settings\settings.dat","ACCESS DENIED","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:42.2876279 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\Settings\settings.dat","ACCESS DENIED","Desired Access: Read Data/List Directory, Write Data/Add File, Read Control, Disposition: OpenIf, Options: Sequential Access, Synchronous IO Non-Alert, No Compression, Attributes: N, ShareMode: None, AllocationSize: 0, Impersonating: xps\Chloe"
- "1:15:42.2877622 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\Settings\settings.dat","ACCESS DENIED","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: xps\Chloe"
- "1:15:42.2879617 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\Windows.Storage.ApplicationData.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:42.2881960 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\OLEAUT32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:42.2883025 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\OLEAUT32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:42.3068041 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en-US\mscorrc.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:42.3069798 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en-US\mscorrc.dll.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:42.3071422 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en-US\mscorrc.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:42.3072964 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en-US\mscorrc.dll.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:42.3074193 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en\mscorrc.dll","PATH NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:42.3075008 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en\mscorrc.dll.DLL","PATH NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:42.3075771 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en\mscorrc.dll","PATH NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:42.3076514 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en\mscorrc.dll.DLL","PATH NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:42.3502694 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:42.5655290 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
- "1:15:42.5933363 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:42.5935712 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:42.5938764 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server","NAME NOT FOUND","Desired Access: Read"
- "1:15:42.5941046 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:42.5943050 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:42.8210512 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\diasymreader.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:42.8222913 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
- "1:15:42.8224295 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:42.8225400 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:42.8226955 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server","NAME NOT FOUND","Desired Access: Read"
- "1:15:42.8228096 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:42.8229128 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:42.8234731 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.pdb","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Random Access, Disallow Exclusive, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a"
- "1:15:42.8235908 PM","wwahost.exe","2812","CreateFile","C:\windows\symbols\winmd\Platform.pdb","PATH NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Random Access, Disallow Exclusive, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a"
- "1:15:42.8236723 PM","wwahost.exe","2812","CreateFile","C:\windows\winmd\Platform.pdb","PATH NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Random Access, Disallow Exclusive, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a"
- "1:15:42.8237710 PM","wwahost.exe","2812","CreateFile","C:\Windows\Platform.pdb","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Random Access, Disallow Exclusive, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a"
- "1:15:43.0343654 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
- "1:15:43.0344903 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
- "1:15:43.0345830 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
- "1:15:43.0346425 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
- "1:15:43.0347599 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wwahost.exe","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:43.0350965 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\WINBRAND.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:43.0351955 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\WINBRAND.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:43.0353005 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\WINBRAND.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:43.0356410 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\winbrand.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:43.0360642 PM","wwahost.exe","2812","CreateFile","C:\windows\system32\Branding\Basebrd\Basebrd.dll","PATH NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:43.0363812 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Branding\Basebrd\basebrd.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:43.0365611 PM","wwahost.exe","2812","CreateFile","C:\windows\system32\Branding\Basebrd\Basebrd.dll","PATH NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:43.0368460 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Branding\Basebrd\basebrd.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:43.0370649 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Branding\Basebrd\en-US\basebrd.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:43.0373538 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Query Value"
- "1:15:43.0380502 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wwahost.exe","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:43.0381938 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\wer.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:43.0382938 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\wer.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:43.0383834 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\wer.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:43.0387466 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\wer.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:43.0393427 PM","wwahost.exe","2812","CreateFile","C:\","ACCESS DENIED","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:43.0440303 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\WaitOnStart","NAME NOT FOUND","Length: 144"
- "1:15:43.1601502 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\CTF\Compatibility\wwahost.exe","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.1713703 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\CTF\EnableAnchorContext","NAME NOT FOUND","Length: 144"
- "1:15:43.1752009 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\wer.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:43.1753648 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Windows Error Reporting","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.1754204 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData","NAME NOT FOUND","Length: 144"
- "1:15:43.1754288 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled","NAME NOT FOUND","Length: 144"
- "1:15:43.1754711 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent","NAME NOT FOUND","Length: 144"
- "1:15:43.1755124 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior","NAME NOT FOUND","Length: 144"
- "1:15:43.1755577 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\WWAJSE","NAME NOT FOUND","Length: 144"
- "1:15:43.1755728 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled","NAME NOT FOUND","Length: 144"
- "1:15:43.1755800 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI","NAME NOT FOUND","Length: 144"
- "1:15:43.1755870 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive","NAME NOT FOUND","Length: 144"
- "1:15:43.1755939 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive","NAME NOT FOUND","Length: 144"
- "1:15:43.1756012 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue","NAME NOT FOUND","Length: 144"
- "1:15:43.1756081 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount","NAME NOT FOUND","Length: 144"
- "1:15:43.1756151 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount","NAME NOT FOUND","Length: 144"
- "1:15:43.1756223 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue","NAME NOT FOUND","Length: 144"
- "1:15:43.1756289 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval","NAME NOT FOUND","Length: 144"
- "1:15:43.1756474 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ExcludedApplications","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.1756712 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DebugApplications","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.1757035 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DebugApplications","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.1757162 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles","NAME NOT FOUND","Length: 144"
- "1:15:43.1757234 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling","NAME NOT FOUND","Length: 144"
- "1:15:43.1757310 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection","NAME NOT FOUND","Length: 144"
- "1:15:43.1757947 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassPowerThrottling","NAME NOT FOUND","Length: 144"
- "1:15:43.1758016 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassNetworkCostThrottling","NAME NOT FOUND","Length: 144"
- "1:15:43.1758089 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueueNoPesterInterval","NAME NOT FOUND","Length: 144"
- "1:15:43.1758339 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Windows Error Reporting","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.1760036 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior","NAME NOT FOUND","Length: 144"
- "1:15:43.1760419 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\Windows Error Reporting\Consent\WWAJSE","NAME NOT FOUND","Length: 144"
- "1:15:43.1762472 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval","NAME NOT FOUND","Length: 144"
- "1:15:43.1762698 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\Windows Error Reporting\ExcludedApplications","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.1762991 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\Windows Error Reporting\DebugApplications","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.1763229 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\Windows Error Reporting\DebugApplications","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.1763428 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\Windows Error Reporting\SendEFSFiles","NAME NOT FOUND","Length: 144"
- "1:15:43.1763525 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling","NAME NOT FOUND","Length: 144"
- "1:15:43.1763601 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection","NAME NOT FOUND","Length: 144"
- "1:15:43.1763709 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\Windows Error Reporting\BypassPowerThrottling","NAME NOT FOUND","Length: 144"
- "1:15:43.1763794 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\Windows Error Reporting\BypassNetworkCostThrottling","NAME NOT FOUND","Length: 144"
- "1:15:43.1763872 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\Windows Error Reporting\QueueNoPesterInterval","NAME NOT FOUND","Length: 144"
- "1:15:43.1764228 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Windows Error Reporting","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.1765034 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior","NAME NOT FOUND","Length: 144"
- "1:15:43.1765424 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\WWAJSE","NAME NOT FOUND","Length: 144"
- "1:15:43.1765572 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval","NAME NOT FOUND","Length: 144"
- "1:15:43.1765662 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue","NAME NOT FOUND","Length: 144"
- "1:15:43.1765735 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount","NAME NOT FOUND","Length: 144"
- "1:15:43.1765804 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount","NAME NOT FOUND","Length: 144"
- "1:15:43.1765874 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive","NAME NOT FOUND","Length: 144"
- "1:15:43.1765940 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive","NAME NOT FOUND","Length: 144"
- "1:15:43.1766009 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue","NAME NOT FOUND","Length: 144"
- "1:15:43.1766193 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ExcludedApplications","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.1766486 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DebugApplications","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.1766731 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DebugApplications","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.1766849 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer","NAME NOT FOUND","Length: 144"
- "1:15:43.1766921 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL","NAME NOT FOUND","Length: 144"
- "1:15:43.1766990 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber","NAME NOT FOUND","Length: 144"
- "1:15:43.1767060 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication","NAME NOT FOUND","Length: 144"
- "1:15:43.1767184 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles","NAME NOT FOUND","Length: 144"
- "1:15:43.1767286 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling","NAME NOT FOUND","Length: 144"
- "1:15:43.1767362 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection","NAME NOT FOUND","Length: 144"
- "1:15:43.1767440 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassPowerThrottling","NAME NOT FOUND","Length: 144"
- "1:15:43.1767507 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassNetworkCostThrottling","NAME NOT FOUND","Length: 144"
- "1:15:43.1767576 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueueNoPesterInterval","NAME NOT FOUND","Length: 144"
- "1:15:43.1768850 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\MiniNT","REPARSE","Desired Access: Read"
- "1:15:43.1769013 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\MiniNT","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.1769508 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\MiniNT","REPARSE","Desired Access: Read"
- "1:15:43.1769650 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\MiniNT","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.2052531 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\OLEACC.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:43.2054068 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\OLEACC.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:43.2055236 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\OLEACC.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:43.2058892 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\oleacc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:43.2064651 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\OLEACCRC.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:43.2065831 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\OLEACCRC.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:43.2066915 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\OLEACCRC.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
- "1:15:43.2070567 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\oleaccrc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:43.2074386 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.2075618 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:43.2077187 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.2404678 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.2405951 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:43.2406833 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{00020424-0000-0000-C000-000000000046}","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.2407216 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{00020424-0000-0000-C000-000000000046}","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.2408122 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.2409362 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:43.2409996 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{00020424-0000-0000-C000-000000000046}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:43.2410959 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:43.2411847 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:43.2412764 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.2414059 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:43.2414301 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32\InprocServer32","NAME NOT FOUND","Length: 144"
- "1:15:43.2414923 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:43.2415874 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:43.2416861 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:43.2417938 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:43.2418361 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{00020424-0000-0000-C000-000000000046}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:43.2419022 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:43.2419544 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{00020424-0000-0000-C000-000000000046}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:43.2420809 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.2421736 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.2422152 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{00020424-0000-0000-C000-000000000046}\TreatAs","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.2426819 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\sxs.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:43.2432403 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:43.2433581 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:43.2456196 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:43.2457346 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
- "1:15:43.2677003 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\AppHost","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:43.2677800 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\AppHost\EnableWebContentEvaluation","NAME NOT FOUND","Length: 144"
- "1:15:43.2678920 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\AppHost","NAME NOT FOUND","Desired Access: Query Value"
- "1:15:43.2679518 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\AppHost\EnableWebContentEvaluation","NAME NOT FOUND","Length: 144"
- "1:15:43.2739877 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.2740587 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\PageSetup\Print_Background","NAME NOT FOUND","Length: 144"
- "1:15:43.2742054 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\MenuExt","NAME NOT FOUND","Desired Access: Read"
- "1:15:43.2742582 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Nls\CodePage","REPARSE","Desired Access: Read"
- "1:15:43.2743690 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSize","NAME NOT FOUND","Length: 144"
- "1:15:43.2743895 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSizePrivate","NAME NOT FOUND","Length: 144"
- "1:15:43.2744940 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\AcceptLanguage","NAME NOT FOUND","Length: 144"
- "1:15:43.3625805 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\Windows.Graphics.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:45.2757892 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\twinapi.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
- "1:15:45.3049461 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:45.3050276 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:45.3050853 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
- "1:15:45.3051372 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:45.3051731 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:45.3052115 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
- "1:15:45.3054222 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:45.3054708 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:45.3054979 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
- "1:15:45.3055167 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:45.3055308 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:45.3055562 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
- "1:15:45.3129952 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:45.3130846 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:45.3131133 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
- "1:15:45.3131341 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
- "1:15:45.3131498 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
- "1:15:45.3131751 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
- "1:15:45.3210416 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles","NAME NOT FOUND","Length: 20"
Advertisement
Add Comment
Please, Sign In to add comment