Guest User

Untitled

a guest
Mar 9th, 2013
996
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 448.19 KB | None | 0 0
  1. "Time of Day","Process Name","PID","Operation","Path","Result","Detail"
  2. "1:15:34.0637176 PM","rundll32.exe","9780","CreateFile","C:\Windows\Prefetch\RUNDLL32.EXE-12CD7E38.pf","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: None, AllocationSize: n/a"
  3. "1:15:34.0638634 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\UseFilter","NAME NOT FOUND","Length: 544"
  4. "1:15:34.0638733 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\DisableHeapLookaside","NAME NOT FOUND","Length: 1,024"
  5. "1:15:34.0638800 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\FrontEndHeapDebugOptions","NAME NOT FOUND","Length: 1,024"
  6. "1:15:34.0638857 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\ShutdownFlags","NAME NOT FOUND","Length: 1,024"
  7. "1:15:34.0638942 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\UnloadEventTraceDepth","NAME NOT FOUND","Length: 1,024"
  8. "1:15:34.0639026 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\TracingFlags","NAME NOT FOUND","Length: 1,024"
  9. "1:15:34.0639083 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\MinimumStackCommitInBytes","NAME NOT FOUND","Length: 1,024"
  10. "1:15:34.0639171 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\BreakOnInitializeProcessFailure","NAME NOT FOUND","Length: 1,024"
  11. "1:15:34.0639259 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\KeepActivationContextsAlive","NAME NOT FOUND","Length: 1,024"
  12. "1:15:34.0639319 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\TrackActivationContextReleases","NAME NOT FOUND","Length: 1,024"
  13. "1:15:34.0639373 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\MaxDeadActivationContexts","NAME NOT FOUND","Length: 1,024"
  14. "1:15:34.0639512 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\GlobalFlag","NAME NOT FOUND","Length: 1,024"
  15. "1:15:34.0639606 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\CWDIllegalInDLLSearch","NAME NOT FOUND","Length: 1,024"
  16. "1:15:34.0640191 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\DebugProcessHeapOnly","NAME NOT FOUND","Length: 1,024"
  17. "1:15:34.0736195 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\UseFilter","NAME NOT FOUND","Length: 544"
  18. "1:15:34.0736297 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe\SearchPathMode","NAME NOT FOUND","Length: 1,024"
  19. "1:15:34.0737055 PM","rundll32.exe","9780","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","REPARSE","Desired Access: Query Value, Set Value"
  20. "1:15:34.0737251 PM","rundll32.exe","9780","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","NAME NOT FOUND","Desired Access: Query Value, Set Value"
  21. "1:15:34.0737387 PM","rundll32.exe","9780","RegOpenKey","HKLM\System\CurrentControlSet\Control\Srp\GP\DLL","REPARSE","Desired Access: Read"
  22. "1:15:34.0737499 PM","rundll32.exe","9780","RegOpenKey","HKLM\System\CurrentControlSet\Control\Srp\GP\DLL","NAME NOT FOUND","Desired Access: Read"
  23. "1:15:34.0737749 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled","NAME NOT FOUND","Length: 80"
  24. "1:15:34.0737924 PM","rundll32.exe","9780","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","NAME NOT FOUND","Desired Access: Query Value"
  25. "1:15:34.0749193 PM","rundll32.exe","9780","CreateFileMapping","C:\Windows\System32\imm32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  26. "1:15:34.0753844 PM","rundll32.exe","9780","CreateFileMapping","C:\Windows\System32\imm32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  27. "1:15:34.0758445 PM","rundll32.exe","9780","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions","REPARSE","Desired Access: Read"
  28. "1:15:34.0759489 PM","rundll32.exe","9780","RegOpenKey","HKLM\System\CurrentControlSet\Control\Error Message Instrument\","REPARSE","Desired Access: Read"
  29. "1:15:34.0759643 PM","rundll32.exe","9780","RegOpenKey","HKLM\System\CurrentControlSet\Control\Error Message Instrument","NAME NOT FOUND","Desired Access: Read"
  30. "1:15:34.0759996 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles","NAME NOT FOUND","Length: 20"
  31. "1:15:34.0760591 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Compatibility32\rundll32","NAME NOT FOUND","Length: 172"
  32. "1:15:34.0760811 PM","rundll32.exe","9780","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\IME Compatibility","NAME NOT FOUND","Desired Access: Read"
  33. "1:15:34.0761732 PM","rundll32.exe","9780","RegOpenKey","HKCU\Control Panel\Desktop\MuiCached\MachineLanguageConfiguration","NAME NOT FOUND","Desired Access: Read"
  34. "1:15:34.0762022 PM","rundll32.exe","9780","RegOpenKey","HKLM\Software\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read"
  35. "1:15:34.0762345 PM","rundll32.exe","9780","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read"
  36. "1:15:34.0762644 PM","rundll32.exe","9780","RegEnumValue","HKCU\Control Panel\Desktop\LanguageConfiguration","NO MORE ENTRIES","Index: 0, Length: 512"
  37. "1:15:34.0762985 PM","rundll32.exe","9780","RegOpenKey","HKLM\Software\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read"
  38. "1:15:34.0763299 PM","rundll32.exe","9780","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read"
  39. "1:15:34.0763576 PM","rundll32.exe","9780","RegQueryValue","HKCU\Control Panel\Desktop\PreferredUILanguages","NAME NOT FOUND","Length: 12"
  40. "1:15:34.0763896 PM","rundll32.exe","9780","RegOpenKey","HKLM\Software\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read"
  41. "1:15:34.0764343 PM","rundll32.exe","9780","RegQueryValue","HKCU\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages","BUFFER OVERFLOW","Length: 12"
  42. "1:15:34.0766423 PM","rundll32.exe","9780","CreateFileMapping","C:\Windows\System32\en-US\rundll32.exe.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  43. "1:15:34.0772581 PM","rundll32.exe","9780","CreateFile","C:\Windows\System32\shell32.dll.manifest","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  44. "1:15:34.0774262 PM","rundll32.exe","9780","CreateFileMapping","C:\Windows\System32\shell32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  45. "1:15:34.0775077 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest","NAME NOT FOUND","Length: 20"
  46. "1:15:34.0775771 PM","rundll32.exe","9780","CreateFile","C:\Windows\System32\shell32.dll.123.Manifest","NAME NOT FOUND","Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a"
  47. "1:15:34.0777752 PM","rundll32.exe","9780","CreateFileMapping","C:\Windows\System32\shell32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  48. "1:15:34.0778775 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest","NAME NOT FOUND","Length: 20"
  49. "1:15:34.0784604 PM","rundll32.exe","9780","CreateFileMapping","C:\Windows\System32\combase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  50. "1:15:34.0790110 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\PageAllocatorUseSystemHeap","NAME NOT FOUND","Length: 144"
  51. "1:15:34.0790605 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\PageAllocatorSystemHeapIsPrivate","NAME NOT FOUND","Length: 144"
  52. "1:15:34.0791043 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\AggressiveMTATesting","NAME NOT FOUND","Length: 144"
  53. "1:15:34.0791519 PM","rundll32.exe","9780","RegOpenKey","HKLM\Software\Microsoft\OLE\Tracing","NAME NOT FOUND","Desired Access: Read"
  54. "1:15:34.0798906 PM","rundll32.exe","9780","CreateFileMapping","C:\Windows\System32\uxtheme.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  55. "1:15:34.0801611 PM","rundll32.exe","9780","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  56. "1:15:34.0802226 PM","rundll32.exe","9780","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  57. "1:15:34.0802622 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
  58. "1:15:34.0802918 PM","rundll32.exe","9780","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  59. "1:15:34.0803117 PM","rundll32.exe","9780","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  60. "1:15:34.0803425 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
  61. "1:15:34.0803763 PM","rundll32.exe","9780","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Appcompat\","NAME NOT FOUND","Desired Access: Query Value"
  62. "1:15:34.0830046 PM","rundll32.exe","9780","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\DirectManipulation","NAME NOT FOUND","Desired Access: Query Value"
  63. "1:15:34.0831588 PM","rundll32.exe","9780","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","REPARSE","Desired Access: Read"
  64. "1:15:34.0832041 PM","rundll32.exe","9780","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\en-US","NAME NOT FOUND","Length: 532"
  65. "1:15:34.0832304 PM","rundll32.exe","9780","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","REPARSE","Desired Access: Read"
  66. "1:15:34.0832627 PM","rundll32.exe","9780","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale\en-US","NAME NOT FOUND","Length: 532"
  67. "1:15:34.0841350 PM","rundll32.exe","9780","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value"
  68. "1:15:34.0841782 PM","rundll32.exe","9780","RegQueryValue","HKLM\System\CurrentControlSet\Control\SESSION MANAGER\SafeDllSearchMode","NAME NOT FOUND","Length: 16"
  69. "1:15:34.0845154 PM","rundll32.exe","9780","CreateFileMapping","C:\Windows\System32\dwmapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  70. "1:15:34.0851408 PM","rundll32.exe","9780","CreateFileMapping","C:\Windows\System32\SHCore.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  71. "1:15:34.0891900 PM","rundll32.exe","9780","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles","NAME NOT FOUND","Length: 20"
  72. "1:15:34.6501867 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  73. "1:15:34.6503802 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  74. "1:15:34.6601756 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  75. "1:15:34.6605417 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\common","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  76. "1:15:34.6776958 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\common\css","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  77. "1:15:34.6783312 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\css","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  78. "1:15:34.6787749 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\css\und-latn","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  79. "1:15:34.6791408 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\images","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  80. "1:15:34.6901922 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\microsoft.system.package.metadata","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  81. "1:15:34.6906338 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\nytshared","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  82. "1:15:34.6912408 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\wsjshared","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  83. "1:15:34.6949824 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  84. "1:15:34.6955822 PM","wwahost.exe","2812","FileSystemControl","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\microsoft.system.package.metadata","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  85. "1:15:34.7284151 PM","wwahost.exe","2812","FileSystemControl","C:\Users","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  86. "1:15:34.7285887 PM","wwahost.exe","2812","FileSystemControl","C:\Users\Chloe","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  87. "1:15:34.7289080 PM","wwahost.exe","2812","FileSystemControl","C:\Users\Chloe\AppData\Local","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  88. "1:15:34.7290883 PM","wwahost.exe","2812","FileSystemControl","C:\Users\Chloe\AppData\Local\Packages","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  89. "1:15:34.7292651 PM","wwahost.exe","2812","FileSystemControl","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  90. "1:15:34.7294478 PM","wwahost.exe","2812","FileSystemControl","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\AC","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  91. "1:15:34.7297988 PM","wwahost.exe","2812","FileSystemControl","C:\Windows","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  92. "1:15:34.7299709 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\apppatch","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  93. "1:15:34.7301375 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\apppatch\apppatch64","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  94. "1:15:34.7303087 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\assembly","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  95. "1:15:34.7304783 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\assembly\NativeImages_v4.0.30319_64","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  96. "1:15:34.7437970 PM","wwahost.exe","2812","CreateFile","C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\36BDCA19B5E894E99F1723ACD37EF442","NAME NOT FOUND","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Complete If Oplocked, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  97. "1:15:34.7453929 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Diagd2d95910#\664c4b72d162ef6bf0961ab8f6466e57","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  98. "1:15:34.7663712 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.caf7096d#\6893cdef3f45a5a82453d1a2a613eb7e","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  99. "1:15:34.7893092 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runt0d283adf#\c0773b528798357263b45b13e47df3a0","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  100. "1:15:34.8018409 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runt1e58aa76#\ed7dab94f316db1c7076b5dcece5e0ba","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  101. "1:15:34.8078186 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtbff93e24#\3e4a52cfe965934afd16ce06288bbcc7","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  102. "1:15:34.8153817 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Thre7bb2aad0#\212e032faa8c80bc75ee5ed64f2bf8c8","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  103. "1:15:34.8252827 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.App640a3541#\52610b15de6cf7f4ddd8b93f543abe24","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  104. "1:15:34.8332708 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Gloaae92e31#\678926c3ae1779d1515a93d5afbc45f4","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  105. "1:15:34.8416507 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\Microsoft.NET","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  106. "1:15:34.8419985 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\Microsoft.NET\assembly\GAC_64","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  107. "1:15:34.8425989 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  108. "1:15:34.8430372 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\Microsoft.NET\assembly\GAC_MSIL","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  109. "1:15:34.8453902 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\Microsoft.NET\Framework64","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  110. "1:15:34.8455671 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\Microsoft.NET\Framework64\v4.0.30319","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  111. "1:15:34.8460748 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Config","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  112. "1:15:34.8465831 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\ServiceProfiles\LocalService","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  113. "1:15:34.8469106 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\ServiceProfiles\LocalService\AppData\Local","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  114. "1:15:34.8470661 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\System32","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  115. "1:15:34.8472388 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\System32\en-US","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  116. "1:15:34.8474072 PM","wwahost.exe","2812","FileSystemControl","C:\Windows\System32\WinMetadata","END OF FILE","Control: FSCTL_FILE_PREFETCH"
  117. "1:15:34.8693687 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\ntdll.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  118. "1:15:34.8695441 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WWAHost.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  119. "1:15:34.8697110 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\kernel32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  120. "1:15:34.8698716 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\KernelBase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  121. "1:15:34.8700364 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\locale.nls","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  122. "1:15:34.8702305 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-1327121770-2262649544-634666869-1001.pckgdep","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  123. "1:15:34.8703926 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\apphelp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  124. "1:15:34.8705592 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\apppatch\apppatch64\sysmain.sdb","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  125. "1:15:34.8707415 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\combase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  126. "1:15:34.8709042 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinTypes.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  127. "1:15:34.8710672 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\SHCore.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  128. "1:15:34.8712281 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\BCP47Langs.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  129. "1:15:34.8713902 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\iertutil.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  130. "1:15:34.8715765 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\mshtml.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  131. "1:15:34.8717591 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\urlmon.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  132. "1:15:34.8719212 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\twinapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  133. "1:15:34.8720815 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\profapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  134. "1:15:34.8722406 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dwmapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  135. "1:15:34.8724042 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\ole32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  136. "1:15:34.8725811 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\oleaut32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  137. "1:15:34.8727543 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rometadata.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  138. "1:15:34.8729267 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\uxtheme.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  139. "1:15:34.8730970 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dui70.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  140. "1:15:34.8733569 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\user32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  141. "1:15:34.8735383 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\gdi32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  142. "1:15:34.8736898 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\msvcrt.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  143. "1:15:34.8738428 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rpcrt4.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  144. "1:15:34.8739956 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\sechost.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  145. "1:15:34.8741516 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\shlwapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  146. "1:15:34.8743056 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\wininet.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  147. "1:15:34.8744586 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\imm32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  148. "1:15:34.8746295 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\msctf.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  149. "1:15:34.8748106 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\cryptbase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  150. "1:15:34.8749694 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\bcryptprimitives.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  151. "1:15:34.8751538 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\advapi32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  152. "1:15:34.8753304 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rpcss.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  153. "1:15:34.8755124 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\MrmCoreR.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  154. "1:15:34.8756887 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\d2d1.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  155. "1:15:34.8758460 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Globalization\Sorting\SortDefault.nls","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  156. "1:15:34.8760461 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\resources.pri","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  157. "1:15:34.8762505 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\resources.pri","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  158. "1:15:34.8764298 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\DWrite.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  159. "1:15:34.8766091 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\AppEx.Common.NewsBdiTransformer.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  160. "1:15:34.8767857 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  161. "1:15:34.8769454 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\d3d11.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  162. "1:15:34.8771023 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\aticfx64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  163. "1:15:34.8772527 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\atiuxp64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  164. "1:15:34.8775741 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\version.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  165. "1:15:34.8778392 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\atidxx64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  166. "1:15:34.8780426 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Microsoft.Media.AdaptiveStreaming.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  167. "1:15:34.8782542 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\MicrosoftAdvertising.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  168. "1:15:34.8784435 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\News.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  169. "1:15:34.8786349 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\NYT.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  170. "1:15:34.8788350 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  171. "1:15:34.8790176 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\cryptsp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  172. "1:15:34.8791827 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rsaenh.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  173. "1:15:34.8793672 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\actxprxy.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  174. "1:15:34.8795320 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.UI.Immersive.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  175. "1:15:34.8796917 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.UI.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  176. "1:15:34.8798746 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\ninput.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  177. "1:15:34.8800572 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\comctl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  178. "1:15:34.8802975 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\secur32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  179. "1:15:34.8804759 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\sspicli.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  180. "1:15:34.8806380 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\msimtf.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  181. "1:15:34.8808164 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\powrprof.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  182. "1:15:34.8809740 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dcomp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  183. "1:15:34.8811349 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WwaApi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  184. "1:15:34.8813127 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\tzres.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  185. "1:15:34.8814726 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\tzres.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  186. "1:15:34.8816529 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\shell32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  187. "1:15:34.8818361 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\Autogen\JSByteCodeCache_64","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  188. "1:15:34.8820287 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\default.html","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  189. "1:15:34.8822367 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\microsoft.system.package.metadata\Autogen\JSByteCodeCache_64","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  190. "1:15:34.8824304 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\css\ui-light.css","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  191. "1:15:34.8826251 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\common\css\und-latn\immersive.css","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  192. "1:15:34.8828192 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\common\css\und-latn\common.css","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  193. "1:15:34.8830607 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\css\und-latn\default.css","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  194. "1:15:34.8833140 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\css\und-latn\partners.css","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  195. "1:15:34.8835005 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\css\und-latn\apNewsTheme.css","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  196. "1:15:34.8837013 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\nytshared\und-latn\nytTheme.css","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  197. "1:15:34.8838942 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\wsjshared\und-latn\wsjTheme.css","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  198. "1:15:34.8841260 PM","wwahost.exe","2812","CreateFileMapping","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\AC\INetCache\MSIMGSIZ.DAT","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  199. "1:15:34.8843225 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WindowsCodecs.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  200. "1:15:34.8845054 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\images\splash.scale-100.png","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  201. "1:15:34.8846742 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\jscript9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  202. "1:15:34.8848668 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Foundation.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  203. "1:15:34.8850651 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\clrhost.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  204. "1:15:34.8852489 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\mscoree.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  205. "1:15:34.8854418 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  206. "1:15:34.8856299 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  207. "1:15:34.8858119 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\msvcr110_clr0400.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  208. "1:15:34.8859942 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.ApplicationModel.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  209. "1:15:34.8861777 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  210. "1:15:34.8862544 PM","wwahost.exe","2812","CreateFile","C:\WINDOWS\ASSEMBLY\NATIVEIMAGES_V4.0.30319_64\MSCORLIB\36BDCA19B5E894E99F1723ACD37EF442\MSCORLIB.NI.DLL.AUX","PATH NOT FOUND","Desired Access: Read Data/List Directory, Execute/Traverse, Read Attributes, Disposition: Open, Options: Non-Directory File, Complete If Oplocked, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  211. "1:15:34.8864328 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  212. "1:15:34.8866393 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\5a23c5e185cb978f73c67718f6e061a4\mscorlib.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  213. "1:15:34.8868219 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\5a23c5e185cb978f73c67718f6e061a4\mscorlib.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  214. "1:15:34.8870226 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime\92dbe33346751ef372e3590eb71b1cac\System.Runtime.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  215. "1:15:34.8872149 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime\92dbe33346751ef372e3590eb71b1cac\System.Runtime.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  216. "1:15:34.8874078 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Networking.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  217. "1:15:34.8876040 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\WWAHost_AppExNews.profile","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  218. "1:15:34.8878470 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtbff93e24#\3e4a52cfe965934afd16ce06288bbcc7\System.Runtime.InteropServices.WindowsRuntime.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  219. "1:15:34.8880474 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtbff93e24#\3e4a52cfe965934afd16ce06288bbcc7\System.Runtime.InteropServices.WindowsRuntime.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  220. "1:15:34.8882355 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  221. "1:15:34.8884266 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\bcrypt.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  222. "1:15:34.8886041 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Collections\29ced27766a0483b74ea5e43df52a217\System.Collections.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  223. "1:15:34.8888377 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Collections\29ced27766a0483b74ea5e43df52a217\System.Collections.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  224. "1:15:34.8890898 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.App640a3541#\52610b15de6cf7f4ddd8b93f543abe24\Windows.ApplicationModel.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  225. "1:15:34.8894710 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.App640a3541#\52610b15de6cf7f4ddd8b93f543abe24\Windows.ApplicationModel.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  226. "1:15:34.8898556 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Foundation\87788b39516ef9bf7e5c60a2b5fb3aeb\Windows.Foundation.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  227. "1:15:34.8900491 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Foundation\87788b39516ef9bf7e5c60a2b5fb3aeb\Windows.Foundation.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  228. "1:15:34.8902347 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Storage.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  229. "1:15:34.8904183 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.Storage.ApplicationData.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  230. "1:15:34.8905776 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.UI.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  231. "1:15:34.8907551 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Media.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  232. "1:15:34.8909450 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Globalization.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  233. "1:15:34.8911249 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\propsys.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  234. "1:15:34.8912897 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\shell32.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  235. "1:15:34.8914681 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.ApplicationModel.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  236. "1:15:34.8916468 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Graphics.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  237. "1:15:34.8918270 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.Graphics.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  238. "1:15:34.8920676 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Gloaae92e31#\678926c3ae1779d1515a93d5afbc45f4\Windows.Globalization.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  239. "1:15:34.8922659 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Gloaae92e31#\678926c3ae1779d1515a93d5afbc45f4\Windows.Globalization.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  240. "1:15:34.8924615 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Linq\edff7029ad67ee17c87b4f3f69df5c93\System.Linq.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  241. "1:15:34.8926553 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Linq\edff7029ad67ee17c87b4f3f69df5c93\System.Linq.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  242. "1:15:34.8928534 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\3145945493fbcef888aa44b0081134cc\System.Core.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  243. "1:15:34.8930456 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System\67f7ddcb264bac2f465b439bb19616b1\System.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  244. "1:15:34.8932283 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System\67f7ddcb264bac2f465b439bb19616b1\System.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  245. "1:15:34.8934109 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\3145945493fbcef888aa44b0081134cc\System.Core.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  246. "1:15:34.8936053 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.System\4022b99b813a11eb3afa84dd8fd0eee6\Windows.System.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  247. "1:15:34.8938371 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Diagd2d95910#\664c4b72d162ef6bf0961ab8f6466e57\System.Diagnostics.Tracing.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  248. "1:15:34.8940369 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Diagd2d95910#\664c4b72d162ef6bf0961ab8f6466e57\System.Diagnostics.Tracing.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  249. "1:15:34.8942335 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.System\4022b99b813a11eb3afa84dd8fd0eee6\Windows.System.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  250. "1:15:34.8944303 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.Globalization.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  251. "1:15:34.8945987 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Threading\b715c79b7d168a31bc4086b6a3e1201f\System.Threading.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  252. "1:15:34.8947801 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Threading\b715c79b7d168a31bc4086b6a3e1201f\System.Threading.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  253. "1:15:34.8950029 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Thre7bb2aad0#\212e032faa8c80bc75ee5ed64f2bf8c8\System.Threading.Tasks.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  254. "1:15:34.8951894 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Thre7bb2aad0#\212e032faa8c80bc75ee5ed64f2bf8c8\System.Threading.Tasks.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  255. "1:15:34.8953784 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.Requests\e19ae87ac64e07ecb0e1d216e7c042fa\System.Net.Requests.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  256. "1:15:34.8955843 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.Requests\e19ae87ac64e07ecb0e1d216e7c042fa\System.Net.Requests.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  257. "1:15:34.8958807 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.caf7096d#\6893cdef3f45a5a82453d1a2a613eb7e\System.Net.Primitives.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  258. "1:15:34.8960917 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.caf7096d#\6893cdef3f45a5a82453d1a2a613eb7e\System.Net.Primitives.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  259. "1:15:34.8962846 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\8517b132cbe0b329b40bc6a9ef106828\System.Configuration.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  260. "1:15:34.8964636 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\8517b132cbe0b329b40bc6a9ef106828\System.Configuration.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  261. "1:15:34.8966921 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml\4334f45efbe62a6415f2cb7393c59f74\System.Xml.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  262. "1:15:34.8968850 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml\4334f45efbe62a6415f2cb7393c59f74\System.Xml.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  263. "1:15:34.8971277 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  264. "1:15:34.8973067 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rasapi32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  265. "1:15:34.8974679 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rasman.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  266. "1:15:34.8976273 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\ws2_32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  267. "1:15:34.8978066 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\nsi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  268. "1:15:34.8979647 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\mswsock.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  269. "1:15:34.8981238 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\winhttp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  270. "1:15:34.8982808 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\IPHLPAPI.DLL","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  271. "1:15:34.8984359 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\winnsi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  272. "1:15:34.8985890 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dhcpcsvc6.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  273. "1:15:34.8987668 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dhcpcsvc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  274. "1:15:34.8989736 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Collections.Concurrent\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Collections.Concurrent.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  275. "1:15:34.8991643 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.Http\69640072694356ffed3bbe2d2352f935\System.Net.Http.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  276. "1:15:34.8993524 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.Http\69640072694356ffed3bbe2d2352f935\System.Net.Http.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  277. "1:15:34.8995890 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runt0d283adf#\c0773b528798357263b45b13e47df3a0\System.Runtime.WindowsRuntime.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  278. "1:15:34.8997843 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runt0d283adf#\c0773b528798357263b45b13e47df3a0\System.Runtime.WindowsRuntime.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  279. "1:15:34.9000098 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runt1e58aa76#\ed7dab94f316db1c7076b5dcece5e0ba\System.Runtime.Extensions.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  280. "1:15:34.9218307 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\Windows.Storage.ApplicationData.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  281. "1:15:34.9220504 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runt1e58aa76#\ed7dab94f316db1c7076b5dcece5e0ba\System.Runtime.Extensions.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  282. "1:15:34.9222511 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.UI\3d103d35427b58930da5043a06ff14e0\Windows.UI.ni.dll.aux","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  283. "1:15:34.9224437 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  284. "1:15:34.9226710 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.UI\3d103d35427b58930da5043a06ff14e0\Windows.UI.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  285. "1:15:34.9228739 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\diasymreader.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  286. "1:15:34.9621120 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\ServiceProfiles\LocalService\AppData\Local\~FontCache-System.dat","FILE LOCKED WITH WRITERS","SyncType: SyncTypeCreateSection, PageProtection: "
  287. "1:15:34.9623960 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IO\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  288. "1:15:34.9625953 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\winbrand.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  289. "1:15:34.9627863 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Text.Encoding\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Text.Encoding.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  290. "1:15:34.9629735 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\oleacc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  291. "1:15:34.9631619 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Branding\Basebrd\basebrd.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  292. "1:15:34.9633644 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\oleaccrc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  293. "1:15:34.9635416 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Branding\Basebrd\en-US\basebrd.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  294. "1:15:34.9637930 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Globalization\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Globalization.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  295. "1:15:34.9640019 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\sxs.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  296. "1:15:34.9641598 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\wer.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  297. "1:15:34.9643786 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\Windows.Graphics.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  298. "1:15:34.9645676 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Security.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  299. "1:15:34.9647490 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Devices.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  300. "1:15:34.9649217 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\atipblag.dat","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  301. "1:15:35.3312453 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\ntdll.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  302. "1:15:35.3313570 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WWAHost.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  303. "1:15:35.3314521 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\kernel32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  304. "1:15:35.3315445 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\KernelBase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  305. "1:15:35.3316375 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\apphelp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  306. "1:15:35.3317289 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\combase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  307. "1:15:35.3318210 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinTypes.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  308. "1:15:35.3319125 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\SHCore.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  309. "1:15:35.3320027 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\BCP47Langs.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  310. "1:15:35.3320933 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\iertutil.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  311. "1:15:35.3321859 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\mshtml.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  312. "1:15:35.3322859 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\urlmon.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  313. "1:15:35.3323773 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\twinapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  314. "1:15:35.3324685 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\profapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  315. "1:15:35.3325584 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dwmapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  316. "1:15:35.3326496 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\ole32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  317. "1:15:35.3327411 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\oleaut32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  318. "1:15:35.3328307 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rometadata.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  319. "1:15:35.3329768 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\uxtheme.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  320. "1:15:35.3330686 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dui70.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  321. "1:15:35.3331597 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\user32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  322. "1:15:35.3332509 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\gdi32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  323. "1:15:35.3333421 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\msvcrt.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  324. "1:15:35.3334335 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rpcrt4.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  325. "1:15:35.3335238 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\sechost.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  326. "1:15:35.3336149 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\shlwapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  327. "1:15:35.3337055 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\wininet.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  328. "1:15:35.3337958 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\imm32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  329. "1:15:35.3338860 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\msctf.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  330. "1:15:35.3339760 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\cryptbase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  331. "1:15:35.3340662 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\bcryptprimitives.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  332. "1:15:35.3341565 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\advapi32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  333. "1:15:35.3342467 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\MrmCoreR.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  334. "1:15:35.3343373 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\d2d1.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  335. "1:15:35.3344297 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\DWrite.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  336. "1:15:35.3345199 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\AppEx.Common.NewsBdiTransformer.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  337. "1:15:35.3637867 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  338. "1:15:35.3638323 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\d3d11.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  339. "1:15:35.3638721 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\aticfx64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  340. "1:15:35.3639105 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\atiuxp64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  341. "1:15:35.3639485 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\version.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  342. "1:15:35.3639877 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\atidxx64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  343. "1:15:35.3640273 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Microsoft.Media.AdaptiveStreaming.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  344. "1:15:35.3645504 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\MicrosoftAdvertising.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  345. "1:15:35.3884480 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\News.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  346. "1:15:35.3887810 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\NYT.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  347. "1:15:35.4114536 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  348. "1:15:35.4299480 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\cryptsp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  349. "1:15:35.4299932 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rsaenh.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  350. "1:15:35.4300334 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\actxprxy.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  351. "1:15:35.4300732 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.UI.Immersive.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  352. "1:15:35.4301134 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.UI.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  353. "1:15:35.4302015 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\ninput.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  354. "1:15:35.4302571 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\comctl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  355. "1:15:35.4302954 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\secur32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  356. "1:15:35.4303334 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\sspicli.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  357. "1:15:35.4303926 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\msimtf.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  358. "1:15:35.4304312 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\powrprof.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  359. "1:15:35.4304696 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dcomp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  360. "1:15:35.4305070 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WwaApi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  361. "1:15:35.4305592 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\tzres.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  362. "1:15:35.4305997 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\shell32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  363. "1:15:35.4306392 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WindowsCodecs.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  364. "1:15:35.4306785 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\jscript9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  365. "1:15:35.4307201 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Foundation.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  366. "1:15:35.4307581 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\clrhost.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  367. "1:15:35.4308514 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\mscoree.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  368. "1:15:35.4308907 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  369. "1:15:35.4309320 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  370. "1:15:35.4309930 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\msvcr110_clr0400.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  371. "1:15:35.4310522 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.ApplicationModel.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  372. "1:15:35.4310920 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  373. "1:15:35.4311337 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\5a23c5e185cb978f73c67718f6e061a4\mscorlib.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  374. "1:15:35.4311747 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime\92dbe33346751ef372e3590eb71b1cac\System.Runtime.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  375. "1:15:35.4314892 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Networking.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  376. "1:15:35.4318174 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtbff93e24#\3e4a52cfe965934afd16ce06288bbcc7\System.Runtime.InteropServices.WindowsRuntime.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  377. "1:15:35.4321168 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  378. "1:15:35.4321630 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\bcrypt.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  379. "1:15:35.4322022 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Collections\29ced27766a0483b74ea5e43df52a217\System.Collections.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  380. "1:15:35.4324685 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.App640a3541#\52610b15de6cf7f4ddd8b93f543abe24\Windows.ApplicationModel.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  381. "1:15:35.4578663 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Foundation\87788b39516ef9bf7e5c60a2b5fb3aeb\Windows.Foundation.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  382. "1:15:35.4582545 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Storage.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  383. "1:15:35.4583043 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.Storage.ApplicationData.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  384. "1:15:35.4583448 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.UI.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  385. "1:15:35.4583846 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Media.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  386. "1:15:35.4584245 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Globalization.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  387. "1:15:35.4586859 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\propsys.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  388. "1:15:35.4587321 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.ApplicationModel.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  389. "1:15:35.4587722 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Graphics.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  390. "1:15:35.4588124 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.Graphics.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  391. "1:15:35.4588788 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Gloaae92e31#\678926c3ae1779d1515a93d5afbc45f4\Windows.Globalization.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  392. "1:15:35.4592558 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Linq\edff7029ad67ee17c87b4f3f69df5c93\System.Linq.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  393. "1:15:35.4595118 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System\67f7ddcb264bac2f465b439bb19616b1\System.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  394. "1:15:35.4595576 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\3145945493fbcef888aa44b0081134cc\System.Core.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  395. "1:15:35.4810485 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Diagd2d95910#\664c4b72d162ef6bf0961ab8f6466e57\System.Diagnostics.Tracing.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  396. "1:15:35.4813785 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.System\4022b99b813a11eb3afa84dd8fd0eee6\Windows.System.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  397. "1:15:35.4818113 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.Globalization.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  398. "1:15:35.4818566 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Threading\b715c79b7d168a31bc4086b6a3e1201f\System.Threading.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  399. "1:15:35.4821539 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Thre7bb2aad0#\212e032faa8c80bc75ee5ed64f2bf8c8\System.Threading.Tasks.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  400. "1:15:35.4824117 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.Requests\e19ae87ac64e07ecb0e1d216e7c042fa\System.Net.Requests.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  401. "1:15:35.4826858 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.caf7096d#\6893cdef3f45a5a82453d1a2a613eb7e\System.Net.Primitives.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  402. "1:15:35.4829566 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\8517b132cbe0b329b40bc6a9ef106828\System.Configuration.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  403. "1:15:35.4908236 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml\4334f45efbe62a6415f2cb7393c59f74\System.Xml.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  404. "1:15:35.4908707 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rasapi32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  405. "1:15:35.4909103 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rasman.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  406. "1:15:35.4909492 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\ws2_32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  407. "1:15:35.4909876 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\nsi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  408. "1:15:35.4910265 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\mswsock.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  409. "1:15:35.4910654 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\winhttp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  410. "1:15:35.4911053 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\IPHLPAPI.DLL","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  411. "1:15:35.4911807 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\winnsi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  412. "1:15:35.4912200 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dhcpcsvc6.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  413. "1:15:35.4912773 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dhcpcsvc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  414. "1:15:35.4913353 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Collections.Concurrent\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Collections.Concurrent.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  415. "1:15:35.4919203 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.Http\69640072694356ffed3bbe2d2352f935\System.Net.Http.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  416. "1:15:35.4924492 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runt0d283adf#\c0773b528798357263b45b13e47df3a0\System.Runtime.WindowsRuntime.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  417. "1:15:35.5031561 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runt1e58aa76#\ed7dab94f316db1c7076b5dcece5e0ba\System.Runtime.Extensions.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  418. "1:15:35.5034338 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.UI\3d103d35427b58930da5043a06ff14e0\Windows.UI.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  419. "1:15:35.5230227 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\diasymreader.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  420. "1:15:35.5233031 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IO\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.IO.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  421. "1:15:35.5235452 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\winbrand.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  422. "1:15:35.5235908 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Text.Encoding\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Text.Encoding.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  423. "1:15:35.5236810 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\oleacc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  424. "1:15:35.5237221 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Globalization\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Globalization.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  425. "1:15:35.5239748 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\sxs.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  426. "1:15:35.5240206 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\wer.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  427. "1:15:35.5240602 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Security.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  428. "1:15:35.5243699 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Devices.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  429. "1:15:36.6722883 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","REPARSE","Desired Access: Query Value, Set Value"
  430. "1:15:36.6723508 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","NAME NOT FOUND","Desired Access: Query Value, Set Value"
  431. "1:15:36.6723882 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Srp\GP\DLL","REPARSE","Desired Access: Read"
  432. "1:15:36.6724172 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Srp\GP\DLL","NAME NOT FOUND","Desired Access: Read"
  433. "1:15:36.6724806 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled","NAME NOT FOUND","Length: 80"
  434. "1:15:36.6725276 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","NAME NOT FOUND","Desired Access: Query Value"
  435. "1:15:36.6732844 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\apphelp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  436. "1:15:36.6738649 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\DbgLog","NAME NOT FOUND","Desired Access: Query Value"
  437. "1:15:36.6739210 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\DbgLog","NAME NOT FOUND","Desired Access: Query Value"
  438. "1:15:36.6740454 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\ShowDebugInfo","NAME NOT FOUND","Length: 256"
  439. "1:15:36.6743711 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\WWAHost.exe","BUFFER OVERFLOW","Information: Owner"
  440. "1:15:36.6747219 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\ntdll.dll","BUFFER OVERFLOW","Information: Owner"
  441. "1:15:36.6750651 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\kernel32.dll","BUFFER OVERFLOW","Information: Owner"
  442. "1:15:36.6753838 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\KernelBase.dll","BUFFER OVERFLOW","Information: Owner"
  443. "1:15:36.6758686 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\apppatch\apppatch64\sysmain.sdb","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  444. "1:15:36.6762550 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","REPARSE","Desired Access: Read"
  445. "1:15:36.6763564 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\PackageRootFolder","BUFFER OVERFLOW","Length: 144"
  446. "1:15:36.6767205 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-1327121770-2262649544-634666869-1001.pckgdep","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  447. "1:15:36.6769849 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","REPARSE","Desired Access: Read"
  448. "1:15:36.6770848 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\PackageRootFolder","BUFFER OVERFLOW","Length: 144"
  449. "1:15:36.6774317 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-1327121770-2262649544-634666869-1001.pckgdep","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  450. "1:15:36.6777293 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","REPARSE","Desired Access: Read"
  451. "1:15:36.6795241 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\combase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  452. "1:15:36.6806154 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinTypes.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  453. "1:15:36.6816909 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\SHCore.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  454. "1:15:36.6823719 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Bcp47Langs.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  455. "1:15:36.7149066 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Bcp47Langs.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  456. "1:15:36.7150467 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Bcp47Langs.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  457. "1:15:36.7154659 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\BCP47Langs.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  458. "1:15:36.7161047 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\MSHTML.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  459. "1:15:36.7162342 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\MSHTML.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  460. "1:15:36.7163489 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\MSHTML.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  461. "1:15:37.0990285 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\mshtml.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  462. "1:15:37.0994789 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\TWINAPI.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  463. "1:15:37.0995727 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\TWINAPI.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  464. "1:15:37.0996567 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\TWINAPI.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  465. "1:15:37.0999449 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\twinapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  466. "1:15:37.1002737 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\profapi.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  467. "1:15:37.1003730 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\profapi.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  468. "1:15:37.1004584 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\profapi.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  469. "1:15:37.1007865 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\profapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  470. "1:15:37.1010842 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\dwmapi.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  471. "1:15:37.1011717 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\dwmapi.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  472. "1:15:37.1012535 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\dwmapi.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  473. "1:15:37.1015529 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dwmapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  474. "1:15:37.1020631 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\RoMetadata.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  475. "1:15:37.1021497 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\RoMetadata.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  476. "1:15:37.1022321 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\RoMetadata.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  477. "1:15:37.1595887 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rometadata.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  478. "1:15:37.1599395 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\UxTheme.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  479. "1:15:37.1600358 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\UxTheme.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  480. "1:15:37.1601276 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\UxTheme.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  481. "1:15:37.1604258 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\uxtheme.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  482. "1:15:37.1606495 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DUI70.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  483. "1:15:37.1607331 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\DUI70.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  484. "1:15:37.1608249 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\DUI70.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  485. "1:15:37.1611092 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dui70.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  486. "1:15:37.1618071 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\sechost.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  487. "1:15:37.1630224 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\msvcrt.dll","BUFFER OVERFLOW","Information: Owner"
  488. "1:15:37.1631863 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\rpcrt4.dll","BUFFER OVERFLOW","Information: Owner"
  489. "1:15:37.1633433 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\combase.dll","BUFFER OVERFLOW","Information: Owner"
  490. "1:15:37.1635017 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\WinTypes.dll","BUFFER OVERFLOW","Information: Owner"
  491. "1:15:37.1636524 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\SHCore.dll","BUFFER OVERFLOW","Information: Owner"
  492. "1:15:37.1637976 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\sechost.dll","BUFFER OVERFLOW","Information: Owner"
  493. "1:15:37.1639503 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\BCP47Langs.dll","BUFFER OVERFLOW","Information: Owner"
  494. "1:15:37.1641100 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\iertutil.dll","BUFFER OVERFLOW","Information: Owner"
  495. "1:15:37.1642558 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\user32.dll","BUFFER OVERFLOW","Information: Owner"
  496. "1:15:37.1644094 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\gdi32.dll","BUFFER OVERFLOW","Information: Owner"
  497. "1:15:37.1645583 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\mshtml.dll","BUFFER OVERFLOW","Information: Owner"
  498. "1:15:37.1647086 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\ole32.dll","BUFFER OVERFLOW","Information: Owner"
  499. "1:15:37.1648577 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\shlwapi.dll","BUFFER OVERFLOW","Information: Owner"
  500. "1:15:37.1650053 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\wininet.dll","BUFFER OVERFLOW","Information: Owner"
  501. "1:15:37.1651556 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\urlmon.dll","BUFFER OVERFLOW","Information: Owner"
  502. "1:15:37.1652978 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\twinapi.dll","BUFFER OVERFLOW","Information: Owner"
  503. "1:15:37.1654457 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\profapi.dll","BUFFER OVERFLOW","Information: Owner"
  504. "1:15:37.1655942 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\dwmapi.dll","BUFFER OVERFLOW","Information: Owner"
  505. "1:15:37.1657361 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\oleaut32.dll","BUFFER OVERFLOW","Information: Owner"
  506. "1:15:37.1658831 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\rometadata.dll","BUFFER OVERFLOW","Information: Owner"
  507. "1:15:37.1660280 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\uxtheme.dll","BUFFER OVERFLOW","Information: Owner"
  508. "1:15:37.1661714 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\dui70.dll","BUFFER OVERFLOW","Information: Owner"
  509. "1:15:37.1663199 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions","REPARSE","Desired Access: Read"
  510. "1:15:37.1664838 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\PageAllocatorUseSystemHeap","NAME NOT FOUND","Length: 144"
  511. "1:15:37.1665285 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\PageAllocatorSystemHeapIsPrivate","NAME NOT FOUND","Length: 144"
  512. "1:15:37.1665686 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\AggressiveMTATesting","NAME NOT FOUND","Length: 144"
  513. "1:15:37.1666281 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\OLE\Tracing","NAME NOT FOUND","Desired Access: Read"
  514. "1:15:37.1672303 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\imm32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  515. "1:15:37.1676608 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\imm32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  516. "1:15:37.1680728 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\msctf.dll","BUFFER OVERFLOW","Information: Owner"
  517. "1:15:37.1682298 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\imm32.dll","BUFFER OVERFLOW","Information: Owner"
  518. "1:15:37.1684667 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Error Message Instrument\","REPARSE","Desired Access: Read"
  519. "1:15:37.1684885 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Error Message Instrument","NAME NOT FOUND","Desired Access: Read"
  520. "1:15:37.1685292 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles","NAME NOT FOUND","Length: 20"
  521. "1:15:37.1686050 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Compatibility32\wwahost","NAME NOT FOUND","Length: 172"
  522. "1:15:37.1686324 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\IME Compatibility","NAME NOT FOUND","Desired Access: Read"
  523. "1:15:37.1687438 PM","wwahost.exe","2812","RegOpenKey","HKCU\Control Panel\Desktop\MuiCached\MachineLanguageConfiguration","NAME NOT FOUND","Desired Access: Read"
  524. "1:15:37.1687716 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read"
  525. "1:15:37.1688039 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read"
  526. "1:15:37.1688341 PM","wwahost.exe","2812","RegEnumValue","HKCU\Control Panel\Desktop\LanguageConfiguration","NO MORE ENTRIES","Index: 0, Length: 512"
  527. "1:15:37.1688670 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read"
  528. "1:15:37.1688981 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read"
  529. "1:15:37.1689268 PM","wwahost.exe","2812","RegQueryValue","HKCU\Control Panel\Desktop\PreferredUILanguages","NAME NOT FOUND","Length: 12"
  530. "1:15:37.1689573 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read"
  531. "1:15:37.1690046 PM","wwahost.exe","2812","RegQueryValue","HKCU\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages","BUFFER OVERFLOW","Length: 12"
  532. "1:15:37.1692030 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\WWAHost.exe.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  533. "1:15:37.1697128 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\CRYPTBASE.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  534. "1:15:37.1698311 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\CRYPTBASE.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  535. "1:15:37.1699211 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\CRYPTBASE.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  536. "1:15:37.1702118 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\cryptbase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  537. "1:15:37.1705656 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\bcryptPrimitives.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  538. "1:15:37.1706588 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\bcryptPrimitives.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  539. "1:15:37.1707461 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\bcryptPrimitives.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  540. "1:15:37.1710301 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\bcryptprimitives.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  541. "1:15:37.1714168 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\bcryptprimitives.dll","BUFFER OVERFLOW","Information: Owner"
  542. "1:15:37.1716184 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\cryptbase.dll","BUFFER OVERFLOW","Information: Owner"
  543. "1:15:37.1717102 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","REPARSE","Desired Access: Query Value"
  544. "1:15:37.1717676 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa","REPARSE","Desired Access: Query Value"
  545. "1:15:37.1717987 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","NAME NOT FOUND","Length: 20"
  546. "1:15:37.1718388 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration","REPARSE","Desired Access: Query Value"
  547. "1:15:37.1718545 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration","NAME NOT FOUND","Desired Access: Query Value"
  548. "1:15:37.1719825 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\OLE\Tracing","NAME NOT FOUND","Desired Access: Read"
  549. "1:15:37.1724217 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\advapi32.dll","BUFFER OVERFLOW","Information: Owner"
  550. "1:15:37.1726511 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only","NAME NOT FOUND","Length: 144"
  551. "1:15:37.1726840 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value"
  552. "1:15:37.1727344 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl","NAME NOT FOUND","Desired Access: Query Value"
  553. "1:15:37.1728174 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_STRUCTURE_NODE_CHILD_COUNT","NAME NOT FOUND","Desired Access: Query Value"
  554. "1:15:37.1728431 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_STRUCTURE_NODE_CHILD_COUNT","NAME NOT FOUND","Desired Access: Query Value"
  555. "1:15:37.1729327 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay","NAME NOT FOUND","Length: 16"
  556. "1:15:37.1729662 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","REPARSE","Desired Access: Read"
  557. "1:15:37.1729976 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\en-US","NAME NOT FOUND","Length: 532"
  558. "1:15:37.1730170 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","REPARSE","Desired Access: Read"
  559. "1:15:37.1730438 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale\en-US","NAME NOT FOUND","Length: 532"
  560. "1:15:37.1797412 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXE","NAME NOT FOUND","Desired Access: Read"
  561. "1:15:37.1798951 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Application Compatibility\wwahost.exe","NAME NOT FOUND","Length: 144"
  562. "1:15:37.1799516 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\DOMStorage","NAME NOT FOUND","Desired Access: Read"
  563. "1:15:37.1799999 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\DOMStorage","NAME NOT FOUND","Desired Access: Read"
  564. "1:15:37.1800282 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\DOMStorage","NAME NOT FOUND","Desired Access: Read"
  565. "1:15:37.1800593 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Internet Explorer\DOMStorage","NAME NOT FOUND","Desired Access: Read"
  566. "1:15:37.1800959 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\DOMStorage","NAME NOT FOUND","Desired Access: Read"
  567. "1:15:37.1801233 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Internet Explorer\DOMStorage","NAME NOT FOUND","Desired Access: Read"
  568. "1:15:37.1801553 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\microsoft\Internet Explorer\Persistence","NAME NOT FOUND","Desired Access: Query Value"
  569. "1:15:37.1801798 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\microsoft\Internet Explorer\Persistence","NAME NOT FOUND","Desired Access: Query Value"
  570. "1:15:37.1803334 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\OLEAUT","NAME NOT FOUND","Desired Access: Query Value"
  571. "1:15:37.1804300 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  572. "1:15:37.1804795 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  573. "1:15:37.1805133 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
  574. "1:15:37.1805396 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  575. "1:15:37.1805580 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  576. "1:15:37.1805912 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
  577. "1:15:37.1806220 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Appcompat\","NAME NOT FOUND","Desired Access: Query Value"
  578. "1:15:37.1807769 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\2a3c6602-411e-4dc6-b138-ea19d64f5bba","NAME NOT FOUND","Length: 524"
  579. "1:15:37.1808040 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\d8b068fb-6f2d-4eab-8a45-93744db9ee59","NAME NOT FOUND","Length: 524"
  580. "1:15:37.1808227 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\bf602ba6-72f7-42fc-ad01-a8ed5b87241e","NAME NOT FOUND","Length: 524"
  581. "1:15:37.1812505 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rpcss.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  582. "1:15:37.1814216 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Ole\AppCompat\InputMessages","NAME NOT FOUND","Desired Access: Read"
  583. "1:15:37.1814835 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wwahost.exe","NAME NOT FOUND","Desired Access: Query Value"
  584. "1:15:37.1815656 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  585. "1:15:37.1816085 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  586. "1:15:37.1816326 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
  587. "1:15:37.1816501 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  588. "1:15:37.1816631 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  589. "1:15:37.1816864 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
  590. "1:15:37.1817259 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\52B21FA5","NAME NOT FOUND","Length: 24"
  591. "1:15:37.1817422 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  592. "1:15:37.1817564 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  593. "1:15:37.1817682 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm","NAME NOT FOUND","Desired Access: Read"
  594. "1:15:37.1818026 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\ThrottleStore\ThrottleExpiryTime","NAME NOT FOUND","Length: 24"
  595. "1:15:37.1818125 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  596. "1:15:37.1818361 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
  597. "1:15:37.1818509 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  598. "1:15:37.1818633 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  599. "1:15:37.1818859 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
  600. "1:15:37.1819125 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows\winsqm8\13238528","NAME NOT FOUND","Desired Access: Read"
  601. "1:15:37.1819315 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8\13238528","NAME NOT FOUND","Desired Access: Read"
  602. "1:15:37.1819457 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  603. "1:15:37.1819577 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  604. "1:15:37.1819692 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm","NAME NOT FOUND","Desired Access: Read"
  605. "1:15:37.1819921 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\ThrottleStore\ThrottleExpiryTime","NAME NOT FOUND","Length: 24"
  606. "1:15:37.1820009 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  607. "1:15:37.1820241 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
  608. "1:15:37.1820444 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  609. "1:15:37.1820573 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  610. "1:15:37.1820821 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
  611. "1:15:37.1821041 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows\winsqm8\13238784","NAME NOT FOUND","Desired Access: Read"
  612. "1:15:37.1821168 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8\13238784","NAME NOT FOUND","Desired Access: Read"
  613. "1:15:37.1821401 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  614. "1:15:37.1821527 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  615. "1:15:37.1821639 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm","NAME NOT FOUND","Desired Access: Read"
  616. "1:15:37.1821868 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\ThrottleStore\ThrottleExpiryTime","NAME NOT FOUND","Length: 24"
  617. "1:15:37.1821986 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  618. "1:15:37.1822240 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
  619. "1:15:37.1822391 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  620. "1:15:37.1822511 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  621. "1:15:37.1822738 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
  622. "1:15:37.1823022 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows\winsqm8\101457980","NAME NOT FOUND","Desired Access: Read"
  623. "1:15:37.1823160 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8\101457980","NAME NOT FOUND","Desired Access: Read"
  624. "1:15:37.1824796 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","REPARSE","Desired Access: Read"
  625. "1:15:37.1825581 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\PackageRootFolder","BUFFER OVERFLOW","Length: 144"
  626. "1:15:37.1825753 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\PackageRootFolder","BUFFER OVERFLOW","Length: 144"
  627. "1:15:37.1826596 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}","NAME NOT FOUND","Desired Access: Read"
  628. "1:15:37.1827091 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}","NAME NOT FOUND","Desired Access: Read"
  629. "1:15:37.1827281 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Applications\Microsoft.BingNews_8wekyb3d8bbwe!AppexNews\DisplayName","BUFFER OVERFLOW","Length: 144"
  630. "1:15:37.1827441 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Applications\Microsoft.BingNews_8wekyb3d8bbwe!AppexNews\DisplayName","BUFFER OVERFLOW","Length: 144"
  631. "1:15:37.1827803 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}","NAME NOT FOUND","Desired Access: Read"
  632. "1:15:37.1828521 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Applications\Microsoft.BingNews_8wekyb3d8bbwe!AppexNews\ApplicationContentUris","NAME NOT FOUND","Length: 144"
  633. "1:15:37.1828745 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  634. "1:15:37.1829355 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  635. "1:15:37.1829388 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","REPARSE","Desired Access: Read"
  636. "1:15:37.1829415 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Main","NAME NOT FOUND","Desired Access: Read"
  637. "1:15:37.1829907 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DevelopmentMode","NAME NOT FOUND","Length: 144"
  638. "1:15:37.1830324 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main","NAME NOT FOUND","Desired Access: Read"
  639. "1:15:37.1830677 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  640. "1:15:37.1831154 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\UseSWRender","NAME NOT FOUND","Length: 144"
  641. "1:15:37.1831552 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  642. "1:15:37.1831791 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\UseSWRender","NAME NOT FOUND","Length: 144"
  643. "1:15:37.1832204 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
  644. "1:15:37.1833384 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  645. "1:15:37.1833650 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\InprocServer32\InprocServer32","NAME NOT FOUND","Length: 144"
  646. "1:15:37.1834009 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\UseSWRender","NAME NOT FOUND","Length: 144"
  647. "1:15:37.1834230 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\UseSWRender","NAME NOT FOUND","Length: 144"
  648. "1:15:37.1834266 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  649. "1:15:37.1834818 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  650. "1:15:37.1835763 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\d2d1.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  651. "1:15:37.1835872 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  652. "1:15:37.1836874 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  653. "1:15:37.1836883 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\d2d1.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  654. "1:15:37.1837140 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  655. "1:15:37.1837523 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  656. "1:15:37.1837767 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  657. "1:15:37.1837930 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\d2d1.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  658. "1:15:37.1838262 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\MaxSxSHashCount","NAME NOT FOUND","Length: 144"
  659. "1:15:37.1839388 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}","NAME NOT FOUND","Desired Access: Read"
  660. "1:15:37.1840472 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  661. "1:15:37.1840759 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{DBCE7E40-7345-439D-B12C-114A11819A09}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  662. "1:15:37.1842283 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\d2d1.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  663. "1:15:37.2398396 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\MrmCoreR.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  664. "1:15:37.2398538 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\MrmCoreR.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  665. "1:15:37.2402960 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize","NAME NOT FOUND","Length: 144"
  666. "1:15:37.2403437 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize","NAME NOT FOUND","Length: 144"
  667. "1:15:37.2403881 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize","NAME NOT FOUND","Length: 144"
  668. "1:15:37.2404385 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize","NAME NOT FOUND","Length: 144"
  669. "1:15:37.2404659 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode","NAME NOT FOUND","Length: 144"
  670. "1:15:37.2404759 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode","NAME NOT FOUND","Length: 144"
  671. "1:15:37.2404847 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode","NAME NOT FOUND","Length: 144"
  672. "1:15:37.2406957 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Globalization\Sorting\SortDefault.nls","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  673. "1:15:37.2407343 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Rpc\MaxRpcSize","NAME NOT FOUND","Length: 144"
  674. "1:15:37.2407847 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName","REPARSE","Desired Access: Read"
  675. "1:15:37.2408354 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids","REPARSE","Desired Access: Read"
  676. "1:15:37.2408544 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DWrite.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  677. "1:15:37.2408828 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids\en-US","NAME NOT FOUND","Length: 90"
  678. "1:15:37.2408997 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids\en","NAME NOT FOUND","Length: 90"
  679. "1:15:37.2410153 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\DWrite.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  680. "1:15:37.2410760 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","REPARSE","Desired Access: Read"
  681. "1:15:37.2411228 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows NT\Rpc","NAME NOT FOUND","Desired Access: Read"
  682. "1:15:37.2411530 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\PackageRootFolder","BUFFER OVERFLOW","Length: 144"
  683. "1:15:37.2411596 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  684. "1:15:37.2411832 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\DWrite.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  685. "1:15:37.2412272 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  686. "1:15:37.2412659 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
  687. "1:15:37.2412949 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  688. "1:15:37.2413151 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  689. "1:15:37.2413477 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
  690. "1:15:37.2414473 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Rpc\IdleTimerWindow","NAME NOT FOUND","Length: 144"
  691. "1:15:37.2416269 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\DWrite.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  692. "1:15:37.2416272 PM","wwahost.exe","2812","RegCreateKey","HKCU\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe%5Cresources.pri","REPARSE","Desired Access: Read/Write"
  693. "1:15:37.2416544 PM","wwahost.exe","2812","RegCreateKey","HKCU\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe%5Cresources.pri","ACCESS DENIED","Desired Access: Read/Write"
  694. "1:15:37.2420374 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\FontCache\Parameters","REPARSE","Desired Access: Read"
  695. "1:15:37.2422363 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\dxgi.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  696. "1:15:37.2423378 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\dxgi.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  697. "1:15:37.2424259 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\dxgi.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  698. "1:15:37.2427193 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  699. "1:15:37.2429638 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  700. "1:15:37.2512242 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\WWAHost.exe","BUFFER OVERFLOW","Information: Owner"
  701. "1:15:37.2514265 PM","wwahost.exe","2812","RegCreateKey","HKCU\Software\Classes\Local Settings\MrtCache","ACCESS DENIED","Desired Access: Maximum Allowed"
  702. "1:15:37.2515351 PM","wwahost.exe","2812","CreateFile","C:\ProgramData\PRICache","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
  703. "1:15:37.2851309 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  704. "1:15:37.2851635 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
  705. "1:15:37.2851894 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  706. "1:15:37.2851949 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication\Server","NAME NOT FOUND","Length: 138"
  707. "1:15:37.2852036 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Core.CoreApplication","BUFFER TOO SMALL","Query: Full, Length: 0"
  708. "1:15:37.2852076 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  709. "1:15:37.2852371 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
  710. "1:15:37.2855550 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Query Value"
  711. "1:15:37.2856582 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Direct3D","NAME NOT FOUND","Desired Access: Read"
  712. "1:15:37.2856902 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Direct3D","NAME NOT FOUND","Desired Access: Read"
  713. "1:15:37.2856972 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\AC\PRICache","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
  714. "1:15:37.2858324 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\DXGIDebug.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  715. "1:15:37.2858559 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","REPARSE","Desired Access: Read"
  716. "1:15:37.2859012 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\PackageRootFolder","BUFFER OVERFLOW","Length: 144"
  717. "1:15:37.2859293 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\DXGIDebug.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  718. "1:15:37.2860214 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\DXGIDebug.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  719. "1:15:37.2861086 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\DXGIDebug.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  720. "1:15:37.2862013 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\DXGIDebug.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  721. "1:15:37.2862547 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\resources.pri","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  722. "1:15:37.2862849 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\DXGIDebug.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  723. "1:15:37.2864814 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\DXGI","NAME NOT FOUND","Desired Access: Read"
  724. "1:15:37.2865104 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\DXGI","NAME NOT FOUND","Desired Access: Read"
  725. "1:15:37.2867307 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\apppatch\apppatch64\sysmain.sdb","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  726. "1:15:37.2870875 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\d3d11.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  727. "1:15:37.2871778 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\d3d11.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  728. "1:15:37.2872629 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\d3d11.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  729. "1:15:37.2875346 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\d3d11.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  730. "1:15:37.2878358 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  731. "1:15:37.2878920 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  732. "1:15:37.2879312 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
  733. "1:15:37.2879542 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  734. "1:15:37.2879798 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  735. "1:15:37.2880085 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
  736. "1:15:37.2881809 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\aticfx64.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  737. "1:15:37.2882787 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\aticfx64.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  738. "1:15:37.2883641 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\aticfx64.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  739. "1:15:37.2885829 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Query Value"
  740. "1:15:37.2886349 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\aticfx64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  741. "1:15:37.2886699 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\Microsoft.BingNews_8wekyb3d8bbwe","REPARSE","Desired Access: Read/Write"
  742. "1:15:37.2888419 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\ManifestLanguagesList","BUFFER OVERFLOW","Length: 144"
  743. "1:15:37.3000017 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet\Server","NAME NOT FOUND","Length: 138"
  744. "1:15:37.3000104 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Collections.PropertySet","BUFFER TOO SMALL","Query: Full, Length: 0"
  745. "1:15:37.3059848 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\KernelBase.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  746. "1:15:37.3063118 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\atiuxp64.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  747. "1:15:37.3063483 PM","wwahost.exe","2812","CreateFile","C:\ProgramData\PRICache","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
  748. "1:15:37.3064120 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\atiuxp64.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  749. "1:15:37.3065086 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\atiuxp64.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  750. "1:15:37.3065958 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Query Value"
  751. "1:15:37.3067093 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\AC\PRICache","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
  752. "1:15:37.3068225 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\atiuxp64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  753. "1:15:37.3070767 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\resources.pri","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  754. "1:15:37.3071690 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\VERSION.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  755. "1:15:37.3072699 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\VERSION.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  756. "1:15:37.3073559 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\VERSION.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  757. "1:15:37.3076792 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\version.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  758. "1:15:37.3085325 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000","REPARSE","Desired Access: Query Value"
  759. "1:15:37.3086062 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000\Blacklist","NAME NOT FOUND","Length: 144"
  760. "1:15:37.3087677 PM","wwahost.exe","2812","QueryAllInformationFile","C:\Windows\System32\atipblag.dat","BUFFER OVERFLOW","CreationTime: 2/15/2013 10:25:14 PM, LastAccessTime: 2/15/2013 10:25:14 PM, LastWriteTime: 9/13/2011 9:06:16 AM, ChangeTime: 3/9/2013 1:47:51 AM, FileAttributes: A, AllocationSize: 4,096, EndOfFile: 3,917, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x100000007478c, EaSize: 0, Access: Read Data/List Directory, Read Attributes, Synchronize, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Long"
  761. "1:15:37.3089711 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\atidxx64.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  762. "1:15:37.3090729 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\atidxx64.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  763. "1:15:37.3091622 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\atidxx64.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  764. "1:15:37.3094420 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\resources.pri","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  765. "1:15:37.3094577 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\atidxx64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  766. "1:15:37.3317573 PM","wwahost.exe","2812","RegEnumValue","HKLM\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000\UMD","NO MORE ENTRIES","Index: 76, Length: 770"
  767. "1:15:37.3334963 PM","wwahost.exe","2812","RegEnumValue","HKLM\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000\UMD\DXVA","NO MORE ENTRIES","Index: 84, Length: 770"
  768. "1:15:37.3340780 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\GraphicsDrivers","REPARSE","Desired Access: Read"
  769. "1:15:37.3343771 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Direct3D","NAME NOT FOUND","Desired Access: Read"
  770. "1:15:37.3344158 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Direct3D","NAME NOT FOUND","Desired Access: Read"
  771. "1:15:37.3345130 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\GraphicsDrivers\Scheduler","REPARSE","Desired Access: Read, Maximum Allowed"
  772. "1:15:37.3345344 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\GraphicsDrivers\Scheduler","NAME NOT FOUND","Desired Access: Read, Maximum Allowed"
  773. "1:15:37.3425793 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\resources.pri","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  774. "1:15:37.3471530 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\ManifestLanguagesList","BUFFER OVERFLOW","Length: 144"
  775. "1:15:37.3472418 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\OverrideLanguagesList","NAME NOT FOUND","Length: 144"
  776. "1:15:37.3478684 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  777. "1:15:37.3479276 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  778. "1:15:37.3479575 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
  779. "1:15:37.3479750 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  780. "1:15:37.3479892 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  781. "1:15:37.3480127 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
  782. "1:15:37.3480951 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only","NAME NOT FOUND","Length: 144"
  783. "1:15:37.3481247 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\","NAME NOT FOUND","Desired Access: Read"
  784. "1:15:37.3481513 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\","NAME NOT FOUND","Desired Access: Read"
  785. "1:15:37.3481830 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\","NAME NOT FOUND","Desired Access: Read"
  786. "1:15:37.3482162 PM","wwahost.exe","2812","RegOpenKey","HKLM\ZoneMap\Ranges\","NAME NOT FOUND","Desired Access: Read"
  787. "1:15:37.3482391 PM","wwahost.exe","2812","RegOpenKey","HKCU\ZoneMap\Ranges\","NAME NOT FOUND","Desired Access: Read"
  788. "1:15:37.3482606 PM","wwahost.exe","2812","RegOpenKey","HKLM\ZoneMap\Ranges\","NAME NOT FOUND","Desired Access: Read"
  789. "1:15:37.3485078 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap","NAME NOT FOUND","Desired Access: Query Value"
  790. "1:15:37.3485826 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap","NAME NOT FOUND","Desired Access: Query Value"
  791. "1:15:37.3486587 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","NAME NOT FOUND","Desired Access: Read"
  792. "1:15:37.3486895 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","NAME NOT FOUND","Desired Access: Read"
  793. "1:15:37.3487185 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","NAME NOT FOUND","Desired Access: Read"
  794. "1:15:37.3489859 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\","NAME NOT FOUND","Desired Access: Read"
  795. "1:15:37.3923797 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\AppEx.Common.NewsBdiTransformer.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  796. "1:15:37.4355447 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\GPU\AdapterInfo","BUFFER OVERFLOW","Length: 144"
  797. "1:15:37.4357687 PM","wwahost.exe","2812","RegCreateKey","HKCU\Software\Microsoft\Internet Explorer\GPU","ACCESS DENIED","Desired Access: Write"
  798. "1:15:37.4358052 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\WWAHost.exe","BUFFER OVERFLOW","Information: Owner"
  799. "1:15:37.4359628 PM","wwahost.exe","2812","RegCreateKey","HKCU\Software\Microsoft\Internet Explorer\GPU","ACCESS DENIED","Desired Access: Write"
  800. "1:15:37.4359830 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\WWAHost.exe","BUFFER OVERFLOW","Information: Owner"
  801. "1:15:37.4911318 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Microsoft.Media.AdaptiveStreaming.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  802. "1:15:37.5249709 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\MicrosoftAdvertising.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  803. "1:15:37.5552788 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\News.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  804. "1:15:37.5818367 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\NYT.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  805. "1:15:37.6309891 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  806. "1:15:37.6315424 PM","wwahost.exe","2812","QueryDirectory","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","NO MORE FILES",""
  807. "1:15:37.6317325 PM","wwahost.exe","2812","QueryDirectory","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\*.winmd","NO SUCH FILE","Filter: *.winmd"
  808. "1:15:37.6318820 PM","wwahost.exe","2812","QueryDirectory","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\*.winmd","NO SUCH FILE","Filter: *.winmd"
  809. "1:15:37.6319761 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wwahost.exe","NAME NOT FOUND","Desired Access: Read"
  810. "1:15:37.6321011 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wwahost.exe","NAME NOT FOUND","Desired Access: Query Value"
  811. "1:15:37.6321271 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wwahost.exe","NAME NOT FOUND","Desired Access: Query Value"
  812. "1:15:37.6334737 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\AppID\wwahost.exe","NAME NOT FOUND","Desired Access: Read"
  813. "1:15:37.6335005 PM","wwahost.exe","2812","RegOpenKey","HKCR\AppID\wwahost.exe","NAME NOT FOUND","Desired Access: Read"
  814. "1:15:37.6335660 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\AppID\wwahost.exe","NAME NOT FOUND","Desired Access: Read"
  815. "1:15:37.6335826 PM","wwahost.exe","2812","RegOpenKey","HKCR\AppID\wwahost.exe","NAME NOT FOUND","Desired Access: Read"
  816. "1:15:37.6336258 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel","NAME NOT FOUND","Length: 144"
  817. "1:15:37.6336738 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\DefaultAccessPermission","NAME NOT FOUND","Length: 144"
  818. "1:15:37.6343626 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\CRYPTSP.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  819. "1:15:37.6344671 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\CRYPTSP.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  820. "1:15:37.6345567 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\CRYPTSP.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  821. "1:15:37.6348797 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\cryptsp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  822. "1:15:37.6354928 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rsaenh.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  823. "1:15:37.6357255 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","REPARSE","Desired Access: Query Value"
  824. "1:15:37.6357823 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa","REPARSE","Desired Access: Query Value"
  825. "1:15:37.6358125 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","NAME NOT FOUND","Length: 20"
  826. "1:15:37.6358427 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration","REPARSE","Desired Access: Query Value"
  827. "1:15:37.6358581 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration","NAME NOT FOUND","Desired Access: Query Value"
  828. "1:15:37.6359236 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCacheMaxItems","NAME NOT FOUND","Length: 144"
  829. "1:15:37.6359323 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCachePurgeIntervalSeconds","NAME NOT FOUND","Length: 144"
  830. "1:15:37.6359402 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Cryptography\PrivateKeyLifetimeSeconds","NAME NOT FOUND","Length: 144"
  831. "1:15:37.6360663 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Cryptography\Offload","NAME NOT FOUND","Desired Access: Read"
  832. "1:15:37.6362118 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}","NAME NOT FOUND","Desired Access: Read"
  833. "1:15:37.6362752 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
  834. "1:15:37.6363450 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  835. "1:15:37.6369097 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  836. "1:15:37.6369487 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  837. "1:15:37.6369828 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  838. "1:15:37.6370103 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  839. "1:15:37.6370332 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package","REPARSE","Desired Access: Read"
  840. "1:15:37.6371020 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package","REPARSE","Desired Access: Read"
  841. "1:15:37.6371298 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DebugInformation\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  842. "1:15:37.6371585 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa\CommandLine","NAME NOT FOUND","Length: 530"
  843. "1:15:37.6371669 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa\ActivatableClasses","BUFFER OVERFLOW","Length: 136"
  844. "1:15:37.6371980 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa\Identity","NAME NOT FOUND","Length: 138"
  845. "1:15:37.6372050 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa\ServiceName","NAME NOT FOUND","Length: 138"
  846. "1:15:37.6372119 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa\Permissions","BUFFER OVERFLOW","Length: 136"
  847. "1:15:37.6372348 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
  848. "1:15:37.6372726 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  849. "1:15:37.6373055 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  850. "1:15:37.6373206 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  851. "1:15:37.6373348 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  852. "1:15:37.6373520 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package","REPARSE","Desired Access: Read"
  853. "1:15:37.6374169 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{35262B8B-9081-54A2-9E54-E5D67149AF20}","NAME NOT FOUND","Desired Access: Read"
  854. "1:15:37.6374317 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{35262B8B-9081-54A2-9E54-E5D67149AF20}","NAME NOT FOUND","Desired Access: Read"
  855. "1:15:37.6374836 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{35262B8B-9081-54A2-9E54-E5D67149AF20}","NAME NOT FOUND","Desired Access: Read"
  856. "1:15:37.6374984 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{35262B8B-9081-54A2-9E54-E5D67149AF20}","NAME NOT FOUND","Desired Access: Read"
  857. "1:15:37.6375539 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Wow6432Node\CLSID\{35262B8B-9081-54A2-9E54-E5D67149AF20}","NAME NOT FOUND","Desired Access: Read"
  858. "1:15:37.6375720 PM","wwahost.exe","2812","RegOpenKey","HKCR\Wow6432Node\CLSID\{35262B8B-9081-54A2-9E54-E5D67149AF20}","NAME NOT FOUND","Desired Access: Read"
  859. "1:15:37.6375889 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\CLSID","REPARSE","Desired Access: Read"
  860. "1:15:37.6376493 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  861. "1:15:37.6376638 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  862. "1:15:37.6377229 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\DllPath","NAME NOT FOUND","Length: 530"
  863. "1:15:37.6377395 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  864. "1:15:37.6377543 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  865. "1:15:37.6378008 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DebugInformation\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  866. "1:15:37.6378144 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
  867. "1:15:37.6378446 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
  868. "1:15:37.6378884 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\AppexNews.AppX840xcewdazfg7z839sn6pf6ws2g4dfec.wwa","NAME NOT FOUND","Desired Access: Read"
  869. "1:15:37.6379074 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppX840xcewdazfg7z839sn6pf6ws2g4dfec.wwa","NAME NOT FOUND","Desired Access: Read"
  870. "1:15:37.6379222 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppX840xcewdazfg7z839sn6pf6ws2g4dfec.wwa","NAME NOT FOUND","Desired Access: Read"
  871. "1:15:37.6379361 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppX840xcewdazfg7z839sn6pf6ws2g4dfec.wwa","NAME NOT FOUND","Desired Access: Read"
  872. "1:15:37.6489965 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{15E195FA-CCBA-52B5-83D6-34A16E8180C0}","NAME NOT FOUND","Desired Access: Read"
  873. "1:15:37.6490228 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{15E195FA-CCBA-52B5-83D6-34A16E8180C0}","NAME NOT FOUND","Desired Access: Read"
  874. "1:15:37.6490780 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{15E195FA-CCBA-52B5-83D6-34A16E8180C0}","NAME NOT FOUND","Desired Access: Read"
  875. "1:15:37.6490961 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{15E195FA-CCBA-52B5-83D6-34A16E8180C0}","NAME NOT FOUND","Desired Access: Read"
  876. "1:15:37.6491523 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Wow6432Node\CLSID\{15E195FA-CCBA-52B5-83D6-34A16E8180C0}","NAME NOT FOUND","Desired Access: Read"
  877. "1:15:37.6491701 PM","wwahost.exe","2812","RegOpenKey","HKCR\Wow6432Node\CLSID\{15E195FA-CCBA-52B5-83D6-34A16E8180C0}","NAME NOT FOUND","Desired Access: Read"
  878. "1:15:37.6575823 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\AppexNews.AppX840xcewdazfg7z839sn6pf6ws2g4dfec.wwa","NAME NOT FOUND","Desired Access: Read"
  879. "1:15:37.6576067 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppX840xcewdazfg7z839sn6pf6ws2g4dfec.wwa","NAME NOT FOUND","Desired Access: Read"
  880. "1:15:37.6576768 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppX840xcewdazfg7z839sn6pf6ws2g4dfec.wwa\DllPath","NAME NOT FOUND","Length: 530"
  881. "1:15:37.6576955 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  882. "1:15:37.6577148 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  883. "1:15:37.6577652 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DebugInformation\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  884. "1:15:37.6577800 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
  885. "1:15:37.6578129 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppX840xcewdazfg7z839sn6pf6ws2g4dfec.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
  886. "1:15:37.6578582 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\AppexNews.AppXmr5vsssa5hr66w886547dqn2casn6rsg.wwa","NAME NOT FOUND","Desired Access: Read"
  887. "1:15:37.6578769 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXmr5vsssa5hr66w886547dqn2casn6rsg.wwa","NAME NOT FOUND","Desired Access: Read"
  888. "1:15:37.6578926 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXmr5vsssa5hr66w886547dqn2casn6rsg.wwa","NAME NOT FOUND","Desired Access: Read"
  889. "1:15:37.6579077 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXmr5vsssa5hr66w886547dqn2casn6rsg.wwa","NAME NOT FOUND","Desired Access: Read"
  890. "1:15:37.6579623 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{118D5336-7258-57A7-946D-C218AC241D40}","NAME NOT FOUND","Desired Access: Read"
  891. "1:15:37.6579792 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{118D5336-7258-57A7-946D-C218AC241D40}","NAME NOT FOUND","Desired Access: Read"
  892. "1:15:37.6580308 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{118D5336-7258-57A7-946D-C218AC241D40}","NAME NOT FOUND","Desired Access: Read"
  893. "1:15:37.6580484 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{118D5336-7258-57A7-946D-C218AC241D40}","NAME NOT FOUND","Desired Access: Read"
  894. "1:15:37.6581111 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Wow6432Node\CLSID\{118D5336-7258-57A7-946D-C218AC241D40}","NAME NOT FOUND","Desired Access: Read"
  895. "1:15:37.6581293 PM","wwahost.exe","2812","RegOpenKey","HKCR\Wow6432Node\CLSID\{118D5336-7258-57A7-946D-C218AC241D40}","NAME NOT FOUND","Desired Access: Read"
  896. "1:15:37.6581812 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\AppexNews.AppXmr5vsssa5hr66w886547dqn2casn6rsg.wwa","NAME NOT FOUND","Desired Access: Read"
  897. "1:15:37.6581966 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXmr5vsssa5hr66w886547dqn2casn6rsg.wwa","NAME NOT FOUND","Desired Access: Read"
  898. "1:15:37.6582557 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXmr5vsssa5hr66w886547dqn2casn6rsg.wwa\DllPath","NAME NOT FOUND","Length: 530"
  899. "1:15:37.6582726 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  900. "1:15:37.6582883 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  901. "1:15:37.6583339 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DebugInformation\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  902. "1:15:37.6583478 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
  903. "1:15:37.6583774 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXmr5vsssa5hr66w886547dqn2casn6rsg.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
  904. "1:15:37.6584199 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\AppexNews.AppXctnv7jgfexcxjqxhnfr8weh1x4cw0e6g.wwa","NAME NOT FOUND","Desired Access: Read"
  905. "1:15:37.6584387 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXctnv7jgfexcxjqxhnfr8weh1x4cw0e6g.wwa","NAME NOT FOUND","Desired Access: Read"
  906. "1:15:37.6584531 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXctnv7jgfexcxjqxhnfr8weh1x4cw0e6g.wwa","NAME NOT FOUND","Desired Access: Read"
  907. "1:15:37.6584673 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXctnv7jgfexcxjqxhnfr8weh1x4cw0e6g.wwa","NAME NOT FOUND","Desired Access: Read"
  908. "1:15:37.6585244 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{D9A93F9B-739F-5240-AF23-A40768CD5D31}","NAME NOT FOUND","Desired Access: Read"
  909. "1:15:37.6585404 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{D9A93F9B-739F-5240-AF23-A40768CD5D31}","NAME NOT FOUND","Desired Access: Read"
  910. "1:15:37.6585896 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D9A93F9B-739F-5240-AF23-A40768CD5D31}","NAME NOT FOUND","Desired Access: Read"
  911. "1:15:37.6586062 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{D9A93F9B-739F-5240-AF23-A40768CD5D31}","NAME NOT FOUND","Desired Access: Read"
  912. "1:15:37.6586596 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Wow6432Node\CLSID\{D9A93F9B-739F-5240-AF23-A40768CD5D31}","NAME NOT FOUND","Desired Access: Read"
  913. "1:15:37.6586762 PM","wwahost.exe","2812","RegOpenKey","HKCR\Wow6432Node\CLSID\{D9A93F9B-739F-5240-AF23-A40768CD5D31}","NAME NOT FOUND","Desired Access: Read"
  914. "1:15:37.6746213 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\AppexNews.AppXctnv7jgfexcxjqxhnfr8weh1x4cw0e6g.wwa","NAME NOT FOUND","Desired Access: Read"
  915. "1:15:37.6746506 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXctnv7jgfexcxjqxhnfr8weh1x4cw0e6g.wwa","NAME NOT FOUND","Desired Access: Read"
  916. "1:15:37.6747182 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXctnv7jgfexcxjqxhnfr8weh1x4cw0e6g.wwa\DllPath","NAME NOT FOUND","Length: 530"
  917. "1:15:37.6747354 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  918. "1:15:37.6747533 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  919. "1:15:37.6748019 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DebugInformation\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  920. "1:15:37.6748160 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
  921. "1:15:37.6748480 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.AppXctnv7jgfexcxjqxhnfr8weh1x4cw0e6g.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
  922. "1:15:37.6791963 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  923. "1:15:37.6792235 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  924. "1:15:37.6792395 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm","NAME NOT FOUND","Desired Access: Read"
  925. "1:15:37.6792624 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
  926. "1:15:37.6792811 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\ThrottleStore\ThrottleExpiryTime","NAME NOT FOUND","Length: 24"
  927. "1:15:37.6792938 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  928. "1:15:37.6793270 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DebugInformation\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  929. "1:15:37.6793310 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
  930. "1:15:37.6793439 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
  931. "1:15:37.6793563 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  932. "1:15:37.6793714 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  933. "1:15:37.6793962 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
  934. "1:15:37.6794212 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows\winsqm8\101457980","NAME NOT FOUND","Desired Access: Read"
  935. "1:15:37.6794306 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
  936. "1:15:37.6794345 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8\101457980","NAME NOT FOUND","Desired Access: Read"
  937. "1:15:37.6794840 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DebugInformation\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  938. "1:15:37.6794979 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
  939. "1:15:37.6795407 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{2E5500B6-66AD-467F-ABB5-022A64283D88}","NAME NOT FOUND","Desired Access: Read"
  940. "1:15:37.6795957 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  941. "1:15:37.6796238 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  942. "1:15:37.6796446 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  943. "1:15:37.6796618 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  944. "1:15:37.6797161 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
  945. "1:15:37.6797729 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DebugInformation\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  946. "1:15:37.6797880 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
  947. "1:15:37.6803084 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue\Server","NAME NOT FOUND","Length: 138"
  948. "1:15:37.6803186 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.PropertyValue","BUFFER TOO SMALL","Query: Full, Length: 0"
  949. "1:15:37.6803817 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\CustomAttributes\AppObject.Aliased","BUFFER TOO SMALL","Length: 0"
  950. "1:15:37.6804246 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\CustomAttributes\AppObject.RuntimeType","NAME NOT FOUND","Length: 0"
  951. "1:15:37.6804336 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\CustomAttributes\AppObject.EntryPoint","BUFFER TOO SMALL","Length: 0"
  952. "1:15:37.6805493 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
  953. "1:15:37.6806030 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DebugInformation\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  954. "1:15:37.6806175 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
  955. "1:15:37.6807065 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{AF86E2E0-B12D-4C6A-9C5A-D7AA65101E90}","NAME NOT FOUND","Desired Access: Read"
  956. "1:15:37.6879059 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{2E5500B6-66AD-467F-ABB5-022A64283D88}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
  957. "1:15:37.6879472 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{AF86E2E0-B12D-4C6A-9C5A-D7AA65101E90}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
  958. "1:15:37.6879898 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{2E5500B6-66AD-467F-ABB5-022A64283D88}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  959. "1:15:37.6880462 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{AF86E2E0-B12D-4C6A-9C5A-D7AA65101E90}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  960. "1:15:37.6880474 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}","NAME NOT FOUND","Desired Access: Read"
  961. "1:15:37.6880680 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}","NAME NOT FOUND","Desired Access: Read"
  962. "1:15:37.6881220 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}","NAME NOT FOUND","Desired Access: Read"
  963. "1:15:37.6882011 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  964. "1:15:37.6882479 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  965. "1:15:37.6883206 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  966. "1:15:37.6883813 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  967. "1:15:37.6884495 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
  968. "1:15:37.6885292 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  969. "1:15:37.6885528 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32\InprocServer32","NAME NOT FOUND","Length: 144"
  970. "1:15:37.6885959 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  971. "1:15:37.6886463 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  972. "1:15:37.6887152 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  973. "1:15:37.6887961 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  974. "1:15:37.6888296 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  975. "1:15:37.6888712 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  976. "1:15:37.6889138 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  977. "1:15:37.6889956 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}","NAME NOT FOUND","Desired Access: Read"
  978. "1:15:37.6890792 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  979. "1:15:37.6891221 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  980. "1:15:37.6892546 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{92696C00-7578-48E1-AC1A-2CA909E2C8CF}","NAME NOT FOUND","Desired Access: Read"
  981. "1:15:37.6895347 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\actxprxy.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  982. "1:15:37.6906235 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}","NAME NOT FOUND","Desired Access: Read"
  983. "1:15:37.6906552 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}","NAME NOT FOUND","Desired Access: Read"
  984. "1:15:37.6907156 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}","NAME NOT FOUND","Desired Access: Read"
  985. "1:15:37.6907868 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  986. "1:15:37.6908119 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  987. "1:15:37.6908617 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  988. "1:15:37.6908750 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\(Default)","NAME NOT FOUND","Length: 144"
  989. "1:15:37.6909100 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
  990. "1:15:37.6909794 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  991. "1:15:37.6909933 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\InProcServer32\InprocServer32","NAME NOT FOUND","Length: 144"
  992. "1:15:37.6910274 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  993. "1:15:37.6910781 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  994. "1:15:37.6911288 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  995. "1:15:37.6911910 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  996. "1:15:37.6912179 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  997. "1:15:37.6912559 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  998. "1:15:37.6912801 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  999. "1:15:37.6913543 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}","NAME NOT FOUND","Desired Access: Read"
  1000. "1:15:37.6914153 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1001. "1:15:37.6914416 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{02844640-E37C-4322-A3B8-4C61A2E58879}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1002. "1:15:37.6953247 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{92696C00-7578-48E1-AC1A-2CA909E2C8CF}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
  1003. "1:15:37.6954077 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{92696C00-7578-48E1-AC1A-2CA909E2C8CF}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1004. "1:15:37.7015798 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}","NAME NOT FOUND","Desired Access: Read"
  1005. "1:15:37.7016387 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}","NAME NOT FOUND","Desired Access: Read"
  1006. "1:15:37.7018068 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}","NAME NOT FOUND","Desired Access: Read"
  1007. "1:15:37.7066450 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1008. "1:15:37.7066839 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1009. "1:15:37.7067504 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1010. "1:15:37.7067673 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\(Default)","NAME NOT FOUND","Length: 144"
  1011. "1:15:37.7068110 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
  1012. "1:15:37.7068415 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
  1013. "1:15:37.7068892 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1014. "1:15:37.7069828 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\InProcHandler32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1015. "1:15:37.7070978 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1016. "1:15:37.7071757 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\InProcHandler32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1017. "1:15:37.7072871 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1018. "1:15:37.7073182 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1019. "1:15:37.7074087 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}","NAME NOT FOUND","Desired Access: Read"
  1020. "1:15:37.7074860 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1021. "1:15:37.7075207 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{14DE3806-5D5B-405C-AB89-4AC936BCBF48}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1022. "1:15:37.7078733 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.UI.Immersive.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1023. "1:15:37.7084163 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{CD292360-2763-4085-8A9F-74B224A29175}","NAME NOT FOUND","Desired Access: Read"
  1024. "1:15:37.7084900 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{CD292360-2763-4085-8A9F-74B224A29175}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
  1025. "1:15:37.7085697 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{CD292360-2763-4085-8A9F-74B224A29175}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1026. "1:15:37.7088628 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{CF651713-CD08-4FD8-B697-A281B6544E2E}","NAME NOT FOUND","Desired Access: Read"
  1027. "1:15:37.7089666 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{CF651713-CD08-4FD8-B697-A281B6544E2E}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
  1028. "1:15:37.7090451 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{CF651713-CD08-4FD8-B697-A281B6544E2E}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1029. "1:15:37.7093128 PM","wwahost.exe","2812","RegOpenKey","HKCR\Extensions\ContractId\Windows.Launch\PackageId\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","NAME NOT FOUND","Desired Access: Read"
  1030. "1:15:37.7095495 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Extensions\ContractId\Windows.Launch\PackageId\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\Icon","BUFFER OVERFLOW","Length: 144"
  1031. "1:15:37.7095598 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Extensions\ContractId\Windows.Launch\PackageId\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\Icon","BUFFER OVERFLOW","Length: 144"
  1032. "1:15:37.7095821 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Extensions\ContractId\Windows.Launch\PackageId\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\DisplayName","BUFFER OVERFLOW","Length: 144"
  1033. "1:15:37.7095915 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Extensions\ContractId\Windows.Launch\PackageId\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\DisplayName","BUFFER OVERFLOW","Length: 144"
  1034. "1:15:37.7096126 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Extensions\ContractId\Windows.Launch\PackageId\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\Description","BUFFER OVERFLOW","Length: 144"
  1035. "1:15:37.7096222 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Extensions\ContractId\Windows.Launch\PackageId\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\Description","BUFFER OVERFLOW","Length: 144"
  1036. "1:15:37.7096585 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Extensions\ContractId\Windows.Launch\PackageId\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa\CustomProperties","NAME NOT FOUND","Desired Access: Read"
  1037. "1:15:37.7096805 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  1038. "1:15:37.7096995 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  1039. "1:15:37.7097527 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
  1040. "1:15:37.7098106 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\DebugInformation\AppexNews.wwa","NAME NOT FOUND","Desired Access: Read"
  1041. "1:15:37.7098263 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Server\AppexNews.wwa","BUFFER TOO SMALL","Query: Full, Length: 0"
  1042. "1:15:37.7101267 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","REPARSE","Desired Access: Read"
  1043. "1:15:37.7101762 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\PackageRootFolder","BUFFER OVERFLOW","Length: 144"
  1044. "1:15:37.7104807 PM","wwahost.exe","2812","RegCreateKey","HKCU\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe%5Cresources.pri","REPARSE","Desired Access: Read/Write"
  1045. "1:15:37.7105043 PM","wwahost.exe","2812","RegCreateKey","HKCU\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe%5Cresources.pri","ACCESS DENIED","Desired Access: Read/Write"
  1046. "1:15:37.7105299 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\WWAHost.exe","BUFFER OVERFLOW","Information: Owner"
  1047. "1:15:37.7106878 PM","wwahost.exe","2812","RegCreateKey","HKCU\Software\Classes\Local Settings\MrtCache","ACCESS DENIED","Desired Access: Maximum Allowed"
  1048. "1:15:37.7107838 PM","wwahost.exe","2812","CreateFile","C:\ProgramData\PRICache","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
  1049. "1:15:37.7110289 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Query Value"
  1050. "1:15:37.7111385 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\AC\PRICache","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"
  1051. "1:15:37.7112517 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","REPARSE","Desired Access: Read"
  1052. "1:15:37.7112985 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\PackageRootFolder","BUFFER OVERFLOW","Length: 144"
  1053. "1:15:37.7116468 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\resources.pri","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1054. "1:15:37.7138978 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Query Value"
  1055. "1:15:37.7139880 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\Microsoft.BingNews_8wekyb3d8bbwe","REPARSE","Desired Access: Read/Write"
  1056. "1:15:37.7141145 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\ManifestLanguagesList","BUFFER OVERFLOW","Length: 144"
  1057. "1:15:37.7141269 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\ManifestLanguagesList","BUFFER OVERFLOW","Length: 144"
  1058. "1:15:37.7141921 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\OverrideLanguagesList","NAME NOT FOUND","Length: 144"
  1059. "1:15:37.7148840 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\windows.ui.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1060. "1:15:37.7149766 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\windows.ui.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1061. "1:15:37.7150639 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\windows.ui.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1062. "1:15:37.7852700 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.UI.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1063. "1:15:37.7856317 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\NInput.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1064. "1:15:37.7857307 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\NInput.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1065. "1:15:37.7858209 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\NInput.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1066. "1:15:37.8300799 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\ninput.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1067. "1:15:37.8305100 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\2c3e6d9f-8298-450f-8e5d-49b724f1216f","NAME NOT FOUND","Length: 524"
  1068. "1:15:37.8305526 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\954cc269-9c80-41b9-a2cd-ce4c8ccf59a2","NAME NOT FOUND","Length: 524"
  1069. "1:15:37.8306021 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\a3d95055-34cc-4e4a-b99f-ec88f5370495","NAME NOT FOUND","Length: 524"
  1070. "1:15:37.8306268 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\23e0d3d9-6334-4edd-9c80-54d3d7cfa8da","NAME NOT FOUND","Length: 524"
  1071. "1:15:37.8337698 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\DirectManipulation","NAME NOT FOUND","Desired Access: Query Value"
  1072. "1:15:37.8359767 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{C7EE80FC-8335-492C-81FB-11D2E10B2FF9}","NAME NOT FOUND","Desired Access: Read"
  1073. "1:15:37.8360509 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{C7EE80FC-8335-492C-81FB-11D2E10B2FF9}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
  1074. "1:15:37.8361324 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{C7EE80FC-8335-492C-81FB-11D2E10B2FF9}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1075. "1:15:37.8862136 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Resources.Core.ResourceManager\Server","NAME NOT FOUND","Length: 138"
  1076. "1:15:37.8862236 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Resources.Core.ResourceManager","BUFFER TOO SMALL","Query: Full, Length: 0"
  1077. "1:15:37.8970625 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.ApplicationView\Server","NAME NOT FOUND","Length: 138"
  1078. "1:15:37.8970727 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.ApplicationView","BUFFER TOO SMALL","Query: Full, Length: 0"
  1079. "1:15:37.8972560 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Scaling","NAME NOT FOUND","Desired Access: Query Value"
  1080. "1:15:37.8973088 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Scaling","NAME NOT FOUND","Desired Access: Query Value"
  1081. "1:15:37.8976997 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Query Value"
  1082. "1:15:37.8977999 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\Microsoft.BingNews_8wekyb3d8bbwe","REPARSE","Desired Access: Read/Write"
  1083. "1:15:37.8979418 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\ManifestLanguagesList","BUFFER OVERFLOW","Length: 144"
  1084. "1:15:37.8979542 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\ManifestLanguagesList","BUFFER OVERFLOW","Length: 144"
  1085. "1:15:37.8980085 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\OverrideLanguagesList","NAME NOT FOUND","Length: 144"
  1086. "1:15:37.8981821 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Query Value"
  1087. "1:15:37.8982530 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\Microsoft.BingNews_8wekyb3d8bbwe","REPARSE","Desired Access: Read"
  1088. "1:15:37.8985277 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.AccessibilitySettings\Server","NAME NOT FOUND","Length: 138"
  1089. "1:15:37.8985383 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.ViewManagement.AccessibilitySettings","BUFFER TOO SMALL","Query: Full, Length: 0"
  1090. "1:15:37.9027703 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.Core.CoreWindow\Server","NAME NOT FOUND","Length: 138"
  1091. "1:15:37.9027809 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.Core.CoreWindow","BUFFER TOO SMALL","Query: Full, Length: 0"
  1092. "1:15:37.9028890 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Query Value"
  1093. "1:15:37.9029747 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\Microsoft.BingNews_8wekyb3d8bbwe","REPARSE","Desired Access: Read/Write"
  1094. "1:15:37.9031078 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\ManifestLanguagesList","BUFFER OVERFLOW","Length: 144"
  1095. "1:15:37.9031187 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\ManifestLanguagesList","BUFFER OVERFLOW","Length: 144"
  1096. "1:15:37.9031561 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\OverrideLanguagesList","NAME NOT FOUND","Length: 144"
  1097. "1:15:37.9032162 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe","REPARSE","Desired Access: Read"
  1098. "1:15:37.9166776 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}","NAME NOT FOUND","Desired Access: Read"
  1099. "1:15:37.9167591 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}","NAME NOT FOUND","Desired Access: Read"
  1100. "1:15:37.9168409 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}","NAME NOT FOUND","Desired Access: Read"
  1101. "1:15:37.9169221 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1102. "1:15:37.9169523 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1103. "1:15:37.9170115 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1104. "1:15:37.9170730 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1105. "1:15:37.9171328 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
  1106. "1:15:37.9172131 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1107. "1:15:37.9172288 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InProcServer32\InprocServer32","NAME NOT FOUND","Length: 144"
  1108. "1:15:37.9172696 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1109. "1:15:37.9173278 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1110. "1:15:37.9173867 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1111. "1:15:37.9174588 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1112. "1:15:37.9174875 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1113. "1:15:37.9175319 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1114. "1:15:37.9175605 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1115. "1:15:37.9176662 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}","NAME NOT FOUND","Desired Access: Read"
  1116. "1:15:37.9177402 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1117. "1:15:37.9177909 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{25336920-03F9-11cf-8FD0-00AA00686F13}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1118. "1:15:37.9217470 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots","NAME NOT FOUND","Desired Access: Enumerate Sub Keys"
  1119. "1:15:37.9219091 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\wwahost.exe.Local","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1120. "1:15:37.9726070 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9200.16384_none_7762d5fd3178b04e\comctl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1121. "1:15:37.9734308 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9200.16384_none_7762d5fd3178b04e\comctl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1122. "1:15:37.9740357 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragScrollInset","NAME NOT FOUND","Length: 16"
  1123. "1:15:37.9741227 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragScrollDelay","NAME NOT FOUND","Length: 16"
  1124. "1:15:37.9742005 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay","NAME NOT FOUND","Length: 16"
  1125. "1:15:37.9742760 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragScrollInterval","NAME NOT FOUND","Length: 16"
  1126. "1:15:37.9743463 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IEharden","NAME NOT FOUND","Length: 144"
  1127. "1:15:37.9743877 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value"
  1128. "1:15:37.9752408 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\FlipAhead\NotificationDelay","NAME NOT FOUND","Length: 144"
  1129. "1:15:37.9753144 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Internet Explorer\Security\Floppy Access","NAME NOT FOUND","Desired Access: Read"
  1130. "1:15:37.9753588 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Security\Adv AddrBar Spoof Detection","NAME NOT FOUND","Desired Access: Read"
  1131. "1:15:37.9753956 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Internet Explorer\Security\Adv AddrBar Spoof Detection","NAME NOT FOUND","Desired Access: Read"
  1132. "1:15:37.9755396 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer","NAME NOT FOUND","Desired Access: Query Value"
  1133. "1:15:37.9755797 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer","NAME NOT FOUND","Desired Access: Query Value"
  1134. "1:15:37.9756380 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck","NAME NOT FOUND","Length: 144"
  1135. "1:15:37.9757325 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck","NAME NOT FOUND","Length: 144"
  1136. "1:15:37.9758910 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Secur32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1137. "1:15:37.9760039 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Secur32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1138. "1:15:37.9761107 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Secur32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1139. "1:15:37.9764597 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\secur32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1140. "1:15:37.9768385 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\SSPICLI.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1141. "1:15:37.9769417 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\SSPICLI.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1142. "1:15:37.9770441 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\SSPICLI.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1143. "1:15:37.9773861 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\sspicli.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1144. "1:15:37.9784550 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\","NAME NOT FOUND","Desired Access: Read"
  1145. "1:15:37.9784942 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\","NAME NOT FOUND","Desired Access: Read"
  1146. "1:15:37.9785304 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\","NAME NOT FOUND","Desired Access: Read"
  1147. "1:15:37.9785669 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\","NAME NOT FOUND","Desired Access: Read"
  1148. "1:15:37.9786038 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\","NAME NOT FOUND","Desired Access: Read"
  1149. "1:15:37.9787804 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0","NAME NOT FOUND","Desired Access: Read"
  1150. "1:15:37.9788181 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0","NAME NOT FOUND","Desired Access: Read"
  1151. "1:15:37.9788616 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0","NAME NOT FOUND","Desired Access: Read"
  1152. "1:15:37.9790590 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1","NAME NOT FOUND","Desired Access: Read"
  1153. "1:15:37.9791021 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1","NAME NOT FOUND","Desired Access: Read"
  1154. "1:15:37.9791423 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1","NAME NOT FOUND","Desired Access: Read"
  1155. "1:15:37.9792413 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","ACCESS DENIED","Desired Access: Read/Write"
  1156. "1:15:37.9792766 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\WWAHost.exe","BUFFER OVERFLOW","Information: Owner"
  1157. "1:15:37.9794692 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2","NAME NOT FOUND","Desired Access: Read"
  1158. "1:15:37.9795087 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2","NAME NOT FOUND","Desired Access: Read"
  1159. "1:15:37.9795685 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2","NAME NOT FOUND","Desired Access: Read"
  1160. "1:15:37.9797566 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3","NAME NOT FOUND","Desired Access: Read"
  1161. "1:15:37.9797949 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3","NAME NOT FOUND","Desired Access: Read"
  1162. "1:15:37.9798305 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3","NAME NOT FOUND","Desired Access: Read"
  1163. "1:15:37.9800385 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4","NAME NOT FOUND","Desired Access: Read"
  1164. "1:15:37.9800784 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4","NAME NOT FOUND","Desired Access: Read"
  1165. "1:15:37.9801143 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4","NAME NOT FOUND","Desired Access: Read"
  1166. "1:15:37.9802281 PM","wwahost.exe","2812","RegEnumKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones","NO MORE ENTRIES","Index: 5, Length: 288"
  1167. "1:15:37.9802812 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read"
  1168. "1:15:37.9803247 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read"
  1169. "1:15:37.9803627 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read"
  1170. "1:15:37.9803989 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read"
  1171. "1:15:37.9804370 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read"
  1172. "1:15:37.9806081 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0","NAME NOT FOUND","Desired Access: Read"
  1173. "1:15:37.9806504 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0","NAME NOT FOUND","Desired Access: Read"
  1174. "1:15:37.9806866 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0","NAME NOT FOUND","Desired Access: Read"
  1175. "1:15:37.9808701 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1","NAME NOT FOUND","Desired Access: Read"
  1176. "1:15:37.9809076 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1","NAME NOT FOUND","Desired Access: Read"
  1177. "1:15:37.9809432 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1","NAME NOT FOUND","Desired Access: Read"
  1178. "1:15:37.9810404 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","ACCESS DENIED","Desired Access: Read/Write"
  1179. "1:15:37.9810697 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\WWAHost.exe","BUFFER OVERFLOW","Information: Owner"
  1180. "1:15:37.9812309 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2","NAME NOT FOUND","Desired Access: Read"
  1181. "1:15:37.9812689 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2","NAME NOT FOUND","Desired Access: Read"
  1182. "1:15:37.9813042 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2","NAME NOT FOUND","Desired Access: Read"
  1183. "1:15:37.9815062 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3","NAME NOT FOUND","Desired Access: Read"
  1184. "1:15:37.9815469 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3","NAME NOT FOUND","Desired Access: Read"
  1185. "1:15:37.9815831 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3","NAME NOT FOUND","Desired Access: Read"
  1186. "1:15:37.9817670 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4","NAME NOT FOUND","Desired Access: Read"
  1187. "1:15:37.9818041 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4","NAME NOT FOUND","Desired Access: Read"
  1188. "1:15:37.9818424 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4","NAME NOT FOUND","Desired Access: Read"
  1189. "1:15:37.9819523 PM","wwahost.exe","2812","RegEnumKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones","NO MORE ENTRIES","Index: 5, Length: 288"
  1190. "1:15:37.9819985 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read"
  1191. "1:15:37.9820353 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read"
  1192. "1:15:37.9820718 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read"
  1193. "1:15:37.9821165 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read"
  1194. "1:15:37.9821784 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\","NAME NOT FOUND","Desired Access: Read"
  1195. "1:15:37.9823852 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0","NAME NOT FOUND","Desired Access: Read"
  1196. "1:15:37.9824314 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0","NAME NOT FOUND","Desired Access: Read"
  1197. "1:15:37.9824694 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0","NAME NOT FOUND","Desired Access: Read"
  1198. "1:15:37.9826553 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1","NAME NOT FOUND","Desired Access: Read"
  1199. "1:15:37.9826934 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1","NAME NOT FOUND","Desired Access: Read"
  1200. "1:15:37.9827353 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1","NAME NOT FOUND","Desired Access: Read"
  1201. "1:15:37.9828319 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","ACCESS DENIED","Desired Access: Read/Write"
  1202. "1:15:37.9828612 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\WWAHost.exe","BUFFER OVERFLOW","Information: Owner"
  1203. "1:15:37.9830197 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2","NAME NOT FOUND","Desired Access: Read"
  1204. "1:15:37.9830604 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2","NAME NOT FOUND","Desired Access: Read"
  1205. "1:15:37.9830988 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2","NAME NOT FOUND","Desired Access: Read"
  1206. "1:15:37.9833098 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3","NAME NOT FOUND","Desired Access: Read"
  1207. "1:15:37.9833514 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3","NAME NOT FOUND","Desired Access: Read"
  1208. "1:15:37.9833882 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3","NAME NOT FOUND","Desired Access: Read"
  1209. "1:15:37.9835959 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4","NAME NOT FOUND","Desired Access: Read"
  1210. "1:15:37.9836352 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4","NAME NOT FOUND","Desired Access: Read"
  1211. "1:15:37.9836711 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4","NAME NOT FOUND","Desired Access: Read"
  1212. "1:15:37.9837740 PM","wwahost.exe","2812","RegEnumKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones","NO MORE ENTRIES","Index: 5, Length: 288"
  1213. "1:15:37.9838323 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}","NAME NOT FOUND","Desired Access: Read"
  1214. "1:15:37.9838607 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}","NAME NOT FOUND","Desired Access: Read"
  1215. "1:15:37.9839449 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}","NAME NOT FOUND","Desired Access: Read"
  1216. "1:15:37.9840415 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1217. "1:15:37.9840801 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1218. "1:15:37.9841676 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1219. "1:15:37.9842491 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1220. "1:15:37.9843500 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
  1221. "1:15:37.9844792 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1222. "1:15:37.9845003 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InProcServer32\InprocServer32","NAME NOT FOUND","Length: 144"
  1223. "1:15:37.9845549 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1224. "1:15:37.9846346 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1225. "1:15:37.9847222 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1226. "1:15:37.9848194 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1227. "1:15:37.9848583 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1228. "1:15:37.9849244 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1229. "1:15:37.9849636 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1230. "1:15:37.9850805 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}","NAME NOT FOUND","Desired Access: Read"
  1231. "1:15:37.9851795 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1232. "1:15:37.9852226 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1233. "1:15:37.9854092 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer\Zoom","NAME NOT FOUND","Desired Access: Read"
  1234. "1:15:37.9854493 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Zoom","NAME NOT FOUND","Desired Access: Read"
  1235. "1:15:37.9856265 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Zoom\ZoomDisabled","NAME NOT FOUND","Length: 144"
  1236. "1:15:37.9856576 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Internet Explorer\Zoom","NAME NOT FOUND","Desired Access: Read"
  1237. "1:15:37.9857989 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  1238. "1:15:37.9858614 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  1239. "1:15:37.9858994 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
  1240. "1:15:37.9859293 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  1241. "1:15:37.9859507 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  1242. "1:15:37.9859891 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
  1243. "1:15:37.9861590 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\MinimumSystemTimerResolution","NAME NOT FOUND","Length: 144"
  1244. "1:15:37.9862236 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\MinimumSystemTimerResolution","NAME NOT FOUND","Length: 144"
  1245. "1:15:37.9862432 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\RenderingLoopMaxTime","NAME NOT FOUND","Length: 144"
  1246. "1:15:37.9863431 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main","NAME NOT FOUND","Desired Access: Read"
  1247. "1:15:37.9864050 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\PageSetup\Print_Background","NAME NOT FOUND","Length: 144"
  1248. "1:15:37.9864524 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\MenuExt","NAME NOT FOUND","Desired Access: Read"
  1249. "1:15:37.9865074 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Nls\CodePage","REPARSE","Desired Access: Read"
  1250. "1:15:37.9868430 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSize","NAME NOT FOUND","Length: 144"
  1251. "1:15:37.9868844 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSizePrivate","NAME NOT FOUND","Length: 144"
  1252. "1:15:37.9869598 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\International\Scripts","NAME NOT FOUND","Desired Access: Read"
  1253. "1:15:37.9872059 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\AcceptLanguage","NAME NOT FOUND","Length: 144"
  1254. "1:15:37.9872717 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TravelLog","NAME NOT FOUND","Desired Access: Read"
  1255. "1:15:37.9873091 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\TravelLog","NAME NOT FOUND","Desired Access: Read"
  1256. "1:15:37.9873523 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TravelLog","NAME NOT FOUND","Desired Access: Read"
  1257. "1:15:37.9873861 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\TravelLog","NAME NOT FOUND","Desired Access: Read"
  1258. "1:15:37.9874238 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TravelLog","NAME NOT FOUND","Desired Access: Read"
  1259. "1:15:37.9874609 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\TravelLog","NAME NOT FOUND","Desired Access: Read"
  1260. "1:15:37.9877459 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\MaximumAllowedAllocationSize","NAME NOT FOUND","Length: 144"
  1261. "1:15:37.9879324 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}","NAME NOT FOUND","Desired Access: Read"
  1262. "1:15:37.9879629 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}","NAME NOT FOUND","Desired Access: Read"
  1263. "1:15:37.9880716 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}","NAME NOT FOUND","Desired Access: Read"
  1264. "1:15:37.9881697 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1265. "1:15:37.9882053 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1266. "1:15:37.9882895 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1267. "1:15:37.9883879 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1268. "1:15:37.9884987 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
  1269. "1:15:37.9886294 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1270. "1:15:37.9886494 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InProcServer32\InprocServer32","NAME NOT FOUND","Length: 144"
  1271. "1:15:37.9886970 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1272. "1:15:37.9887680 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1273. "1:15:37.9888389 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1274. "1:15:37.9889171 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1275. "1:15:37.9890004 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1276. "1:15:37.9890451 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1277. "1:15:37.9891061 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1278. "1:15:37.9891393 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1279. "1:15:37.9892350 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}","NAME NOT FOUND","Desired Access: Read"
  1280. "1:15:37.9893122 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1281. "1:15:37.9893524 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1282. "1:15:38.0138890 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\msimtf.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1283. "1:15:38.0149271 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}","NAME NOT FOUND","Desired Access: Read"
  1284. "1:15:38.0149570 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}","NAME NOT FOUND","Desired Access: Read"
  1285. "1:15:38.0150343 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}","NAME NOT FOUND","Desired Access: Read"
  1286. "1:15:38.0151267 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1287. "1:15:38.0151614 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1288. "1:15:38.0152320 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1289. "1:15:38.0152498 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\(Default)","NAME NOT FOUND","Length: 144"
  1290. "1:15:38.0152975 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
  1291. "1:15:38.0154131 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1292. "1:15:38.0154502 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InProcServer32\InprocServer32","NAME NOT FOUND","Length: 144"
  1293. "1:15:38.0155173 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1294. "1:15:38.0155867 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1295. "1:15:38.0156555 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1296. "1:15:38.0157243 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1297. "1:15:38.0158073 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1298. "1:15:38.0158409 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1299. "1:15:38.0159024 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1300. "1:15:38.0159368 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1301. "1:15:38.0160331 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}","NAME NOT FOUND","Desired Access: Read"
  1302. "1:15:38.0161131 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1303. "1:15:38.0161506 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{54E211B6-3650-4F75-8334-FA359598E1C5}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1304. "1:15:38.0162324 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}","NAME NOT FOUND","Desired Access: Read"
  1305. "1:15:38.0162553 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}","NAME NOT FOUND","Desired Access: Read"
  1306. "1:15:38.0163232 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}","NAME NOT FOUND","Desired Access: Read"
  1307. "1:15:38.0164105 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1308. "1:15:38.0164446 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1309. "1:15:38.0165152 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1310. "1:15:38.0165330 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\(Default)","NAME NOT FOUND","Length: 144"
  1311. "1:15:38.0165822 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
  1312. "1:15:38.0166746 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1313. "1:15:38.0166933 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InProcServer32\InprocServer32","NAME NOT FOUND","Length: 144"
  1314. "1:15:38.0167428 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1315. "1:15:38.0168128 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1316. "1:15:38.0168832 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1317. "1:15:38.0169526 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1318. "1:15:38.0170356 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1319. "1:15:38.0170694 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1320. "1:15:38.0171229 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1321. "1:15:38.0171564 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1322. "1:15:38.0172475 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}","NAME NOT FOUND","Desired Access: Read"
  1323. "1:15:38.0173266 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1324. "1:15:38.0173674 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{79DEA627-A08A-43AC-8EF5-6900B9299126}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1325. "1:15:38.0203069 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\powrprof.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1326. "1:15:38.0207760 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\dcomp.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1327. "1:15:38.0208777 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\dcomp.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1328. "1:15:38.0209604 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\DXGI","NAME NOT FOUND","Desired Access: Read"
  1329. "1:15:38.0209725 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\dcomp.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1330. "1:15:38.0209897 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\DXGI","NAME NOT FOUND","Desired Access: Read"
  1331. "1:15:38.0212852 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dcomp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1332. "1:15:38.0215689 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\UseSWRender","NAME NOT FOUND","Length: 144"
  1333. "1:15:38.0215874 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\UseSWRender","NAME NOT FOUND","Length: 144"
  1334. "1:15:38.0217724 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\CONTROL\VIDEO\{E41E0436-9CB3-4E45-8C09-ED35631B9477}\0000","REPARSE","Desired Access: Read"
  1335. "1:15:38.0218276 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000\PruningMode","NAME NOT FOUND","Length: 52"
  1336. "1:15:38.0218916 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Enum\PCI\VEN_1002&DEV_675D&SUBSYS_2B221028&REV_00\4&1136de53&0&0008\HardwareID","BUFFER OVERFLOW","Length: 271"
  1337. "1:15:38.0221222 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\CONTROL\VIDEO\{E41E0436-9CB3-4E45-8C09-ED35631B9477}\0001","REPARSE","Desired Access: Read"
  1338. "1:15:38.0221760 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000\PruningMode","NAME NOT FOUND","Length: 52"
  1339. "1:15:38.0222255 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Enum\PCI\VEN_1002&DEV_675D&SUBSYS_2B221028&REV_00\4&1136de53&0&0008\HardwareID","BUFFER OVERFLOW","Length: 271"
  1340. "1:15:38.0904415 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Manipulation","NAME NOT FOUND","Desired Access: Query Value"
  1341. "1:15:38.0917941 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\mshtml.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1342. "1:15:38.0925645 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}","NAME NOT FOUND","Desired Access: Read"
  1343. "1:15:38.0925983 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}","NAME NOT FOUND","Desired Access: Read"
  1344. "1:15:38.0926753 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}","NAME NOT FOUND","Desired Access: Read"
  1345. "1:15:38.0927969 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1346. "1:15:38.0928358 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1347. "1:15:38.0929038 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1348. "1:15:38.0929207 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\(Default)","NAME NOT FOUND","Length: 144"
  1349. "1:15:38.0929647 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
  1350. "1:15:38.0930601 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1351. "1:15:38.0930776 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\InProcServer32\InprocServer32","NAME NOT FOUND","Length: 144"
  1352. "1:15:38.0931229 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1353. "1:15:38.0931866 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1354. "1:15:38.0932678 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1355. "1:15:38.0933575 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1356. "1:15:38.0933888 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1357. "1:15:38.0934362 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1358. "1:15:38.0934716 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1359. "1:15:38.0935654 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}","NAME NOT FOUND","Desired Access: Read"
  1360. "1:15:38.0936382 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1361. "1:15:38.0936841 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{D5120AA3-46BA-44C5-822D-CA8092C1FC72}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1362. "1:15:38.0939711 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wwahost.exe","NAME NOT FOUND","Desired Access: Query Value"
  1363. "1:15:38.0940071 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}","NAME NOT FOUND","Desired Access: Read"
  1364. "1:15:38.0940300 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}","NAME NOT FOUND","Desired Access: Read"
  1365. "1:15:38.0940892 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}","NAME NOT FOUND","Desired Access: Read"
  1366. "1:15:38.0941679 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1367. "1:15:38.0941975 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1368. "1:15:38.0942561 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1369. "1:15:38.0943168 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1370. "1:15:38.0943774 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
  1371. "1:15:38.0944064 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
  1372. "1:15:38.0944686 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1373. "1:15:38.0944991 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1374. "1:15:38.0945441 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1375. "1:15:38.0945727 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{228826AF-02E1-4226-A9E0-99A855E455A6}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1376. "1:15:38.1073145 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\DXGI","NAME NOT FOUND","Desired Access: Read"
  1377. "1:15:38.1073541 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\DXGI","NAME NOT FOUND","Desired Access: Read"
  1378. "1:15:38.1090457 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\OLE\MaximumAllowedAllocationSize","NAME NOT FOUND","Length: 144"
  1379. "1:15:38.1091369 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{1A887A1C-8182-4463-B485-38A701B839BA}","NAME NOT FOUND","Desired Access: Read"
  1380. "1:15:38.1092220 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{1A887A1C-8182-4463-B485-38A701B839BA}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
  1381. "1:15:38.1093098 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{1A887A1C-8182-4463-B485-38A701B839BA}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1382. "1:15:38.1101191 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{1C613948-2128-4731-A329-EF818F969E04}","NAME NOT FOUND","Desired Access: Read"
  1383. "1:15:38.1101997 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{1C613948-2128-4731-A329-EF818F969E04}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
  1384. "1:15:38.1102845 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{1C613948-2128-4731-A329-EF818F969E04}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1385. "1:15:38.1108632 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Query Value"
  1386. "1:15:38.1109634 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\Microsoft.BingNews_8wekyb3d8bbwe","REPARSE","Desired Access: Read/Write"
  1387. "1:15:38.1111189 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\ManifestLanguagesList","BUFFER OVERFLOW","Length: 144"
  1388. "1:15:38.1111349 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\ManifestLanguagesList","BUFFER OVERFLOW","Length: 144"
  1389. "1:15:38.1111880 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.bingnews_8wekyb3d8bbwe\OverrideLanguagesList","NAME NOT FOUND","Length: 144"
  1390. "1:15:38.1112520 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main","NAME NOT FOUND","Desired Access: Read"
  1391. "1:15:38.1113054 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\PageSetup\Print_Background","NAME NOT FOUND","Length: 144"
  1392. "1:15:38.1113543 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\MenuExt","NAME NOT FOUND","Desired Access: Read"
  1393. "1:15:38.1114071 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSize","NAME NOT FOUND","Length: 144"
  1394. "1:15:38.1114256 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSizePrivate","NAME NOT FOUND","Length: 144"
  1395. "1:15:38.1115152 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\AcceptLanguage","NAME NOT FOUND","Length: 144"
  1396. "1:15:38.1117612 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.WebUI.WebUIApplication\Server","NAME NOT FOUND","Length: 138"
  1397. "1:15:38.1117709 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.UI.WebUI.WebUIApplication","BUFFER TOO SMALL","Query: Full, Length: 0"
  1398. "1:15:38.1416414 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WwaApi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1399. "1:15:38.1420266 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\565e0113-343e-43a3-a927-a17037182ff2","NAME NOT FOUND","Length: 524"
  1400. "1:15:38.1530810 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}","NAME NOT FOUND","Desired Access: Read"
  1401. "1:15:38.1531226 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}","NAME NOT FOUND","Desired Access: Read"
  1402. "1:15:38.1532086 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}","NAME NOT FOUND","Desired Access: Read"
  1403. "1:15:38.1533004 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1404. "1:15:38.1533333 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1405. "1:15:38.1534006 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1406. "1:15:38.1534978 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1407. "1:15:38.1535651 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
  1408. "1:15:38.1536536 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1409. "1:15:38.1536708 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\InProcServer32\InprocServer32","NAME NOT FOUND","Length: 144"
  1410. "1:15:38.1537143 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1411. "1:15:38.1537855 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1412. "1:15:38.1538501 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1413. "1:15:38.1539340 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1414. "1:15:38.1539657 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1415. "1:15:38.1540137 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1416. "1:15:38.1540442 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1417. "1:15:38.1541369 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}","NAME NOT FOUND","Desired Access: Read"
  1418. "1:15:38.1542093 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1419. "1:15:38.1542485 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{4D3BD4B7-AD22-4DC4-B889-311DAE0D8AEB}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1420. "1:15:38.1546307 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize","NAME NOT FOUND","Length: 144"
  1421. "1:15:38.1547016 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize","NAME NOT FOUND","Length: 144"
  1422. "1:15:38.1547457 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize","NAME NOT FOUND","Length: 144"
  1423. "1:15:38.1547910 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize","NAME NOT FOUND","Length: 144"
  1424. "1:15:38.1548933 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Internet Explorer","NAME NOT FOUND","Desired Access: Read"
  1425. "1:15:38.1549298 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer","NAME NOT FOUND","Desired Access: Read"
  1426. "1:15:38.1550850 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\FrameTabWindow","NAME NOT FOUND","Length: 144"
  1427. "1:15:38.1551097 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FrameTabWindow","NAME NOT FOUND","Length: 144"
  1428. "1:15:38.1551294 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\FrameMerging","NAME NOT FOUND","Length: 144"
  1429. "1:15:38.1551463 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FrameMerging","NAME NOT FOUND","Length: 144"
  1430. "1:15:38.1551614 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\SessionMerging","NAME NOT FOUND","Length: 144"
  1431. "1:15:38.1551734 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\SessionMerging","NAME NOT FOUND","Length: 144"
  1432. "1:15:38.1551855 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\AdminTabProcs","NAME NOT FOUND","Length: 144"
  1433. "1:15:38.1551967 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\AdminTabProcs","NAME NOT FOUND","Length: 144"
  1434. "1:15:38.1552190 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\TabProcGrowth","NAME NOT FOUND","Length: 144"
  1435. "1:15:38.1558487 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\tzres.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1436. "1:15:38.1559598 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\tzres.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1437. "1:15:38.1560585 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\tzres.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1438. "1:15:38.1563987 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\tzres.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1439. "1:15:38.1566619 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\tzres.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1440. "1:15:38.1568986 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\tzres.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1441. "1:15:38.1569921 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\tzres.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1442. "1:15:38.1570836 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\tzres.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1443. "1:15:38.1573858 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\tzres.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1444. "1:15:38.1576297 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\tzres.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1445. "1:15:38.1579062 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSize","NAME NOT FOUND","Length: 144"
  1446. "1:15:38.1579282 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSizePrivate","NAME NOT FOUND","Length: 144"
  1447. "1:15:38.1580097 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\IEDevTools\Options","NAME NOT FOUND","Desired Access: Read"
  1448. "1:15:38.1580707 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\IEDevTools\Options","NAME NOT FOUND","Desired Access: Read"
  1449. "1:15:38.1585609 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\text/xml\UserChoice","NAME NOT FOUND","Desired Access: Query Value"
  1450. "1:15:38.1586720 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\MIME\Database\Content Type\text/xml","NAME NOT FOUND","Desired Access: Read"
  1451. "1:15:38.1587795 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\MIME\Database\Content Type\text/xml","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1452. "1:15:38.1973972 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\Autogen\JSByteCodeCache_64","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1453. "1:15:38.2018041 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\IsTextPlainHonored","NAME NOT FOUND","Length: 144"
  1454. "1:15:38.2019740 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\default.html","END OF FILE","Offset: 3,296, Length: 4,896"
  1455. "1:15:38.2020142 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\default.html","END OF FILE","Offset: 3,296, Length: 4,896"
  1456. "1:15:38.2030502 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck","NAME NOT FOUND","Length: 144"
  1457. "1:15:38.2031247 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck","NAME NOT FOUND","Length: 144"
  1458. "1:15:38.2033834 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\PROTOCOLS\Name-Space Handler\","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1459. "1:15:38.2034918 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\PROTOCOLS\Name-Space Handler","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1460. "1:15:38.2035271 PM","wwahost.exe","2812","RegEnumKey","HKCR\PROTOCOLS\Name-Space Handler","NO MORE ENTRIES","Index: 1, Length: 288"
  1461. "1:15:38.2067860 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\PredictedViewExpansion","NAME NOT FOUND","Length: 144"
  1462. "1:15:38.2068204 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\ContentLayerCacheExpansion","NAME NOT FOUND","Length: 144"
  1463. "1:15:38.2068448 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\PredictedViewChangeThreshold","NAME NOT FOUND","Length: 144"
  1464. "1:15:38.2068690 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Main\PredictedViewChangeThresholdPaint","NAME NOT FOUND","Length: 144"
  1465. "1:15:38.2074051 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\microsoft.system.package.metadata\Autogen\JSByteCodeCache_64","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1466. "1:15:38.2109818 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\common\dynamicpano\js\dynamicPanoAuth.js","PATH NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1467. "1:15:38.2116827 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Read"
  1468. "1:15:38.2118092 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1469. "1:15:38.2118826 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1470. "1:15:38.2653636 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\css\ui-light.css","END OF FILE","Offset: 114,370, Length: 318"
  1471. "1:15:38.2660902 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1472. "1:15:38.2661599 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1473. "1:15:38.2801900 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\common\css\und-latn\immersive.css","END OF FILE","Offset: 114,496, Length: 192"
  1474. "1:15:38.2808979 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1475. "1:15:38.2809691 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1476. "1:15:38.2934423 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\common\css\und-latn\common.css","END OF FILE","Offset: 119,307, Length: 3,573"
  1477. "1:15:38.2940481 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1478. "1:15:38.2941269 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1479. "1:15:38.3094556 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\css\und-latn\default.css","END OF FILE","Offset: 239,471, Length: 6,289"
  1480. "1:15:38.3100675 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1481. "1:15:38.3101369 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1482. "1:15:38.3249027 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\css\und-latn\partners.css","END OF FILE","Offset: 2,018, Length: 6,174"
  1483. "1:15:38.3255816 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1484. "1:15:38.3256507 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1485. "1:15:38.3601701 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\css\und-latn\apNewsTheme.css","END OF FILE","Offset: 42,599, Length: 6,553"
  1486. "1:15:38.3608412 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1487. "1:15:38.3609157 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1488. "1:15:38.3945981 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\nytshared\und-latn\nytTheme.css","END OF FILE","Offset: 127,530, Length: 3,542"
  1489. "1:15:38.3952875 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1490. "1:15:38.3953630 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\.css","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1491. "1:15:38.4117226 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\wsjshared\und-latn\wsjTheme.css","END OF FILE","Offset: 90,927, Length: 7,377"
  1492. "1:15:38.4127033 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\.png\Content Type","NAME NOT FOUND","Length: 144"
  1493. "1:15:38.4127987 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\.png\Content Type","NAME NOT FOUND","Length: 144"
  1494. "1:15:38.4135712 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Description","NAME NOT FOUND","Length: 144"
  1495. "1:15:38.4135947 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\ParsingName","NAME NOT FOUND","Length: 144"
  1496. "1:15:38.4136044 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\InfoTip","NAME NOT FOUND","Length: 144"
  1497. "1:15:38.4136137 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\LocalizedName","NAME NOT FOUND","Length: 144"
  1498. "1:15:38.4136234 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Icon","NAME NOT FOUND","Length: 144"
  1499. "1:15:38.4136328 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Security","NAME NOT FOUND","Length: 144"
  1500. "1:15:38.4136421 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\StreamResource","NAME NOT FOUND","Length: 144"
  1501. "1:15:38.4136515 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\StreamResourceType","NAME NOT FOUND","Length: 144"
  1502. "1:15:38.4136741 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Roamable","NAME NOT FOUND","Length: 144"
  1503. "1:15:38.4136835 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PreCreate","NAME NOT FOUND","Length: 144"
  1504. "1:15:38.4136928 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Stream","NAME NOT FOUND","Length: 144"
  1505. "1:15:38.4137022 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PublishExpandedPath","NAME NOT FOUND","Length: 144"
  1506. "1:15:38.4137115 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Attributes","NAME NOT FOUND","Length: 144"
  1507. "1:15:38.4137209 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\FolderTypeID","NAME NOT FOUND","Length: 144"
  1508. "1:15:38.4137303 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\InitFolderHandler","NAME NOT FOUND","Length: 144"
  1509. "1:15:38.4137565 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PropertyBag","NAME NOT FOUND","Desired Access: Read"
  1510. "1:15:38.4138975 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\ParentFolder","NAME NOT FOUND","Length: 144"
  1511. "1:15:38.4139071 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\Description","NAME NOT FOUND","Length: 144"
  1512. "1:15:38.4139298 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\ParsingName","NAME NOT FOUND","Length: 144"
  1513. "1:15:38.4139391 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\InfoTip","NAME NOT FOUND","Length: 144"
  1514. "1:15:38.4139485 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\LocalizedName","NAME NOT FOUND","Length: 144"
  1515. "1:15:38.4139579 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\Icon","NAME NOT FOUND","Length: 144"
  1516. "1:15:38.4139672 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\Security","NAME NOT FOUND","Length: 144"
  1517. "1:15:38.4139766 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\StreamResource","NAME NOT FOUND","Length: 144"
  1518. "1:15:38.4139859 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\StreamResourceType","NAME NOT FOUND","Length: 144"
  1519. "1:15:38.4140080 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\Roamable","NAME NOT FOUND","Length: 144"
  1520. "1:15:38.4140173 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\PreCreate","NAME NOT FOUND","Length: 144"
  1521. "1:15:38.4140267 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\Stream","NAME NOT FOUND","Length: 144"
  1522. "1:15:38.4140490 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\Attributes","NAME NOT FOUND","Length: 144"
  1523. "1:15:38.4140584 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\FolderTypeID","NAME NOT FOUND","Length: 144"
  1524. "1:15:38.4140677 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\InitFolderHandler","NAME NOT FOUND","Length: 144"
  1525. "1:15:38.4140919 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\PropertyBag","NAME NOT FOUND","Desired Access: Read"
  1526. "1:15:38.4141504 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Read"
  1527. "1:15:38.4143240 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders","NAME NOT FOUND","Desired Access: Query Value"
  1528. "1:15:38.4146558 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\KnownFolderSettings","NAME NOT FOUND","Desired Access: Query Value"
  1529. "1:15:38.4146871 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\KnownFolderSettings","NAME NOT FOUND","Desired Access: Query Value"
  1530. "1:15:38.4205885 PM","wwahost.exe","2812","CreateFileMapping","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\AC\INetCache\MSIMGSIZ.DAT","FILE LOCKED WITH WRITERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1531. "1:15:38.4209136 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}","NAME NOT FOUND","Desired Access: Read"
  1532. "1:15:38.4209501 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}","NAME NOT FOUND","Desired Access: Read"
  1533. "1:15:38.4210301 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\AppHost","NAME NOT FOUND","Desired Access: Query Value"
  1534. "1:15:38.4210491 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}","NAME NOT FOUND","Desired Access: Read"
  1535. "1:15:38.4211071 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\AppHost\EnableWebContentEvaluation","NAME NOT FOUND","Length: 144"
  1536. "1:15:38.4211575 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1537. "1:15:38.4212031 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1538. "1:15:38.4212610 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\AppHost","NAME NOT FOUND","Desired Access: Query Value"
  1539. "1:15:38.4212979 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1540. "1:15:38.4213202 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\(Default)","NAME NOT FOUND","Length: 144"
  1541. "1:15:38.4213413 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\AppHost\EnableWebContentEvaluation","NAME NOT FOUND","Length: 144"
  1542. "1:15:38.4214114 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
  1543. "1:15:38.4214980 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1544. "1:15:38.4215137 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InProcServer32\InprocServer32","NAME NOT FOUND","Length: 144"
  1545. "1:15:38.4215490 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1546. "1:15:38.4216009 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1547. "1:15:38.4216526 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1548. "1:15:38.4217072 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InProcServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1549. "1:15:38.4217733 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1550. "1:15:38.4217990 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1551. "1:15:38.4218394 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1552. "1:15:38.4218720 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1553. "1:15:38.4219786 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}","NAME NOT FOUND","Desired Access: Read"
  1554. "1:15:38.4220250 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck","NAME NOT FOUND","Length: 144"
  1555. "1:15:38.4220447 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1556. "1:15:38.4220736 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{317D06E8-5F24-433D-BDF7-79CE68D8ABC2}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1557. "1:15:38.4220981 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck","NAME NOT FOUND","Length: 144"
  1558. "1:15:38.4223559 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\AppHost","NAME NOT FOUND","Desired Access: Query Value"
  1559. "1:15:38.4224084 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\AppHost\EnableWebContentEvaluation","NAME NOT FOUND","Length: 144"
  1560. "1:15:38.4224470 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WindowsCodecs.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1561. "1:15:38.4225183 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\AppHost","NAME NOT FOUND","Desired Access: Query Value"
  1562. "1:15:38.4225759 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\AppHost\EnableWebContentEvaluation","NAME NOT FOUND","Length: 144"
  1563. "1:15:38.4227172 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnIntranet","NAME NOT FOUND","Length: 144"
  1564. "1:15:38.4227700 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnIntranet","NAME NOT FOUND","Length: 144"
  1565. "1:15:38.4228198 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnIntranet","NAME NOT FOUND","Length: 144"
  1566. "1:15:38.4228666 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance","NAME NOT FOUND","Desired Access: Read"
  1567. "1:15:38.4229424 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","NAME NOT FOUND","Desired Access: Query Value"
  1568. "1:15:38.4229629 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled","NAME NOT FOUND","Desired Access: Read"
  1569. "1:15:38.4229747 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\","NAME NOT FOUND","Desired Access: Query Value"
  1570. "1:15:38.4229816 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled","NAME NOT FOUND","Desired Access: Read"
  1571. "1:15:38.4230656 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}","NAME NOT FOUND","Desired Access: Read"
  1572. "1:15:38.4230906 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}","NAME NOT FOUND","Desired Access: Read"
  1573. "1:15:38.4231582 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}","NAME NOT FOUND","Desired Access: Read"
  1574. "1:15:38.4232470 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1575. "1:15:38.4232877 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1576. "1:15:38.4233505 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1577. "1:15:38.4234133 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1578. "1:15:38.4234755 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
  1579. "1:15:38.4235715 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1580. "1:15:38.4235893 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\InprocServer32\InprocServer32","NAME NOT FOUND","Length: 144"
  1581. "1:15:38.4236424 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1582. "1:15:38.4237052 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1583. "1:15:38.4237677 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1584. "1:15:38.4238428 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1585. "1:15:38.4238736 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1586. "1:15:38.4239216 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1587. "1:15:38.4239518 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1588. "1:15:38.4240381 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}","NAME NOT FOUND","Desired Access: Read"
  1589. "1:15:38.4241218 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1590. "1:15:38.4241553 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{16D51579-A30B-4C8B-A276-0FF4DC41E755}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1591. "1:15:38.4361983 PM","wwahost.exe","2812","ReadFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\images\splash.scale-100.png","END OF FILE","Offset: 2,452, Length: 1,796"
  1592. "1:15:38.5138619 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\jscript9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1593. "1:15:38.5144028 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\JScript9","NAME NOT FOUND","Desired Access: Read"
  1594. "1:15:38.5145589 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{16D51579-A30B-4C8B-A276-0FF4DC41E755}","NAME NOT FOUND","Desired Access: Read"
  1595. "1:15:38.5311385 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{16D51579-A30B-4C8B-A276-0FF4DC41E755}","NAME NOT FOUND","Desired Access: Read"
  1596. "1:15:38.5318482 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Locale","REPARSE","Desired Access: Read"
  1597. "1:15:38.5319049 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts","REPARSE","Desired Access: Read"
  1598. "1:15:38.5319420 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Language Groups","REPARSE","Desired Access: Read"
  1599. "1:15:38.5325938 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}","NAME NOT FOUND","Desired Access: Read"
  1600. "1:15:38.5326257 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}","NAME NOT FOUND","Desired Access: Read"
  1601. "1:15:38.5327021 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}","NAME NOT FOUND","Desired Access: Read"
  1602. "1:15:38.5327897 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1603. "1:15:38.5328223 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  1604. "1:15:38.5328878 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1605. "1:15:38.5329536 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1606. "1:15:38.5330182 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
  1607. "1:15:38.5331181 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1608. "1:15:38.5331371 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\InprocServer32\InprocServer32","NAME NOT FOUND","Length: 144"
  1609. "1:15:38.5331824 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1610. "1:15:38.5332479 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1611. "1:15:38.5333140 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1612. "1:15:38.5334009 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1613. "1:15:38.5334341 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  1614. "1:15:38.5334854 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1615. "1:15:38.5335180 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  1616. "1:15:38.5336140 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}","NAME NOT FOUND","Desired Access: Read"
  1617. "1:15:38.5336925 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1618. "1:15:38.5337272 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{842A1268-6E6A-465C-868F-8BC445B9828F}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  1619. "1:15:38.6047671 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Foundation.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1620. "1:15:38.6053642 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Foundation.Uri.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1621. "1:15:38.6069457 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri\Server","NAME NOT FOUND","Length: 138"
  1622. "1:15:38.6069605 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Foundation.Uri","BUFFER TOO SMALL","Query: Full, Length: 0"
  1623. "1:15:38.6185126 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.Networking.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1624. "1:15:38.6191305 PM","wwahost.exe","2812","CreateFileMapping","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1625. "1:15:38.6197279 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.Networking.NetworkManager.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1626. "1:15:38.6201994 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Platform.Networking.NetworkManager","NAME NOT FOUND","Desired Access: Read"
  1627. "1:15:38.6202438 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Networking.NetworkManager","NAME NOT FOUND","Desired Access: Read"
  1628. "1:15:38.6202706 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Networking.NetworkManager","NAME NOT FOUND","Desired Access: Read"
  1629. "1:15:38.6202933 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\ActivatableClassId\Platform.Networking.NetworkManager","NAME NOT FOUND","Desired Access: Read"
  1630. "1:15:38.6203947 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{205A397A-0A27-5ACC-A7B7-2149C760480E}","NAME NOT FOUND","Desired Access: Read"
  1631. "1:15:38.6204252 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{205A397A-0A27-5ACC-A7B7-2149C760480E}","NAME NOT FOUND","Desired Access: Read"
  1632. "1:15:38.6205290 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{205A397A-0A27-5ACC-A7B7-2149C760480E}","NAME NOT FOUND","Desired Access: Read"
  1633. "1:15:38.6205637 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{205A397A-0A27-5ACC-A7B7-2149C760480E}","NAME NOT FOUND","Desired Access: Read"
  1634. "1:15:38.6206709 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Wow6432Node\CLSID\{205A397A-0A27-5ACC-A7B7-2149C760480E}","NAME NOT FOUND","Desired Access: Read"
  1635. "1:15:38.6206960 PM","wwahost.exe","2812","RegOpenKey","HKCR\Wow6432Node\CLSID\{205A397A-0A27-5ACC-A7B7-2149C760480E}","NAME NOT FOUND","Desired Access: Read"
  1636. "1:15:38.6290258 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Platform.Networking.NetworkManager","NAME NOT FOUND","Desired Access: Read"
  1637. "1:15:38.6290557 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Networking.NetworkManager","NAME NOT FOUND","Desired Access: Read"
  1638. "1:15:38.6291758 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Networking.NetworkManager\Server","NAME NOT FOUND","Length: 138"
  1639. "1:15:38.6291888 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Networking.NetworkManager","BUFFER TOO SMALL","Query: Full, Length: 0"
  1640. "1:15:38.6505209 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\clrhost.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1641. "1:15:38.6508882 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\mscoree.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1642. "1:15:38.6509957 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\mscoree.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1643. "1:15:38.6510935 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\mscoree.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1644. "1:15:38.7250705 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\mscoree.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1645. "1:15:38.7722252 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\mscoree.dll.local","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1646. "1:15:38.8340240 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1647. "1:15:38.8345459 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\.NETFramework\CLRLoadLogDir","NAME NOT FOUND","Length: 144"
  1648. "1:15:38.8345954 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  1649. "1:15:38.8346675 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  1650. "1:15:38.8347095 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
  1651. "1:15:38.8347424 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  1652. "1:15:38.8347656 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  1653. "1:15:38.8348061 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
  1654. "1:15:38.8351191 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  1655. "1:15:38.8351430 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  1656. "1:15:38.8351635 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm","NAME NOT FOUND","Desired Access: Read"
  1657. "1:15:38.8352248 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\ThrottleStore\ThrottleExpiryTime","NAME NOT FOUND","Length: 24"
  1658. "1:15:38.8352426 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  1659. "1:15:38.8352848 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
  1660. "1:15:38.8353189 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  1661. "1:15:38.8353404 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  1662. "1:15:38.8354086 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
  1663. "1:15:38.8354659 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\ThrottleStore\sqm\windows\winsqm8\101457945","NAME NOT FOUND","Desired Access: Read"
  1664. "1:15:38.8354883 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8\101457945","NAME NOT FOUND","Desired Access: Read"
  1665. "1:15:38.8356567 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\mscoree.dll.local","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1666. "1:15:38.8360159 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v2.0.50727\clr.dll","NAME NOT FOUND","Desired Access: Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Random Access, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1667. "1:15:38.8731359 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll","ACCESS DENIED","Desired Access: Read Attributes, Read Control, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Random Access, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1668. "1:15:38.8734199 PM","wwahost.exe","2812","QueryDirectory","C:\Windows\Microsoft.NET\Framework64","NO MORE FILES",""
  1669. "1:15:38.9449748 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1670. "1:15:38.9454753 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\MSVCR110_CLR0400.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1671. "1:15:38.9455870 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\MSVCR110_CLR0400.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1672. "1:15:38.9456914 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\MSVCR110_CLR0400.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1673. "1:15:39.0321724 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\msvcr110_clr0400.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1674. "1:15:39.0335386 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\.NETFramework","ACCESS DENIED","Desired Access: Read"
  1675. "1:15:39.0336542 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\.NETFramework\DisableConfigCache","NAME NOT FOUND","Length: 144"
  1676. "1:15:39.0337143 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\.NETFramework","ACCESS DENIED","Desired Access: Read"
  1677. "1:15:39.0342283 PM","wwahost.exe","2812","RegEnumValue","HKLM\SOFTWARE\Microsoft\.NETFramework","NO MORE ENTRIES","Index: 2, Length: 220"
  1678. "1:15:39.0453386 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\api-ms-win-core-winrt-l1-1-0.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1679. "1:15:39.0454599 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\api-ms-win-core-winrt-l1-1-0.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1680. "1:15:39.0455819 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\api-ms-win-core-winrt-string-l1-1-0.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1681. "1:15:39.0456821 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\api-ms-win-core-winrt-string-l1-1-0.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1682. "1:15:39.0695857 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.DesignMode\Server","NAME NOT FOUND","Length: 138"
  1683. "1:15:39.0696017 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.DesignMode","BUFFER TOO SMALL","Query: Full, Length: 0"
  1684. "1:15:39.0700992 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.ApplicationModel.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1685. "1:15:39.0705490 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\wwahost.exe.config","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1686. "1:15:39.0706782 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoree.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1687. "1:15:39.0708535 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoree.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1688. "1:15:39.0709486 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\wwahost.exe.config","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Disallow Exclusive, Attributes: N, ShareMode: Read, AllocationSize: n/a"
  1689. "1:15:39.1143663 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wwahost.exe","NAME NOT FOUND","Desired Access: Read"
  1690. "1:15:39.1145326 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\fusion.localgac","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1691. "1:15:39.1146337 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Fusion\CacheLocation","NAME NOT FOUND","Length: 144"
  1692. "1:15:39.1147318 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB","NAME NOT FOUND","Length: 144"
  1693. "1:15:39.1147665 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Fusion","NAME NOT FOUND","Desired Access: Read"
  1694. "1:15:39.1148073 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Fusion\EnableLog","NAME NOT FOUND","Length: 144"
  1695. "1:15:39.1148218 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Fusion\LoggingLevel","NAME NOT FOUND","Length: 144"
  1696. "1:15:39.1148357 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Fusion\ForceLog","NAME NOT FOUND","Length: 144"
  1697. "1:15:39.1148489 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Fusion\LogFailures","NAME NOT FOUND","Length: 144"
  1698. "1:15:39.1148625 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Fusion\LogResourceBinds","NAME NOT FOUND","Length: 144"
  1699. "1:15:39.1148764 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts","NAME NOT FOUND","Length: 144"
  1700. "1:15:39.1148900 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries","NAME NOT FOUND","Length: 144"
  1701. "1:15:39.1149063 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Fusion\DisableMSIPeek","NAME NOT FOUND","Length: 144"
  1702. "1:15:39.1149975 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable","NAME NOT FOUND","Length: 144"
  1703. "1:15:39.1219076 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries","NAME NOT FOUND","Length: 144"
  1704. "1:15:39.1226227 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\NoNGen.txt","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1705. "1:15:39.1231250 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ole32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1706. "1:15:39.1232443 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ole32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1707. "1:15:39.1237891 PM","wwahost.exe","2812","CreateFile","C:\windows\Microsoft.Net\assembly\GAC_MSIL\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll","PATH NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1708. "1:15:39.1892824 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\5a23c5e185cb978f73c67718f6e061a4\mscorlib.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1709. "1:15:39.1896742 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\StrongName","NAME NOT FOUND","Desired Access: Read"
  1710. "1:15:39.1915360 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Platform.Networking.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1711. "1:15:39.1916701 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Platform.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1712. "1:15:39.1917917 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Platform.Networking.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1713. "1:15:39.1919058 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Platform.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1714. "1:15:39.1920220 PM","wwahost.exe","2812","CreateFile","C:\Windows\assembly\NativeImages_v4.0.30319_64\Platform","NAME NOT FOUND","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1715. "1:15:39.2195407 PM","wwahost.exe","2812","CreateFile","C:\windows\assembly\GAC\PublisherPolicy.tme","PATH NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1716. "1:15:39.2965614 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Security.Authentication.OnlineId.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1717. "1:15:39.2966815 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Security.Authentication.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1718. "1:15:39.2972623 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Networking.NetworkOperators.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1719. "1:15:39.3003757 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Foundation.Collections.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1720. "1:15:39.3160220 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Storage.Streams.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1721. "1:15:39.4016797 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.UI.Xaml.Interop.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1722. "1:15:39.4049033 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.System.Profile.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1723. "1:15:39.4062484 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.ApplicationModel.Background.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1724. "1:15:39.4075225 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Globalization.Fonts.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1725. "1:15:39.4334918 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.UI.ApplicationSettings.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1726. "1:15:39.4351701 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Data.Html.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1727. "1:15:39.4547080 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Devices.Sms.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1728. "1:15:39.4565801 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Graphics.Display.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1729. "1:15:39.5300008 PM","wwahost.exe","2812","CreateFileMapping","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\Platform\6e7823fcc964cf9789d4f388f3042791\Platform.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1730. "1:15:39.5320969 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\Cryptography\Offload","NAME NOT FOUND","Desired Access: Read"
  1731. "1:15:39.5340155 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA","NAME NOT FOUND","Desired Access: Read"
  1732. "1:15:39.5483378 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Networking.Connectivity.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1733. "1:15:39.6378069 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Networking\170d797fe060a5a3f9697960928c48d7\Windows.Networking.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1734. "1:15:39.6390454 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Networking.Connectivity.NetworkStatusChangedEventHandler.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1735. "1:15:39.7469520 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Networking.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1736. "1:15:39.7999848 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1737. "1:15:39.8004204 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\.NETFramework","ACCESS DENIED","Desired Access: Read"
  1738. "1:15:39.8005402 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\.NETFramework\CseOn","NAME NOT FOUND","Length: 144"
  1739. "1:15:39.8005915 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\.NETFramework","ACCESS DENIED","Desired Access: Read"
  1740. "1:15:39.8006612 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\.NETFramework\TailCallOpt","NAME NOT FOUND","Length: 144"
  1741. "1:15:39.8007105 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\.NETFramework","ACCESS DENIED","Desired Access: Read"
  1742. "1:15:39.8007699 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\.NETFramework\PInvokeInline","NAME NOT FOUND","Length: 144"
  1743. "1:15:39.8008149 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\.NETFramework","ACCESS DENIED","Desired Access: Read"
  1744. "1:15:39.8008713 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\.NETFramework\NewGCCalc","NAME NOT FOUND","Length: 144"
  1745. "1:15:39.8009296 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\.NETFramework","ACCESS DENIED","Desired Access: Read"
  1746. "1:15:39.8009870 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\.NETFramework\TURNOFFDEBUGINFO","NAME NOT FOUND","Length: 144"
  1747. "1:15:39.8010325 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\.NETFramework","ACCESS DENIED","Desired Access: Read"
  1748. "1:15:39.8010881 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\.NETFramework\DisableHotCold","NAME NOT FOUND","Length: 144"
  1749. "1:15:39.8011352 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\.NETFramework\internal\jit\Perf","NAME NOT FOUND","Desired Access: Read"
  1750. "1:15:39.8700222 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\api-ms-win-core-winrt-roparameterizediid-l1-1-0.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1751. "1:15:39.8701270 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\api-ms-win-core-winrt-roparameterizediid-l1-1-0.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1752. "1:15:39.8702722 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\bcrypt.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1753. "1:15:39.8703660 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\bcrypt.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1754. "1:15:39.8704548 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\bcrypt.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1755. "1:15:39.8708134 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\bcrypt.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1756. "1:15:39.8711651 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
  1757. "1:15:39.8712336 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
  1758. "1:15:39.8713018 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
  1759. "1:15:39.8713492 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
  1760. "1:15:39.8714506 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
  1761. "1:15:39.8714986 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
  1762. "1:15:39.8715511 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
  1763. "1:15:39.8715958 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
  1764. "1:15:39.8716683 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
  1765. "1:15:39.8717141 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
  1766. "1:15:39.8717645 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
  1767. "1:15:39.8718092 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
  1768. "1:15:39.8797207 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.Resources.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1769. "1:15:39.8800485 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Platform.Resources.StringResourceLoader","NAME NOT FOUND","Desired Access: Read"
  1770. "1:15:39.8801088 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Resources.StringResourceLoader","NAME NOT FOUND","Desired Access: Read"
  1771. "1:15:39.8801472 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Resources.StringResourceLoader","NAME NOT FOUND","Desired Access: Read"
  1772. "1:15:39.8801783 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\ActivatableClassId\Platform.Resources.StringResourceLoader","NAME NOT FOUND","Desired Access: Read"
  1773. "1:15:39.8802969 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{D86095BD-EFD0-5B58-9176-430CFD0FAF4D}","NAME NOT FOUND","Desired Access: Read"
  1774. "1:15:39.8803256 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{D86095BD-EFD0-5B58-9176-430CFD0FAF4D}","NAME NOT FOUND","Desired Access: Read"
  1775. "1:15:39.8804210 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{D86095BD-EFD0-5B58-9176-430CFD0FAF4D}","NAME NOT FOUND","Desired Access: Read"
  1776. "1:15:39.8804490 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{D86095BD-EFD0-5B58-9176-430CFD0FAF4D}","NAME NOT FOUND","Desired Access: Read"
  1777. "1:15:39.8805474 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Wow6432Node\CLSID\{D86095BD-EFD0-5B58-9176-430CFD0FAF4D}","NAME NOT FOUND","Desired Access: Read"
  1778. "1:15:39.8805822 PM","wwahost.exe","2812","RegOpenKey","HKCR\Wow6432Node\CLSID\{D86095BD-EFD0-5B58-9176-430CFD0FAF4D}","NAME NOT FOUND","Desired Access: Read"
  1779. "1:15:39.8966836 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Platform.Resources.StringResourceLoader","NAME NOT FOUND","Desired Access: Read"
  1780. "1:15:39.8967141 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Resources.StringResourceLoader","NAME NOT FOUND","Desired Access: Read"
  1781. "1:15:39.8968557 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Resources.StringResourceLoader\Server","NAME NOT FOUND","Length: 138"
  1782. "1:15:39.8968907 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Resources.StringResourceLoader","BUFFER TOO SMALL","Query: Full, Length: 0"
  1783. "1:15:39.8971799 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Platform.Resources.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1784. "1:15:39.8973209 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Platform.Resources.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1785. "1:15:39.9467999 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\api-ms-win-core-winrt-string-l1-1-0.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1786. "1:15:39.9469103 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\api-ms-win-core-winrt-string-l1-1-0.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1787. "1:15:40.0750282 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.App640a3541#\52610b15de6cf7f4ddd8b93f543abe24\Windows.ApplicationModel.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1788. "1:15:40.0782029 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.ApplicationModel.Resources.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1789. "1:15:40.1029807 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Resources.ResourceLoader\Server","NAME NOT FOUND","Length: 138"
  1790. "1:15:40.1029958 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Resources.ResourceLoader","BUFFER TOO SMALL","Query: Full, Length: 0"
  1791. "1:15:40.1053724 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Platform.Process","NAME NOT FOUND","Desired Access: Read"
  1792. "1:15:40.1054364 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Process","NAME NOT FOUND","Desired Access: Read"
  1793. "1:15:40.1054678 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Process","NAME NOT FOUND","Desired Access: Read"
  1794. "1:15:40.1054916 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\ActivatableClassId\Platform.Process","NAME NOT FOUND","Desired Access: Read"
  1795. "1:15:40.1055876 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{A8034CBD-D885-5F9F-A046-9C9BB9BD43E7}","NAME NOT FOUND","Desired Access: Read"
  1796. "1:15:40.1056123 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{A8034CBD-D885-5F9F-A046-9C9BB9BD43E7}","NAME NOT FOUND","Desired Access: Read"
  1797. "1:15:40.1056954 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{A8034CBD-D885-5F9F-A046-9C9BB9BD43E7}","NAME NOT FOUND","Desired Access: Read"
  1798. "1:15:40.1057222 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{A8034CBD-D885-5F9F-A046-9C9BB9BD43E7}","NAME NOT FOUND","Desired Access: Read"
  1799. "1:15:40.1058061 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Wow6432Node\CLSID\{A8034CBD-D885-5F9F-A046-9C9BB9BD43E7}","NAME NOT FOUND","Desired Access: Read"
  1800. "1:15:40.1058309 PM","wwahost.exe","2812","RegOpenKey","HKCR\Wow6432Node\CLSID\{A8034CBD-D885-5F9F-A046-9C9BB9BD43E7}","NAME NOT FOUND","Desired Access: Read"
  1801. "1:15:40.1818358 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Platform.Process","NAME NOT FOUND","Desired Access: Read"
  1802. "1:15:40.1818808 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Process","NAME NOT FOUND","Desired Access: Read"
  1803. "1:15:40.1820395 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Process\Server","NAME NOT FOUND","Length: 138"
  1804. "1:15:40.1820540 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Process","BUFFER TOO SMALL","Query: Full, Length: 0"
  1805. "1:15:40.2877948 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Storage.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1806. "1:15:40.2884547 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Storage.ApplicationData.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1807. "1:15:40.3125962 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.ApplicationData\Server","NAME NOT FOUND","Length: 138"
  1808. "1:15:40.3126261 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.ApplicationData","BUFFER TOO SMALL","Query: Full, Length: 0"
  1809. "1:15:40.3135180 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.Storage.ApplicationData.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1810. "1:15:40.3149075 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{E1CDD77A-65D3-4DB0-B339-21F6A48CC2FF}","NAME NOT FOUND","Desired Access: Read"
  1811. "1:15:40.3150838 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{E1CDD77A-65D3-4DB0-B339-21F6A48CC2FF}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
  1812. "1:15:40.3152383 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{E1CDD77A-65D3-4DB0-B339-21F6A48CC2FF}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  1813. "1:15:40.3157738 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.BingNews_8wekyb3d8bbwe\PSR","REPARSE","Desired Access: Query Value"
  1814. "1:15:40.3160045 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Notifications\41C64E6DA3BC70E5","BUFFER TOO SMALL","Length: 0"
  1815. "1:15:40.3163145 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
  1816. "1:15:40.3164660 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
  1817. "1:15:40.3166248 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
  1818. "1:15:40.3167479 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
  1819. "1:15:40.3182105 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.Instrumentation.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1820. "1:15:40.3998348 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.UI.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1821. "1:15:40.4004801 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.UI.ViewManagement.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1822. "1:15:40.4006208 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.UI.ViewManagement.ApplicationView.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1823. "1:15:40.5148278 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Media.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1824. "1:15:40.5154059 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Media.MediaControl.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1825. "1:15:40.5790188 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Globalization.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1826. "1:15:40.5796395 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Globalization.DateTimeFormatting.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1827. "1:15:40.5805127 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\common\dynamicpano\js\dynamicPanoAuth.js","PATH NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1828. "1:15:40.6247883 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.KnownFolders\Server","NAME NOT FOUND","Length: 138"
  1829. "1:15:40.6248046 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Storage.KnownFolders","BUFFER TOO SMALL","Query: Full, Length: 0"
  1830. "1:15:40.6254176 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\PROPSYS.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1831. "1:15:40.6255381 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\PROPSYS.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1832. "1:15:40.6256459 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\PROPSYS.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1833. "1:15:40.6260519 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\propsys.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1834. "1:15:40.6266483 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\Directory","NAME NOT FOUND","Desired Access: Read"
  1835. "1:15:40.6267036 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\Shell\Associations","ACCESS DENIED","Desired Access: Query Value"
  1836. "1:15:40.6269764 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Directory\URL Protocol","NAME NOT FOUND","Length: 144"
  1837. "1:15:40.6269961 PM","wwahost.exe","2812","RegQueryValue","HKCR\Directory\URL Protocol","NAME NOT FOUND","Length: 144"
  1838. "1:15:40.6272146 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Directory\CurVer","NAME NOT FOUND","Desired Access: Query Value"
  1839. "1:15:40.6272406 PM","wwahost.exe","2812","RegOpenKey","HKCR\Directory\CurVer","NAME NOT FOUND","Desired Access: Query Value"
  1840. "1:15:40.6274793 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Directory\IsShortcut","NAME NOT FOUND","Length: 144"
  1841. "1:15:40.6274963 PM","wwahost.exe","2812","RegQueryValue","HKCR\Directory\IsShortcut","NAME NOT FOUND","Length: 144"
  1842. "1:15:40.6276019 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\Directory\FriendlyTypeName","NAME NOT FOUND","Length: 144"
  1843. "1:15:40.6278256 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\shell32.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1844. "1:15:40.6289216 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
  1845. "1:15:40.6290086 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
  1846. "1:15:40.6291009 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
  1847. "1:15:40.6291716 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
  1848. "1:15:40.6296002 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Explorer","NAME NOT FOUND","Desired Access: Query Value"
  1849. "1:15:40.6296376 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Explorer","NAME NOT FOUND","Desired Access: Query Value"
  1850. "1:15:40.6297173 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\LocalState","ACCESS DENIED","Desired Access: Read Data/List Directory, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1851. "1:15:40.6298414 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\LocalState\state.json","ACCESS DENIED","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1852. "1:15:40.6306963 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\jscript9.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1853. "1:15:40.6309734 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
  1854. "1:15:40.6310669 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
  1855. "1:15:40.6311602 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
  1856. "1:15:40.6312399 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
  1857. "1:15:40.6329813 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\RoamingState","ACCESS DENIED","Desired Access: Read Data/List Directory, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1858. "1:15:40.6331606 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\RoamingState\state.json","ACCESS DENIED","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Disallow Exclusive, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1859. "1:15:40.6335721 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.CrashReporting.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1860. "1:15:40.6339732 PM","wwahost.exe","2812","QueryDirectory","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.CrashReporting*.winmd","NO SUCH FILE","Filter: Platform.CrashReporting*.winmd"
  1861. "1:15:40.6341535 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Platform.CrashReporting.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1862. "1:15:40.6342854 PM","wwahost.exe","2812","QueryDirectory","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Platform.CrashReporting*.winmd","NO SUCH FILE","Filter: Platform.CrashReporting*.winmd"
  1863. "1:15:40.6344550 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Platform.CrashReporting.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1864. "1:15:40.6345830 PM","wwahost.exe","2812","QueryDirectory","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Platform.CrashReporting*.winmd","NO SUCH FILE","Filter: Platform.CrashReporting*.winmd"
  1865. "1:15:40.6347925 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.UI.WebUI.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1866. "1:15:40.6352148 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.ApplicationModel.ISuspendingEventArgs.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1867. "1:15:40.7149682 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.ApplicationModel.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1868. "1:15:40.7936847 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\WinMetadata\Windows.Graphics.winmd","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1869. "1:15:40.7944100 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.Graphics.Display.DisplayProperties.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1870. "1:15:40.7950575 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Display.DisplayProperties\Server","NAME NOT FOUND","Length: 138"
  1871. "1:15:40.7950732 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Graphics.Display.DisplayProperties","BUFFER TOO SMALL","Query: Full, Length: 0"
  1872. "1:15:40.8265982 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.Graphics.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1873. "1:15:40.8270069 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\fa5cf675-72eb-49e2-b447-de5552faff1c","NAME NOT FOUND","Length: 524"
  1874. "1:15:40.8274627 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.Globalization.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1875. "1:15:40.8278790 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Platform.Globalization.Marketization","NAME NOT FOUND","Desired Access: Read"
  1876. "1:15:40.8279189 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Globalization.Marketization","NAME NOT FOUND","Desired Access: Read"
  1877. "1:15:40.8279472 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Globalization.Marketization","NAME NOT FOUND","Desired Access: Read"
  1878. "1:15:40.8279717 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\ActivatableClassId\Platform.Globalization.Marketization","NAME NOT FOUND","Desired Access: Read"
  1879. "1:15:40.8280710 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{A33E8EAB-F3C4-5E16-89C0-628E2168A4E9}","NAME NOT FOUND","Desired Access: Read"
  1880. "1:15:40.8281256 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{A33E8EAB-F3C4-5E16-89C0-628E2168A4E9}","NAME NOT FOUND","Desired Access: Read"
  1881. "1:15:40.8282488 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{A33E8EAB-F3C4-5E16-89C0-628E2168A4E9}","NAME NOT FOUND","Desired Access: Read"
  1882. "1:15:40.8282763 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{A33E8EAB-F3C4-5E16-89C0-628E2168A4E9}","NAME NOT FOUND","Desired Access: Read"
  1883. "1:15:40.8283747 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Wow6432Node\CLSID\{A33E8EAB-F3C4-5E16-89C0-628E2168A4E9}","NAME NOT FOUND","Desired Access: Read"
  1884. "1:15:40.8284015 PM","wwahost.exe","2812","RegOpenKey","HKCR\Wow6432Node\CLSID\{A33E8EAB-F3C4-5E16-89C0-628E2168A4E9}","NAME NOT FOUND","Desired Access: Read"
  1885. "1:15:40.8490677 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Platform.Globalization.Marketization","NAME NOT FOUND","Desired Access: Read"
  1886. "1:15:40.8491127 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Globalization.Marketization","NAME NOT FOUND","Desired Access: Read"
  1887. "1:15:40.8492805 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Globalization.Marketization\Server","NAME NOT FOUND","Length: 138"
  1888. "1:15:40.8492959 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.Globalization.Marketization","BUFFER TOO SMALL","Query: Full, Length: 0"
  1889. "1:15:40.8496382 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Platform.Globalization.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1890. "1:15:40.8497895 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Platform.Globalization.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1891. "1:15:40.8781911 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Gloaae92e31#\678926c3ae1779d1515a93d5afbc45f4\Windows.Globalization.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1892. "1:15:40.9737227 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Foundation\87788b39516ef9bf7e5c60a2b5fb3aeb\Windows.Foundation.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1893. "1:15:41.0458934 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtime\92dbe33346751ef372e3590eb71b1cac\System.Runtime.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1894. "1:15:41.1597677 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System\67f7ddcb264bac2f465b439bb19616b1\System.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1895. "1:15:41.2668261 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\3145945493fbcef888aa44b0081134cc\System.Core.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1896. "1:15:41.4147463 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.System\4022b99b813a11eb3afa84dd8fd0eee6\Windows.System.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1897. "1:15:41.4367063 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.System.UserProfile.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1898. "1:15:41.4369934 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.UserProfile.GlobalizationPreferences\Server","NAME NOT FOUND","Length: 138"
  1899. "1:15:41.4370018 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.System.UserProfile.GlobalizationPreferences","BUFFER TOO SMALL","Query: Full, Length: 0"
  1900. "1:15:41.4373393 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\Windows.Globalization.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1901. "1:15:41.4925545 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\WinMetadata\Windows.ApplicationModel.Resources.Core.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1902. "1:15:41.4937499 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\api-ms-win-ro-typeresolution-l1-1-0.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1903. "1:15:41.4938540 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\api-ms-win-ro-typeresolution-l1-1-0.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1904. "1:15:41.4940089 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
  1905. "1:15:41.4940861 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
  1906. "1:15:41.4941595 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
  1907. "1:15:41.4942102 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
  1908. "1:15:41.4948197 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
  1909. "1:15:41.4949132 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
  1910. "1:15:41.4949745 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
  1911. "1:15:41.4950204 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
  1912. "1:15:41.4953639 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
  1913. "1:15:41.4954207 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
  1914. "1:15:41.4954798 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
  1915. "1:15:41.4955296 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
  1916. "1:15:41.4959900 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Platform.ServicesAccessor","NAME NOT FOUND","Desired Access: Read"
  1917. "1:15:41.4960310 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.ServicesAccessor","NAME NOT FOUND","Desired Access: Read"
  1918. "1:15:41.4960609 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.ServicesAccessor","NAME NOT FOUND","Desired Access: Read"
  1919. "1:15:41.4960872 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\ActivatableClassId\Platform.ServicesAccessor","NAME NOT FOUND","Desired Access: Read"
  1920. "1:15:41.4961886 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{CAD01161-1440-542A-BE93-1C79B0C08AD3}","NAME NOT FOUND","Desired Access: Read"
  1921. "1:15:41.4962152 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{CAD01161-1440-542A-BE93-1C79B0C08AD3}","NAME NOT FOUND","Desired Access: Read"
  1922. "1:15:41.4963036 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{CAD01161-1440-542A-BE93-1C79B0C08AD3}","NAME NOT FOUND","Desired Access: Read"
  1923. "1:15:41.4963302 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{CAD01161-1440-542A-BE93-1C79B0C08AD3}","NAME NOT FOUND","Desired Access: Read"
  1924. "1:15:41.4964240 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Wow6432Node\CLSID\{CAD01161-1440-542A-BE93-1C79B0C08AD3}","NAME NOT FOUND","Desired Access: Read"
  1925. "1:15:41.4964503 PM","wwahost.exe","2812","RegOpenKey","HKCR\Wow6432Node\CLSID\{CAD01161-1440-542A-BE93-1C79B0C08AD3}","NAME NOT FOUND","Desired Access: Read"
  1926. "1:15:41.5039102 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Platform.ServicesAccessor","NAME NOT FOUND","Desired Access: Read"
  1927. "1:15:41.5040122 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.ServicesAccessor","NAME NOT FOUND","Desired Access: Read"
  1928. "1:15:41.5043536 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.ServicesAccessor\Server","NAME NOT FOUND","Length: 138"
  1929. "1:15:41.5043913 PM","wwahost.exe","2812","RegQueryKey","HKCU\Software\Classes\ActivatableClasses\Package\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\ActivatableClassId\Platform.ServicesAccessor","BUFFER TOO SMALL","Query: Full, Length: 0"
  1930. "1:15:41.5106609 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.Configuration.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1931. "1:15:41.5109885 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Platform.Configuration.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1932. "1:15:41.5112789 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Platform.Configuration.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1933. "1:15:41.5121950 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Platform.Instrumentation.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1934. "1:15:41.5125086 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Platform.Instrumentation.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1935. "1:15:41.5129554 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.Configuration.Manifest.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1936. "1:15:41.5132630 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Platform.Configuration.Manifest.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1937. "1:15:41.5135612 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Platform.Configuration.Manifest.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1938. "1:15:41.5139917 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.Diagnostics.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1939. "1:15:41.5142857 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\Platform.Diagnostics.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1940. "1:15:41.5145863 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\Platform.Diagnostics.winmd","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1941. "1:15:41.6834275 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\8517b132cbe0b329b40bc6a9ef106828\System.Configuration.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1942. "1:15:41.7879454 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml\4334f45efbe62a6415f2cb7393c59f74\System.Xml.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1943. "1:15:41.8119227 PM","wwahost.exe","2812","ReadFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config","END OF FILE","Offset: 35,983, Length: 4,096"
  1944. "1:15:41.8122511 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\wwahost.exe.config","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1945. "1:15:41.8123975 PM","wwahost.exe","2812","CreateFile","C:\Windows\System32\wwahost.exe.config","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1946. "1:15:41.8138715 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\rasapi32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1947. "1:15:41.8139648 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\rasapi32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1948. "1:15:41.8140762 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\rasapi32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1949. "1:15:41.8141698 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\rasapi32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1950. "1:15:41.8142700 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\rasapi32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1951. "1:15:41.8145866 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rasapi32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1952. "1:15:41.8149766 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\rasman.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1953. "1:15:41.8150717 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\rasman.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1954. "1:15:41.8151970 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\rasman.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1955. "1:15:41.8155474 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\rasman.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1956. "1:15:41.8167292 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\ws2_32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1957. "1:15:41.8168844 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\ws2_32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  1958. "1:15:41.8171108 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  1959. "1:15:41.8171850 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  1960. "1:15:41.8172140 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
  1961. "1:15:41.8172360 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  1962. "1:15:41.8172523 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  1963. "1:15:41.8172801 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
  1964. "1:15:41.8177498 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","REPARSE","Desired Access: Read"
  1965. "1:15:41.8178932 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog\0D0D3D6C-18CC075D","NAME NOT FOUND","Desired Access: Read"
  1966. "1:15:41.8179198 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog\0D0D3D6C","NAME NOT FOUND","Desired Access: Read"
  1967. "1:15:41.8180665 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\00000006","NAME NOT FOUND","Desired Access: Read"
  1968. "1:15:41.8181634 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000001\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
  1969. "1:15:41.8182545 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000002\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
  1970. "1:15:41.8183252 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000003\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
  1971. "1:15:41.8184045 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000004\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
  1972. "1:15:41.8184704 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000005\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
  1973. "1:15:41.8185301 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000006\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
  1974. "1:15:41.8185872 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000007\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
  1975. "1:15:41.8186481 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000008\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
  1976. "1:15:41.8187067 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000009\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
  1977. "1:15:41.8187638 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000010\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
  1978. "1:15:41.8188214 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000011\PackedCatalogItem","BUFFER OVERFLOW","Length: 144"
  1979. "1:15:41.8189422 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\0000001A","NAME NOT FOUND","Desired Access: Read"
  1980. "1:15:41.8191396 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\AddressFamily","NAME NOT FOUND","Length: 144"
  1981. "1:15:41.8193660 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\AddressFamily","NAME NOT FOUND","Length: 144"
  1982. "1:15:41.8195712 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\AddressFamily","NAME NOT FOUND","Length: 144"
  1983. "1:15:41.8197834 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\AddressFamily","NAME NOT FOUND","Length: 144"
  1984. "1:15:41.8199911 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\AddressFamily","NAME NOT FOUND","Length: 144"
  1985. "1:15:41.8202085 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\AddressFamily","NAME NOT FOUND","Length: 144"
  1986. "1:15:41.8204216 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000007\AddressFamily","NAME NOT FOUND","Length: 144"
  1987. "1:15:41.8205459 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Winsock2\Parameters","REPARSE","Desired Access: Query Value"
  1988. "1:15:41.8205791 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Ws2_32NumHandleBuckets","NAME NOT FOUND","Length: 144"
  1989. "1:15:41.8205879 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Ws2_32SpinCount","NAME NOT FOUND","Length: 144"
  1990. "1:15:41.8209625 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\mswsock.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  1991. "1:15:41.8212626 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  1992. "1:15:41.8213395 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  1993. "1:15:41.8213694 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
  1994. "1:15:41.8213905 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  1995. "1:15:41.8214062 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  1996. "1:15:41.8214343 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
  1997. "1:15:41.8218771 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Parameters","REPARSE","Desired Access: Read"
  1998. "1:15:41.8219620 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock","REPARSE","Desired Access: Read"
  1999. "1:15:41.8220407 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Setup Migration\Providers","REPARSE","Desired Access: Read"
  2000. "1:15:41.8221808 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock","REPARSE","Desired Access: Read"
  2001. "1:15:41.8223713 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Parameters","REPARSE","Desired Access: Read"
  2002. "1:15:41.8224537 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock","REPARSE","Desired Access: Read"
  2003. "1:15:41.8225285 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock","REPARSE","Desired Access: Read"
  2004. "1:15:41.8226107 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Setup Migration\Providers","REPARSE","Desired Access: Read"
  2005. "1:15:41.8227290 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock","REPARSE","Desired Access: Read"
  2006. "1:15:41.8241731 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\.NETFramework\LegacyWPADSupport","NAME NOT FOUND","Length: 144"
  2007. "1:15:41.8247460 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\winhttp.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2008. "1:15:41.8248432 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\winhttp.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2009. "1:15:41.8249579 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\winhttp.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2010. "1:15:41.8250530 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\winhttp.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2011. "1:15:41.8251424 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\winhttp.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2012. "1:15:41.8254605 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\winhttp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2013. "1:15:41.8258979 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ShareCredsWithWinHttp","NAME NOT FOUND","Length: 144"
  2014. "1:15:41.8259915 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp\DisableBranchCache","NAME NOT FOUND","Length: 144"
  2015. "1:15:41.8262100 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\IPHLPAPI.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2016. "1:15:41.8263084 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\IPHLPAPI.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2017. "1:15:41.8263984 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\IPHLPAPI.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2018. "1:15:41.8267042 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\IPHLPAPI.DLL","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2019. "1:15:41.8270175 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\WINNSI.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2020. "1:15:41.8271195 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\WINNSI.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2021. "1:15:41.8272095 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\WINNSI.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2022. "1:15:41.8275144 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\winnsi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2023. "1:15:41.8291160 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\dhcpcsvc6.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2024. "1:15:41.8292159 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\dhcpcsvc6.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2025. "1:15:41.8293077 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\dhcpcsvc6.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2026. "1:15:41.8296041 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dhcpcsvc6.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2027. "1:15:41.8301837 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\dhcpcsvc.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2028. "1:15:41.8302770 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\dhcpcsvc.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2029. "1:15:41.8303748 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\dhcpcsvc.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2030. "1:15:41.8306697 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\dhcpcsvc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2031. "1:15:41.8311986 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read"
  2032. "1:15:41.8313474 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read"
  2033. "1:15:41.8314666 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read"
  2034. "1:15:41.8315819 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read"
  2035. "1:15:41.8316480 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{97e1de57-d6fa-11e1-be62-806e6f6e6963}\EnableDhcp","NAME NOT FOUND","Length: 144"
  2036. "1:15:41.8316870 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read"
  2037. "1:15:41.8318035 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read"
  2038. "1:15:41.8318566 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62fd552d-2a3f-4558-9937-3b0b4057f927}","NAME NOT FOUND","Desired Access: Query Value"
  2039. "1:15:41.8318928 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read"
  2040. "1:15:41.8319441 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0b4f74ec-4340-4d00-b2ff-e77f0ec5eed1}","NAME NOT FOUND","Desired Access: Query Value"
  2041. "1:15:41.8319873 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read"
  2042. "1:15:41.8320410 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{d20e8fa7-1438-440c-8296-653e483eb333}","NAME NOT FOUND","Desired Access: Query Value"
  2043. "1:15:41.8320761 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read"
  2044. "1:15:41.8321283 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{d93979cc-e9be-4a24-a75a-4d792ec23e05}","NAME NOT FOUND","Desired Access: Query Value"
  2045. "1:15:41.8321678 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C728CD83-069D-4EAF-BAC9-5B79C65D1C90}","REPARSE","Desired Access: Read"
  2046. "1:15:41.8322831 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0B1A6944-7F9A-43B4-9D0E-299C2B003D29}","REPARSE","Desired Access: Read"
  2047. "1:15:41.8323577 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0B1A6944-7F9A-43B4-9D0E-299C2B003D29}\DhcpDomain","NAME NOT FOUND","Length: 144"
  2048. "1:15:41.8323885 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{0B1A6944-7F9A-43B4-9D0E-299C2B003D29}","REPARSE","Desired Access: Read"
  2049. "1:15:41.8324208 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\TCPIP6\Parameters\Interfaces\{0B1A6944-7F9A-43B4-9D0E-299C2B003D29}\Dhcpv6Domain","NAME NOT FOUND","Length: 144"
  2050. "1:15:41.8324567 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3915EDAE-3B2F-4D83-98A4-FF3EB1FA73E5}","REPARSE","Desired Access: Read"
  2051. "1:15:41.8325264 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3915EDAE-3B2F-4D83-98A4-FF3EB1FA73E5}\DhcpDomain","NAME NOT FOUND","Length: 144"
  2052. "1:15:41.8325590 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3915EDAE-3B2F-4D83-98A4-FF3EB1FA73E5}","REPARSE","Desired Access: Read"
  2053. "1:15:41.8325901 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\TCPIP6\Parameters\Interfaces\{3915EDAE-3B2F-4D83-98A4-FF3EB1FA73E5}\Dhcpv6Domain","NAME NOT FOUND","Length: 144"
  2054. "1:15:41.8326257 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{40F8964E-7AF3-4B88-86E2-DCDBCADAB0A1}","REPARSE","Desired Access: Read"
  2055. "1:15:41.8326925 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{40F8964E-7AF3-4B88-86E2-DCDBCADAB0A1}\DhcpDomain","NAME NOT FOUND","Length: 144"
  2056. "1:15:41.8327217 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{40F8964E-7AF3-4B88-86E2-DCDBCADAB0A1}","REPARSE","Desired Access: Read"
  2057. "1:15:41.8327510 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\TCPIP6\Parameters\Interfaces\{40F8964E-7AF3-4B88-86E2-DCDBCADAB0A1}\Dhcpv6Domain","NAME NOT FOUND","Length: 144"
  2058. "1:15:41.8327857 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{97E1DE57-D6FA-11E1-BE62-806E6F6E6963}","REPARSE","Desired Access: Read"
  2059. "1:15:41.8328150 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{97e1de57-d6fa-11e1-be62-806e6f6e6963}\RegistrationEnabled","NAME NOT FOUND","Length: 144"
  2060. "1:15:41.8328238 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{97e1de57-d6fa-11e1-be62-806e6f6e6963}\RegisterAdapterName","NAME NOT FOUND","Length: 144"
  2061. "1:15:41.8328316 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{97e1de57-d6fa-11e1-be62-806e6f6e6963}\Domain","NAME NOT FOUND","Length: 144"
  2062. "1:15:41.8328398 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{97e1de57-d6fa-11e1-be62-806e6f6e6963}\DhcpDomain","NAME NOT FOUND","Length: 144"
  2063. "1:15:41.8328832 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{97E1DE57-D6FA-11E1-BE62-806E6F6E6963}","REPARSE","Desired Access: Read"
  2064. "1:15:41.8329016 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{97E1DE57-D6FA-11E1-BE62-806E6F6E6963}","NAME NOT FOUND","Desired Access: Read"
  2065. "1:15:41.8329364 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{815D19A4-3D8E-45FE-A47E-7CE7F0B8E381}","REPARSE","Desired Access: Read"
  2066. "1:15:41.8330016 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{815D19A4-3D8E-45FE-A47E-7CE7F0B8E381}\DhcpDomain","NAME NOT FOUND","Length: 144"
  2067. "1:15:41.8330308 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{815D19A4-3D8E-45FE-A47E-7CE7F0B8E381}","REPARSE","Desired Access: Read"
  2068. "1:15:41.8330604 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\TCPIP6\Parameters\Interfaces\{815D19A4-3D8E-45FE-A47E-7CE7F0B8E381}\Dhcpv6Domain","NAME NOT FOUND","Length: 144"
  2069. "1:15:41.8330957 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{969429AB-1E8B-4A16-9F46-E66A3EBF489B}","REPARSE","Desired Access: Read"
  2070. "1:15:41.8331603 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{969429AB-1E8B-4A16-9F46-E66A3EBF489B}\DhcpDomain","NAME NOT FOUND","Length: 144"
  2071. "1:15:41.8331899 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{969429AB-1E8B-4A16-9F46-E66A3EBF489B}","REPARSE","Desired Access: Read"
  2072. "1:15:41.8332189 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\TCPIP6\Parameters\Interfaces\{969429AB-1E8B-4A16-9F46-E66A3EBF489B}\Dhcpv6Domain","NAME NOT FOUND","Length: 144"
  2073. "1:15:41.8332741 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Linkage","REPARSE","Desired Access: Read"
  2074. "1:15:41.8333164 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Linkage\Bind","BUFFER OVERFLOW","Length: 144"
  2075. "1:15:41.8333273 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Linkage\Bind","BUFFER OVERFLOW","Length: 144"
  2076. "1:15:41.8333508 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Linkage\Bind","BUFFER OVERFLOW","Length: 144"
  2077. "1:15:41.8333587 PM","wwahost.exe","2812","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Linkage\Bind","BUFFER OVERFLOW","Length: 144"
  2078. "1:15:41.8334559 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ProxySettingsPerUser","NAME NOT FOUND","Length: 144"
  2079. "1:15:41.8334912 PM","wwahost.exe","2812","RegOpenKey","HKCU","ACCESS DENIED","Desired Access: Query Value, Set Value"
  2080. "1:15:41.8335174 PM","wwahost.exe","2812","QuerySecurityFile","C:\Windows\System32\WWAHost.exe","BUFFER OVERFLOW","Information: Owner"
  2081. "1:15:41.8335887 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings","BUFFER OVERFLOW","Length: 144"
  2082. "1:15:41.8335983 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings","BUFFER OVERFLOW","Length: 144"
  2083. "1:15:41.8656748 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Net.Http\69640072694356ffed3bbe2d2352f935\System.Net.Http.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2084. "1:15:41.8755985 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Package\Server","NAME NOT FOUND","Length: 138"
  2085. "1:15:41.8756084 PM","wwahost.exe","2812","RegQueryKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Package","BUFFER TOO SMALL","Query: Full, Length: 0"
  2086. "1:15:41.8855076 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\oleaut32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2087. "1:15:41.8856139 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\oleaut32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2088. "1:15:41.9825295 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Storage\702ec9a3c9175b1eb68df2438ef50b27\Windows.Storage.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2089. "1:15:42.0619106 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runtbff93e24#\3e4a52cfe965934afd16ce06288bbcc7\System.Runtime.InteropServices.WindowsRuntime.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2090. "1:15:42.2251119 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Runt0d283adf#\c0773b528798357263b45b13e47df3a0\System.Runtime.WindowsRuntime.ni.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2091. "1:15:42.2262653 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{E521C894-2C26-5946-9E61-2B5E188D01ED}","NAME NOT FOUND","Desired Access: Read"
  2092. "1:15:42.2544828 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{E521C894-2C26-5946-9E61-2B5E188D01ED}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
  2093. "1:15:42.2864811 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{E521C894-2C26-5946-9E61-2B5E188D01ED}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  2094. "1:15:42.2871201 PM","wwahost.exe","2812","RegLoadKey","\REGISTRY\A\{52cb3144-3ce2-7974-b278-80a3452eaae2}","ACCESS DENIED","Hive Path: C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\Settings\settings.dat"
  2095. "1:15:42.2874003 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\Settings\settings.dat","ACCESS DENIED","Desired Access: Read Data/List Directory, Write Data/Add File, Read Control, Disposition: OpenIf, Options: Sequential Access, Synchronous IO Non-Alert, No Compression, Attributes: N, ShareMode: None, AllocationSize: 0"
  2096. "1:15:42.2875439 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\Settings\settings.dat","ACCESS DENIED","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2097. "1:15:42.2876279 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\Settings\settings.dat","ACCESS DENIED","Desired Access: Read Data/List Directory, Write Data/Add File, Read Control, Disposition: OpenIf, Options: Sequential Access, Synchronous IO Non-Alert, No Compression, Attributes: N, ShareMode: None, AllocationSize: 0, Impersonating: xps\Chloe"
  2098. "1:15:42.2877622 PM","wwahost.exe","2812","CreateFile","C:\Users\Chloe\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\Settings\settings.dat","ACCESS DENIED","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: xps\Chloe"
  2099. "1:15:42.2879617 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\Windows.Storage.ApplicationData.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2100. "1:15:42.2881960 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\OLEAUT32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2101. "1:15:42.2883025 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\OLEAUT32.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2102. "1:15:42.3068041 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en-US\mscorrc.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2103. "1:15:42.3069798 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en-US\mscorrc.dll.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2104. "1:15:42.3071422 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en-US\mscorrc.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2105. "1:15:42.3072964 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en-US\mscorrc.dll.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2106. "1:15:42.3074193 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en\mscorrc.dll","PATH NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2107. "1:15:42.3075008 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en\mscorrc.dll.DLL","PATH NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2108. "1:15:42.3075771 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en\mscorrc.dll","PATH NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2109. "1:15:42.3076514 PM","wwahost.exe","2812","CreateFile","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\en\mscorrc.dll.DLL","PATH NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2110. "1:15:42.3502694 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2111. "1:15:42.5655290 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
  2112. "1:15:42.5933363 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  2113. "1:15:42.5935712 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  2114. "1:15:42.5938764 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server","NAME NOT FOUND","Desired Access: Read"
  2115. "1:15:42.5941046 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server","NAME NOT FOUND","Desired Access: Maximum Allowed"
  2116. "1:15:42.5943050 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server","NAME NOT FOUND","Desired Access: Maximum Allowed"
  2117. "1:15:42.8210512 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Microsoft.NET\Framework64\v4.0.30319\diasymreader.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2118. "1:15:42.8222913 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
  2119. "1:15:42.8224295 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  2120. "1:15:42.8225400 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  2121. "1:15:42.8226955 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server","NAME NOT FOUND","Desired Access: Read"
  2122. "1:15:42.8228096 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server","NAME NOT FOUND","Desired Access: Maximum Allowed"
  2123. "1:15:42.8229128 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server","NAME NOT FOUND","Desired Access: Maximum Allowed"
  2124. "1:15:42.8234731 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\Platform.pdb","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Random Access, Disallow Exclusive, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a"
  2125. "1:15:42.8235908 PM","wwahost.exe","2812","CreateFile","C:\windows\symbols\winmd\Platform.pdb","PATH NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Random Access, Disallow Exclusive, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a"
  2126. "1:15:42.8236723 PM","wwahost.exe","2812","CreateFile","C:\windows\winmd\Platform.pdb","PATH NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Random Access, Disallow Exclusive, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a"
  2127. "1:15:42.8237710 PM","wwahost.exe","2812","CreateFile","C:\Windows\Platform.pdb","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Random Access, Disallow Exclusive, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a"
  2128. "1:15:43.0343654 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
  2129. "1:15:43.0344903 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
  2130. "1:15:43.0345830 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read"
  2131. "1:15:43.0346425 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read"
  2132. "1:15:43.0347599 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wwahost.exe","NAME NOT FOUND","Desired Access: Query Value"
  2133. "1:15:43.0350965 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\WINBRAND.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2134. "1:15:43.0351955 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\WINBRAND.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2135. "1:15:43.0353005 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\WINBRAND.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2136. "1:15:43.0356410 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\winbrand.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2137. "1:15:43.0360642 PM","wwahost.exe","2812","CreateFile","C:\windows\system32\Branding\Basebrd\Basebrd.dll","PATH NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2138. "1:15:43.0363812 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Branding\Basebrd\basebrd.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2139. "1:15:43.0365611 PM","wwahost.exe","2812","CreateFile","C:\windows\system32\Branding\Basebrd\Basebrd.dll","PATH NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2140. "1:15:43.0368460 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Branding\Basebrd\basebrd.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2141. "1:15:43.0370649 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\Branding\Basebrd\en-US\basebrd.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2142. "1:15:43.0373538 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-508114518-3340871649-811464485-526616082-4258465299-1774086546-1865468257","REPARSE","Desired Access: Query Value"
  2143. "1:15:43.0380502 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wwahost.exe","NAME NOT FOUND","Desired Access: Query Value"
  2144. "1:15:43.0381938 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\wer.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2145. "1:15:43.0382938 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\wer.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2146. "1:15:43.0383834 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\wer.dll","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2147. "1:15:43.0387466 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\wer.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2148. "1:15:43.0393427 PM","wwahost.exe","2812","CreateFile","C:\","ACCESS DENIED","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2149. "1:15:43.0440303 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\WaitOnStart","NAME NOT FOUND","Length: 144"
  2150. "1:15:43.1601502 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\CTF\Compatibility\wwahost.exe","NAME NOT FOUND","Desired Access: Read"
  2151. "1:15:43.1713703 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\CTF\EnableAnchorContext","NAME NOT FOUND","Length: 144"
  2152. "1:15:43.1752009 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\wer.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2153. "1:15:43.1753648 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Windows Error Reporting","NAME NOT FOUND","Desired Access: Read"
  2154. "1:15:43.1754204 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData","NAME NOT FOUND","Length: 144"
  2155. "1:15:43.1754288 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled","NAME NOT FOUND","Length: 144"
  2156. "1:15:43.1754711 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent","NAME NOT FOUND","Length: 144"
  2157. "1:15:43.1755124 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior","NAME NOT FOUND","Length: 144"
  2158. "1:15:43.1755577 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\WWAJSE","NAME NOT FOUND","Length: 144"
  2159. "1:15:43.1755728 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled","NAME NOT FOUND","Length: 144"
  2160. "1:15:43.1755800 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI","NAME NOT FOUND","Length: 144"
  2161. "1:15:43.1755870 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive","NAME NOT FOUND","Length: 144"
  2162. "1:15:43.1755939 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive","NAME NOT FOUND","Length: 144"
  2163. "1:15:43.1756012 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue","NAME NOT FOUND","Length: 144"
  2164. "1:15:43.1756081 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount","NAME NOT FOUND","Length: 144"
  2165. "1:15:43.1756151 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount","NAME NOT FOUND","Length: 144"
  2166. "1:15:43.1756223 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue","NAME NOT FOUND","Length: 144"
  2167. "1:15:43.1756289 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval","NAME NOT FOUND","Length: 144"
  2168. "1:15:43.1756474 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ExcludedApplications","NAME NOT FOUND","Desired Access: Read"
  2169. "1:15:43.1756712 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DebugApplications","NAME NOT FOUND","Desired Access: Read"
  2170. "1:15:43.1757035 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DebugApplications","NAME NOT FOUND","Desired Access: Read"
  2171. "1:15:43.1757162 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles","NAME NOT FOUND","Length: 144"
  2172. "1:15:43.1757234 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling","NAME NOT FOUND","Length: 144"
  2173. "1:15:43.1757310 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection","NAME NOT FOUND","Length: 144"
  2174. "1:15:43.1757947 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassPowerThrottling","NAME NOT FOUND","Length: 144"
  2175. "1:15:43.1758016 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassNetworkCostThrottling","NAME NOT FOUND","Length: 144"
  2176. "1:15:43.1758089 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueueNoPesterInterval","NAME NOT FOUND","Length: 144"
  2177. "1:15:43.1758339 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Windows Error Reporting","NAME NOT FOUND","Desired Access: Read"
  2178. "1:15:43.1760036 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior","NAME NOT FOUND","Length: 144"
  2179. "1:15:43.1760419 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\Windows Error Reporting\Consent\WWAJSE","NAME NOT FOUND","Length: 144"
  2180. "1:15:43.1762472 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval","NAME NOT FOUND","Length: 144"
  2181. "1:15:43.1762698 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\Windows Error Reporting\ExcludedApplications","NAME NOT FOUND","Desired Access: Read"
  2182. "1:15:43.1762991 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\Windows Error Reporting\DebugApplications","NAME NOT FOUND","Desired Access: Read"
  2183. "1:15:43.1763229 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Windows\Windows Error Reporting\DebugApplications","NAME NOT FOUND","Desired Access: Read"
  2184. "1:15:43.1763428 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\Windows Error Reporting\SendEFSFiles","NAME NOT FOUND","Length: 144"
  2185. "1:15:43.1763525 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling","NAME NOT FOUND","Length: 144"
  2186. "1:15:43.1763601 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection","NAME NOT FOUND","Length: 144"
  2187. "1:15:43.1763709 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\Windows Error Reporting\BypassPowerThrottling","NAME NOT FOUND","Length: 144"
  2188. "1:15:43.1763794 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\Windows Error Reporting\BypassNetworkCostThrottling","NAME NOT FOUND","Length: 144"
  2189. "1:15:43.1763872 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\Windows Error Reporting\QueueNoPesterInterval","NAME NOT FOUND","Length: 144"
  2190. "1:15:43.1764228 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Windows Error Reporting","NAME NOT FOUND","Desired Access: Read"
  2191. "1:15:43.1765034 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior","NAME NOT FOUND","Length: 144"
  2192. "1:15:43.1765424 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\WWAJSE","NAME NOT FOUND","Length: 144"
  2193. "1:15:43.1765572 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval","NAME NOT FOUND","Length: 144"
  2194. "1:15:43.1765662 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue","NAME NOT FOUND","Length: 144"
  2195. "1:15:43.1765735 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount","NAME NOT FOUND","Length: 144"
  2196. "1:15:43.1765804 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount","NAME NOT FOUND","Length: 144"
  2197. "1:15:43.1765874 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive","NAME NOT FOUND","Length: 144"
  2198. "1:15:43.1765940 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive","NAME NOT FOUND","Length: 144"
  2199. "1:15:43.1766009 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue","NAME NOT FOUND","Length: 144"
  2200. "1:15:43.1766193 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ExcludedApplications","NAME NOT FOUND","Desired Access: Read"
  2201. "1:15:43.1766486 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DebugApplications","NAME NOT FOUND","Desired Access: Read"
  2202. "1:15:43.1766731 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DebugApplications","NAME NOT FOUND","Desired Access: Read"
  2203. "1:15:43.1766849 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer","NAME NOT FOUND","Length: 144"
  2204. "1:15:43.1766921 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL","NAME NOT FOUND","Length: 144"
  2205. "1:15:43.1766990 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber","NAME NOT FOUND","Length: 144"
  2206. "1:15:43.1767060 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication","NAME NOT FOUND","Length: 144"
  2207. "1:15:43.1767184 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles","NAME NOT FOUND","Length: 144"
  2208. "1:15:43.1767286 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling","NAME NOT FOUND","Length: 144"
  2209. "1:15:43.1767362 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection","NAME NOT FOUND","Length: 144"
  2210. "1:15:43.1767440 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassPowerThrottling","NAME NOT FOUND","Length: 144"
  2211. "1:15:43.1767507 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassNetworkCostThrottling","NAME NOT FOUND","Length: 144"
  2212. "1:15:43.1767576 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueueNoPesterInterval","NAME NOT FOUND","Length: 144"
  2213. "1:15:43.1768850 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\MiniNT","REPARSE","Desired Access: Read"
  2214. "1:15:43.1769013 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\MiniNT","NAME NOT FOUND","Desired Access: Read"
  2215. "1:15:43.1769508 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\MiniNT","REPARSE","Desired Access: Read"
  2216. "1:15:43.1769650 PM","wwahost.exe","2812","RegOpenKey","HKLM\System\CurrentControlSet\Control\MiniNT","NAME NOT FOUND","Desired Access: Read"
  2217. "1:15:43.2052531 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\OLEACC.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2218. "1:15:43.2054068 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\OLEACC.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2219. "1:15:43.2055236 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\OLEACC.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2220. "1:15:43.2058892 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\oleacc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2221. "1:15:43.2064651 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\OLEACCRC.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2222. "1:15:43.2065831 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\OLEACCRC.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2223. "1:15:43.2066915 PM","wwahost.exe","2812","CreateFile","C:\Program Files\WindowsApps\Microsoft.WinJS.1.0_1.0.9200.20602_neutral__8wekyb3d8bbwe\OLEACCRC.DLL","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
  2224. "1:15:43.2070567 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\oleaccrc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2225. "1:15:43.2074386 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
  2226. "1:15:43.2075618 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  2227. "1:15:43.2077187 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}","NAME NOT FOUND","Desired Access: Read"
  2228. "1:15:43.2404678 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Read"
  2229. "1:15:43.2405951 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  2230. "1:15:43.2406833 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Microsoft\WindowsRuntime\CLSID\{00020424-0000-0000-C000-000000000046}","NAME NOT FOUND","Desired Access: Read"
  2231. "1:15:43.2407216 PM","wwahost.exe","2812","RegOpenKey","HKCR\ActivatableClasses\CLSID\{00020424-0000-0000-C000-000000000046}","NAME NOT FOUND","Desired Access: Read"
  2232. "1:15:43.2408122 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}","NAME NOT FOUND","Desired Access: Read"
  2233. "1:15:43.2409362 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  2234. "1:15:43.2409996 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{00020424-0000-0000-C000-000000000046}\TreatAs","NAME NOT FOUND","Desired Access: Query Value"
  2235. "1:15:43.2410959 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  2236. "1:15:43.2411847 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}","NAME NOT FOUND","Desired Access: Maximum Allowed"
  2237. "1:15:43.2412764 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32","NAME NOT FOUND","Desired Access: Read"
  2238. "1:15:43.2414059 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  2239. "1:15:43.2414301 PM","wwahost.exe","2812","RegQueryValue","HKCR\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32\InprocServer32","NAME NOT FOUND","Length: 144"
  2240. "1:15:43.2414923 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  2241. "1:15:43.2415874 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  2242. "1:15:43.2416861 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  2243. "1:15:43.2417938 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  2244. "1:15:43.2418361 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{00020424-0000-0000-C000-000000000046}\InprocHandler32","NAME NOT FOUND","Desired Access: Query Value"
  2245. "1:15:43.2419022 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  2246. "1:15:43.2419544 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{00020424-0000-0000-C000-000000000046}\InprocHandler","NAME NOT FOUND","Desired Access: Query Value"
  2247. "1:15:43.2420809 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}","NAME NOT FOUND","Desired Access: Read"
  2248. "1:15:43.2421736 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  2249. "1:15:43.2422152 PM","wwahost.exe","2812","RegOpenKey","HKCR\CLSID\{00020424-0000-0000-C000-000000000046}\TreatAs","NAME NOT FOUND","Desired Access: Read"
  2250. "1:15:43.2426819 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\sxs.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2251. "1:15:43.2432403 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  2252. "1:15:43.2433581 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  2253. "1:15:43.2456196 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  2254. "1:15:43.2457346 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Classes\Interface\{332C4425-26CB-11D0-B483-00C04FD90119}\ProxyStubClsid32","NAME NOT FOUND","Desired Access: Maximum Allowed"
  2255. "1:15:43.2677003 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\AppHost","NAME NOT FOUND","Desired Access: Query Value"
  2256. "1:15:43.2677800 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\AppHost\EnableWebContentEvaluation","NAME NOT FOUND","Length: 144"
  2257. "1:15:43.2678920 PM","wwahost.exe","2812","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\AppHost","NAME NOT FOUND","Desired Access: Query Value"
  2258. "1:15:43.2679518 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\AppHost\EnableWebContentEvaluation","NAME NOT FOUND","Length: 144"
  2259. "1:15:43.2739877 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Policies\Microsoft\Internet Explorer\Main","NAME NOT FOUND","Desired Access: Read"
  2260. "1:15:43.2740587 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\PageSetup\Print_Background","NAME NOT FOUND","Length: 144"
  2261. "1:15:43.2742054 PM","wwahost.exe","2812","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\MenuExt","NAME NOT FOUND","Desired Access: Read"
  2262. "1:15:43.2742582 PM","wwahost.exe","2812","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Nls\CodePage","REPARSE","Desired Access: Read"
  2263. "1:15:43.2743690 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSize","NAME NOT FOUND","Length: 144"
  2264. "1:15:43.2743895 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSizePrivate","NAME NOT FOUND","Length: 144"
  2265. "1:15:43.2744940 PM","wwahost.exe","2812","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\International\AcceptLanguage","NAME NOT FOUND","Length: 144"
  2266. "1:15:43.3625805 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\Windows.Graphics.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2267. "1:15:45.2757892 PM","wwahost.exe","2812","CreateFileMapping","C:\Windows\System32\en-US\twinapi.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
  2268. "1:15:45.3049461 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  2269. "1:15:45.3050276 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  2270. "1:15:45.3050853 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
  2271. "1:15:45.3051372 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  2272. "1:15:45.3051731 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  2273. "1:15:45.3052115 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
  2274. "1:15:45.3054222 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  2275. "1:15:45.3054708 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  2276. "1:15:45.3054979 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
  2277. "1:15:45.3055167 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  2278. "1:15:45.3055308 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  2279. "1:15:45.3055562 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
  2280. "1:15:45.3129952 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  2281. "1:15:45.3130846 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Policies\Microsoft\SQMClient\Windows","NAME NOT FOUND","Desired Access: Read"
  2282. "1:15:45.3131133 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\SQMClient\Windows\StudyId","NAME NOT FOUND","Length: 20"
  2283. "1:15:45.3131341 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows\winsqm8","NAME NOT FOUND","Desired Access: Read"
  2284. "1:15:45.3131498 PM","wwahost.exe","2812","RegOpenKey","HKLM\Software\Microsoft\TelemetryClient\SampleStore\sqm\windows","NAME NOT FOUND","Desired Access: Read"
  2285. "1:15:45.3131751 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\TelemetryClient\SampleStore\sqm\SampledOut","NAME NOT FOUND","Length: 20"
  2286. "1:15:45.3210416 PM","wwahost.exe","2812","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles","NAME NOT FOUND","Length: 20"
Advertisement
Add Comment
Please, Sign In to add comment